Compare commits
13 Commits
a40a2065a9
...
feature/ev
| Author | SHA1 | Date | |
|---|---|---|---|
| 856b9a6706 | |||
| 3ddff7e0ee | |||
| 22de61c8c0 | |||
| 2d11263adc | |||
| c975b5d51d | |||
| c7afb70196 | |||
| 31955f862d | |||
| bb4495c6cc | |||
| 6e1f0d731c | |||
| 82c18e9e91 | |||
| dfad6fb4b0 | |||
| 3f9b773367 | |||
| 7996d53e12 |
@@ -2,7 +2,6 @@
|
||||
|
||||
namespace App\Domains\Commerce\Purchase\Controllers;
|
||||
|
||||
use App\Shared\Integration\Services\TelepagosIntegrationService;
|
||||
use App\Domains\Commerce\Purchase\Models\Purchase;
|
||||
use App\Domains\Commerce\Purchase\Requests\PaymentIntentRequest;
|
||||
use App\Domains\Commerce\Purchase\Requests\StartCheckoutRequest;
|
||||
@@ -13,6 +12,7 @@ use App\Domains\Commerce\Purchase\Services\CheckoutService;
|
||||
use App\Domains\Commerce\Purchase\Services\PurchaseStateGuard;
|
||||
use App\Domains\Core\Tenant\Models\Tenant;
|
||||
use App\Http\Controllers\Controller;
|
||||
use App\Shared\Integration\Services\TelepagosIntegrationService;
|
||||
use Illuminate\Http\JsonResponse;
|
||||
use Illuminate\Http\Request;
|
||||
use Illuminate\Support\Facades\DB;
|
||||
@@ -151,11 +151,14 @@ class PurchaseController extends Controller
|
||||
}
|
||||
|
||||
$compra->refresh();
|
||||
$compra->loadMissing('event');
|
||||
$totalAmount = (float) $compra->total;
|
||||
|
||||
if ($method === 'transfer') {
|
||||
$telepagosService = new TelepagosIntegrationService;
|
||||
$telepagosService->forTenant($tenant->codigo);
|
||||
$compra->event
|
||||
? $telepagosService->forEvent($compra->event)
|
||||
: $telepagosService->forTenant($tenant->codigo);
|
||||
|
||||
try {
|
||||
$accountInfo = $telepagosService->getAccountInfo();
|
||||
@@ -191,7 +194,9 @@ class PurchaseController extends Controller
|
||||
|
||||
if ($method === 'qr') {
|
||||
$telepagosService = new TelepagosIntegrationService;
|
||||
$telepagosService->forTenant($tenant->codigo);
|
||||
$compra->event
|
||||
? $telepagosService->forEvent($compra->event)
|
||||
: $telepagosService->forTenant($tenant->codigo);
|
||||
|
||||
try {
|
||||
Log::channel('telepagos')->info('Generating Telepagos QR.', [
|
||||
|
||||
@@ -2,13 +2,14 @@
|
||||
|
||||
namespace App\Domains\Commerce\Purchase\Models;
|
||||
|
||||
use App\Domains\Core\Auth\Models\User;
|
||||
use App\Domains\Commerce\Cart\Models\Cart;
|
||||
use App\Domains\Commerce\Catalog\Models\StockReservation;
|
||||
use App\Shared\Logging\Models\Concerns\LogsValueChanges;
|
||||
use App\Domains\Commerce\Purchase\Events\PurchasePaid;
|
||||
use App\Domains\Core\Auth\Models\User;
|
||||
use App\Domains\Core\Tenant\Models\Tenant;
|
||||
use App\Domains\Ticketing\Event\Models\Event;
|
||||
use App\Domains\Ticketing\Ticket\Models\Ticket;
|
||||
use App\Shared\Logging\Models\Concerns\LogsValueChanges;
|
||||
use Illuminate\Database\Eloquent\Attributes\Fillable;
|
||||
use Illuminate\Database\Eloquent\Factories\HasFactory;
|
||||
use Illuminate\Database\Eloquent\Model;
|
||||
@@ -21,6 +22,7 @@ use Illuminate\Support\Facades\DB;
|
||||
#[Fillable([
|
||||
'cart_id',
|
||||
'stock_reservation_id',
|
||||
'event_id',
|
||||
'tenant_codigo',
|
||||
'user_id',
|
||||
'status',
|
||||
@@ -149,6 +151,7 @@ class Purchase extends Model
|
||||
return [
|
||||
'cart_id' => 'integer',
|
||||
'stock_reservation_id' => 'integer',
|
||||
'event_id' => 'integer',
|
||||
'user_id' => 'integer',
|
||||
'total' => 'decimal:2',
|
||||
];
|
||||
@@ -162,6 +165,12 @@ class Purchase extends Model
|
||||
return $this->belongsTo(Tenant::class, 'tenant_codigo', 'codigo');
|
||||
}
|
||||
|
||||
/** @return BelongsTo<Event, $this> */
|
||||
public function event(): BelongsTo
|
||||
{
|
||||
return $this->belongsTo(Event::class);
|
||||
}
|
||||
|
||||
/**
|
||||
* @return BelongsTo<User, $this>
|
||||
*/
|
||||
|
||||
@@ -36,11 +36,11 @@ class PurchaseResource extends JsonResource
|
||||
=== StorefrontWebsiteType::CHECKOUT_SUMMARY_EVENT;
|
||||
/** @var Event|null $checkoutEvent */
|
||||
$checkoutEvent = $usesEventSummary
|
||||
? $items
|
||||
? ($this->event ?? $items
|
||||
->map(fn (PurchaseItem $item) => $item->sourceCatalogItem?->event)
|
||||
->filter()
|
||||
->unique('id')
|
||||
->first()
|
||||
->first())
|
||||
: null;
|
||||
|
||||
$subtotal = $items->isNotEmpty()
|
||||
@@ -62,6 +62,7 @@ class PurchaseResource extends JsonResource
|
||||
return [
|
||||
'id' => $this->id,
|
||||
'cart_id' => $this->cart_id,
|
||||
'event_id' => $this->event_id,
|
||||
'tenant_codigo' => $this->tenant_codigo,
|
||||
'user_id' => $this->user_id,
|
||||
'created_at' => $this->created_at,
|
||||
|
||||
@@ -14,6 +14,7 @@ class PurchaseResponseLoader
|
||||
=== StorefrontWebsiteType::CHECKOUT_SUMMARY_EVENT;
|
||||
$relations = [
|
||||
'tenant',
|
||||
'event.attachment',
|
||||
'items.sourceCatalogItem.event.attachment',
|
||||
'stockReservation',
|
||||
];
|
||||
|
||||
@@ -206,6 +206,7 @@ class StartCheckoutService
|
||||
fn (array $line): float => $line['selection']->getPrice() * $line['quantity'],
|
||||
),
|
||||
$cart->getKey(),
|
||||
$cartItems->first()?->catalogItem?->event_id,
|
||||
);
|
||||
$cart->update(['current_purchase_id' => $purchase->getKey()]);
|
||||
$this->reservations->attachToPurchase($cart, $purchase, $this->checkoutExpiration());
|
||||
@@ -273,6 +274,7 @@ class StartCheckoutService
|
||||
$purchaseData,
|
||||
$cart->getTotalAmount(),
|
||||
$cart->getKey(),
|
||||
$cartItems->first()?->catalogItem?->event_id,
|
||||
);
|
||||
$cart->update(['current_purchase_id' => $purchase->getKey()]);
|
||||
$this->reservations->attachToPurchase($cart, $purchase, $this->checkoutExpiration());
|
||||
@@ -410,10 +412,12 @@ class StartCheckoutService
|
||||
array $purchaseData,
|
||||
float $total,
|
||||
?int $cartId,
|
||||
?int $eventId,
|
||||
): Purchase {
|
||||
return Purchase::query()->create([
|
||||
...$purchaseData,
|
||||
'cart_id' => $cartId,
|
||||
'event_id' => $eventId,
|
||||
'tenant_codigo' => $tenant->codigo,
|
||||
'user_id' => $userId,
|
||||
'status' => Purchase::STATUS_CREATED,
|
||||
|
||||
@@ -8,12 +8,14 @@ use Illuminate\Database\Eloquent\Builder;
|
||||
|
||||
class PurchaseRefundSummaryService
|
||||
{
|
||||
public function totalForTenant(Tenant $tenant): string
|
||||
public function totalForTenant(Tenant $tenant, ?int $eventId = null): string
|
||||
{
|
||||
$total = TicketRefund::query()
|
||||
->whereHas(
|
||||
'purchaseItem.purchase',
|
||||
fn (Builder $query): Builder => $query->where('tenant_codigo', $tenant->codigo)
|
||||
fn (Builder $query): Builder => $query
|
||||
->where('tenant_codigo', $tenant->codigo)
|
||||
->when($eventId !== null, fn (Builder $query): Builder => $query->where('event_id', $eventId))
|
||||
)
|
||||
->sum('amount');
|
||||
|
||||
|
||||
@@ -32,10 +32,10 @@ class SaleController extends Controller
|
||||
$tenant = $request->user()->tenant()->firstOrFail();
|
||||
|
||||
return SaleResource::collection(
|
||||
$this->saleService->sales($tenant, $request->validated())
|
||||
$this->saleService->sales($tenant, $request->validated(), $request->user()->event_id)
|
||||
)->additional([
|
||||
'confirmed_sales_total' => $this->saleService->confirmedSalesTotal($tenant),
|
||||
'refunded_total' => $this->saleService->refundedTotal($tenant),
|
||||
'confirmed_sales_total' => $this->saleService->confirmedSalesTotal($tenant, $request->user()->event_id),
|
||||
'refunded_total' => $this->saleService->refundedTotal($tenant, $request->user()->event_id),
|
||||
]);
|
||||
}
|
||||
|
||||
@@ -43,7 +43,7 @@ class SaleController extends Controller
|
||||
{
|
||||
$tenant = $request->user()->tenant()->firstOrFail();
|
||||
|
||||
return new SaleDetailResource($this->saleService->detail($tenant, $sale));
|
||||
return new SaleDetailResource($this->saleService->detail($tenant, $sale, $request->user()->event_id));
|
||||
}
|
||||
|
||||
public function tickets(Request $request, int $sale): AnonymousResourceCollection
|
||||
@@ -51,7 +51,7 @@ class SaleController extends Controller
|
||||
$tenant = $request->user()->tenant()->firstOrFail();
|
||||
|
||||
return SaleTicketResource::collection(
|
||||
$this->saleService->tickets($tenant, $sale)
|
||||
$this->saleService->tickets($tenant, $sale, $request->user()->event_id)
|
||||
);
|
||||
}
|
||||
|
||||
@@ -59,14 +59,14 @@ class SaleController extends Controller
|
||||
{
|
||||
$tenant = $request->user()->tenant()->firstOrFail();
|
||||
|
||||
return new SaleResource($this->saleService->confirm($tenant, $sale));
|
||||
return new SaleResource($this->saleService->confirm($tenant, $sale, $request->user()->event_id));
|
||||
}
|
||||
|
||||
public function cancel(Request $request, int $sale): SaleResource
|
||||
{
|
||||
$tenant = $request->user()->tenant()->firstOrFail();
|
||||
|
||||
return new SaleResource($this->saleService->cancel($tenant, $sale));
|
||||
return new SaleResource($this->saleService->cancel($tenant, $sale, $request->user()->event_id));
|
||||
}
|
||||
|
||||
public function modifications(
|
||||
@@ -76,6 +76,7 @@ class SaleController extends Controller
|
||||
$this->saleService->modifications(
|
||||
$request->user()->tenant()->firstOrFail(),
|
||||
$request->validated(),
|
||||
$request->user()->event_id,
|
||||
)
|
||||
);
|
||||
}
|
||||
@@ -86,7 +87,7 @@ class SaleController extends Controller
|
||||
|
||||
return $this->salePdfService->downloadSales(
|
||||
$tenant,
|
||||
$this->saleService->salesForExport($tenant, $request->validated()),
|
||||
$this->saleService->salesForExport($tenant, $request->validated(), $request->user()->event_id),
|
||||
$request->validated('timezone'),
|
||||
);
|
||||
}
|
||||
@@ -97,7 +98,7 @@ class SaleController extends Controller
|
||||
|
||||
return $this->salePdfService->downloadModifications(
|
||||
$tenant,
|
||||
$this->saleService->modificationsForExport($tenant, $request->validated()),
|
||||
$this->saleService->modificationsForExport($tenant, $request->validated(), $request->user()->event_id),
|
||||
$request->validated('timezone'),
|
||||
);
|
||||
}
|
||||
@@ -108,7 +109,7 @@ class SaleController extends Controller
|
||||
|
||||
return $this->saleExcelService->downloadSales(
|
||||
$tenant,
|
||||
$this->saleService->salesForExport($tenant, $request->validated()),
|
||||
$this->saleService->salesForExport($tenant, $request->validated(), $request->user()->event_id),
|
||||
$request->validated('timezone'),
|
||||
);
|
||||
}
|
||||
@@ -120,7 +121,7 @@ class SaleController extends Controller
|
||||
|
||||
return $this->saleExcelService->downloadModifications(
|
||||
$tenant,
|
||||
$this->saleService->modificationsForExport($tenant, $request->validated()),
|
||||
$this->saleService->modificationsForExport($tenant, $request->validated(), $request->user()->event_id),
|
||||
$request->validated('timezone'),
|
||||
);
|
||||
}
|
||||
|
||||
@@ -2,7 +2,6 @@
|
||||
|
||||
namespace App\Domains\Commerce\Sale\Services;
|
||||
|
||||
use App\Shared\Logging\Models\ValueChange;
|
||||
use App\Domains\Commerce\Purchase\Models\Purchase;
|
||||
use App\Domains\Commerce\Purchase\Services\CheckoutService;
|
||||
use App\Domains\Commerce\Purchase\Services\PurchaseRefundSummaryService;
|
||||
@@ -10,6 +9,7 @@ use App\Domains\Core\Tenant\Models\Tenant;
|
||||
use App\Domains\Ticketing\Ticket\Models\Ticket;
|
||||
use App\Domains\Ticketing\Ticket\Services\TicketPresentationResolver;
|
||||
use App\Domains\Ticketing\Ticket\Services\TicketValidityResolver;
|
||||
use App\Shared\Logging\Models\ValueChange;
|
||||
use Illuminate\Database\Eloquent\Builder;
|
||||
use Illuminate\Pagination\LengthAwarePaginator;
|
||||
use Illuminate\Support\Collection;
|
||||
@@ -21,19 +21,18 @@ class AdminAppSaleService
|
||||
protected PurchaseRefundSummaryService $refundSummaryService,
|
||||
) {}
|
||||
|
||||
public function confirmedSalesTotal(Tenant $tenant): string
|
||||
public function confirmedSalesTotal(Tenant $tenant, ?int $eventId = null): string
|
||||
{
|
||||
$total = Purchase::query()
|
||||
->where('tenant_codigo', $tenant->codigo)
|
||||
$total = $this->purchasesQuery($tenant, $eventId)
|
||||
->where('status', Purchase::STATUS_PAID)
|
||||
->sum('total');
|
||||
|
||||
return number_format((float) $total, 2, '.', '');
|
||||
}
|
||||
|
||||
public function refundedTotal(Tenant $tenant): string
|
||||
public function refundedTotal(Tenant $tenant, ?int $eventId = null): string
|
||||
{
|
||||
return $this->refundSummaryService->totalForTenant($tenant);
|
||||
return $this->refundSummaryService->totalForTenant($tenant, $eventId);
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -47,43 +46,42 @@ class AdminAppSaleService
|
||||
* } $filters
|
||||
* @return LengthAwarePaginator<Purchase>
|
||||
*/
|
||||
public function sales(Tenant $tenant, array $filters = []): LengthAwarePaginator
|
||||
public function sales(Tenant $tenant, array $filters = [], ?int $eventId = null): LengthAwarePaginator
|
||||
{
|
||||
return $this->salesQuery($tenant, $filters)
|
||||
return $this->salesQuery($tenant, $filters, $eventId)
|
||||
->paginateFromRequest()
|
||||
->withQueryString();
|
||||
}
|
||||
|
||||
public function detail(Tenant $tenant, int $saleId): Purchase
|
||||
public function detail(Tenant $tenant, int $saleId, ?int $eventId = null): Purchase
|
||||
{
|
||||
return Purchase::query()
|
||||
->where('tenant_codigo', $tenant->codigo)
|
||||
return $this->purchasesQuery($tenant, $eventId)
|
||||
->with('items')
|
||||
->findOrFail($saleId);
|
||||
}
|
||||
|
||||
/** @return Collection<int, Ticket> */
|
||||
public function tickets(Tenant $tenant, int $saleId): Collection
|
||||
public function tickets(Tenant $tenant, int $saleId, ?int $eventId = null): Collection
|
||||
{
|
||||
return $this->findForTenant($tenant, $saleId)
|
||||
return $this->findForTenant($tenant, $saleId, $eventId)
|
||||
->tickets()
|
||||
->with([...TicketValidityResolver::RELATIONS, ...TicketPresentationResolver::RELATIONS, 'refund'])
|
||||
->orderBy('id')
|
||||
->get();
|
||||
}
|
||||
|
||||
public function confirm(Tenant $tenant, int $saleId): Purchase
|
||||
public function confirm(Tenant $tenant, int $saleId, ?int $eventId = null): Purchase
|
||||
{
|
||||
$sale = $this->findForTenant($tenant, $saleId);
|
||||
$sale = $this->findForTenant($tenant, $saleId, $eventId);
|
||||
|
||||
return $this->saleForResponse(
|
||||
$this->checkoutService->confirmPaidPurchase($sale)
|
||||
);
|
||||
}
|
||||
|
||||
public function cancel(Tenant $tenant, int $saleId): Purchase
|
||||
public function cancel(Tenant $tenant, int $saleId, ?int $eventId = null): Purchase
|
||||
{
|
||||
$sale = $this->findForTenant($tenant, $saleId);
|
||||
$sale = $this->findForTenant($tenant, $saleId, $eventId);
|
||||
|
||||
return $this->saleForResponse(
|
||||
$this->checkoutService->cancelPurchaseFromAdmin($sale)
|
||||
@@ -94,18 +92,18 @@ class AdminAppSaleService
|
||||
* @param array<string, mixed> $filters
|
||||
* @return Collection<int, Purchase>
|
||||
*/
|
||||
public function salesForExport(Tenant $tenant, array $filters = []): Collection
|
||||
public function salesForExport(Tenant $tenant, array $filters = [], ?int $eventId = null): Collection
|
||||
{
|
||||
return $this->salesQuery($tenant, $filters)->get();
|
||||
return $this->salesQuery($tenant, $filters, $eventId)->get();
|
||||
}
|
||||
|
||||
/**
|
||||
* @param array<string, mixed> $filters
|
||||
* @return LengthAwarePaginator<ValueChange>
|
||||
*/
|
||||
public function modifications(Tenant $tenant, array $filters = []): LengthAwarePaginator
|
||||
public function modifications(Tenant $tenant, array $filters = [], ?int $eventId = null): LengthAwarePaginator
|
||||
{
|
||||
return $this->modificationsQuery($tenant, $filters)
|
||||
return $this->modificationsQuery($tenant, $filters, $eventId)
|
||||
->paginateFromRequest()
|
||||
->withQueryString();
|
||||
}
|
||||
@@ -114,13 +112,13 @@ class AdminAppSaleService
|
||||
* @param array<string, mixed> $filters
|
||||
* @return Collection<int, ValueChange>
|
||||
*/
|
||||
public function modificationsForExport(Tenant $tenant, array $filters = []): Collection
|
||||
public function modificationsForExport(Tenant $tenant, array $filters = [], ?int $eventId = null): Collection
|
||||
{
|
||||
return $this->modificationsQuery($tenant, $filters)->get();
|
||||
return $this->modificationsQuery($tenant, $filters, $eventId)->get();
|
||||
}
|
||||
|
||||
/** @param array<string, mixed> $filters */
|
||||
protected function salesQuery(Tenant $tenant, array $filters): Builder
|
||||
protected function salesQuery(Tenant $tenant, array $filters, ?int $eventId = null): Builder
|
||||
{
|
||||
$sortColumns = [
|
||||
'id' => 'id',
|
||||
@@ -137,8 +135,7 @@ class AdminAppSaleService
|
||||
? $requestedDirection
|
||||
: 'desc';
|
||||
|
||||
return Purchase::query()
|
||||
->where('tenant_codigo', $tenant->codigo)
|
||||
return $this->purchasesQuery($tenant, $eventId)
|
||||
->when($filters['q'] ?? null, function (Builder $query, string $search): void {
|
||||
$term = trim($search);
|
||||
|
||||
@@ -176,11 +173,18 @@ class AdminAppSaleService
|
||||
* @param array<string, mixed> $filters
|
||||
* @return Builder<ValueChange>
|
||||
*/
|
||||
protected function modificationsQuery(Tenant $tenant, array $filters): Builder
|
||||
protected function modificationsQuery(Tenant $tenant, array $filters, ?int $eventId = null): Builder
|
||||
{
|
||||
return ValueChange::query()
|
||||
->where('tenant_code', $tenant->codigo)
|
||||
->where('trackable_type', (new Purchase)->getMorphClass())
|
||||
->when($eventId !== null, fn (Builder $query): Builder => $query->whereHasMorph(
|
||||
'trackable',
|
||||
[Purchase::class],
|
||||
fn (Builder $sales): Builder => $sales
|
||||
->where('tenant_codigo', $tenant->codigo)
|
||||
->where('event_id', $eventId),
|
||||
))
|
||||
->when($filters['q'] ?? null, function (Builder $query, string $search): void {
|
||||
$term = trim($search);
|
||||
|
||||
@@ -221,11 +225,18 @@ class AdminAppSaleService
|
||||
->orderByDesc('id');
|
||||
}
|
||||
|
||||
protected function findForTenant(Tenant $tenant, int $saleId): Purchase
|
||||
protected function findForTenant(Tenant $tenant, int $saleId, ?int $eventId = null): Purchase
|
||||
{
|
||||
return $this->purchasesQuery($tenant, $eventId)
|
||||
->findOrFail($saleId);
|
||||
}
|
||||
|
||||
/** @return Builder<Purchase> */
|
||||
protected function purchasesQuery(Tenant $tenant, ?int $eventId): Builder
|
||||
{
|
||||
return Purchase::query()
|
||||
->where('tenant_codigo', $tenant->codigo)
|
||||
->findOrFail($saleId);
|
||||
->when($eventId !== null, fn (Builder $query): Builder => $query->where('event_id', $eventId));
|
||||
}
|
||||
|
||||
protected function saleForResponse(Purchase $sale): Purchase
|
||||
|
||||
@@ -29,4 +29,8 @@ Consume compras de `Purchase`, datos del tenant y entradas de `Logging`. No es d
|
||||
|
||||
La consulta paginada y la colección de exportación deben aplicar los mismos filtros para evitar diferencias entre pantalla, PDF y Excel.
|
||||
|
||||
Cuando el usuario autenticado tiene `event_id`, el controlador lo pasa al servicio como alcance obligatorio para ventas, totales, historial y exportaciones. El alcance se combina con el tenant y no se obtiene de los filtros enviados por el cliente. Los administradores sin `event_id` conservan el alcance del tenant.
|
||||
|
||||
El detalle, los tickets de una venta, la confirmación y la cancelación buscan la compra dentro del mismo alcance. Una venta de otro evento o sin evento devuelve 404 para un administrador con `event_id`, antes de ejecutar cualquier acción en `CheckoutService`.
|
||||
|
||||
El historial comparte con ventas los filtros de búsqueda, ID, fecha de venta y estado. En el historial, el estado se evalúa sobre `ValueChange.new_value`: representa el resultado de esa modificación y no el estado actual de la venta.
|
||||
|
||||
@@ -20,6 +20,7 @@ class AdminAppAdministratorController extends Controller
|
||||
return AdministratorResource::collection($this->administratorService->list(
|
||||
$request->user()->tenant()->firstOrFail(),
|
||||
$request->string('search')->trim()->toString() ?: null,
|
||||
$request->user()->event_id,
|
||||
));
|
||||
}
|
||||
|
||||
@@ -28,6 +29,7 @@ class AdminAppAdministratorController extends Controller
|
||||
return AdministratorResource::make($this->administratorService->create(
|
||||
$request->user()->tenant()->firstOrFail(),
|
||||
$request->validated(),
|
||||
$request->user()->event_id,
|
||||
));
|
||||
}
|
||||
|
||||
@@ -37,6 +39,7 @@ class AdminAppAdministratorController extends Controller
|
||||
$request->user()->tenant()->firstOrFail(),
|
||||
$administrator,
|
||||
$request->validated(),
|
||||
$request->user()->event_id,
|
||||
));
|
||||
}
|
||||
|
||||
|
||||
@@ -18,6 +18,7 @@ class AdministratorResource extends JsonResource
|
||||
'dni' => $this->dni,
|
||||
'email' => $this->email,
|
||||
'rol_codigo' => $this->rol_codigo,
|
||||
'event_id' => $this->event_id,
|
||||
'role' => $this->whenLoaded('role', fn () => [
|
||||
'codigo' => $this->role?->codigo,
|
||||
'nombre' => $this->role?->nombre,
|
||||
|
||||
@@ -19,9 +19,9 @@ class AdministratorService
|
||||
public function __construct(private readonly ResetPasswordAttemptService $resetPasswordAttemptService) {}
|
||||
|
||||
/** @return Collection<int, User> */
|
||||
public function list(Tenant $tenant, ?string $search = null): Collection
|
||||
public function list(Tenant $tenant, ?string $search = null, ?int $eventId = null): Collection
|
||||
{
|
||||
return $this->query($tenant)->with('role')
|
||||
return $this->query($tenant, $eventId)->with('role')
|
||||
->when($search, fn (Builder $query, string $search) => $query->where(function (Builder $query) use ($search): void {
|
||||
$query->where('nombre_apellido', 'like', "%{$search}%")
|
||||
->orWhere('dni', 'like', "%{$search}%")
|
||||
@@ -31,14 +31,15 @@ class AdministratorService
|
||||
}
|
||||
|
||||
/** @param array<string, mixed> $data */
|
||||
public function create(Tenant $tenant, array $data): User
|
||||
public function create(Tenant $tenant, array $data, ?int $eventId = null): User
|
||||
{
|
||||
return DB::transaction(function () use ($tenant, $data): User {
|
||||
return DB::transaction(function () use ($tenant, $data, $eventId): User {
|
||||
$administrator = User::query()->create([
|
||||
...$this->attributes($data),
|
||||
'password' => Str::random(64),
|
||||
'rol_codigo' => RoleCode::AdminApp->value,
|
||||
'tenant_codigo' => $tenant->codigo,
|
||||
'event_id' => $eventId,
|
||||
]);
|
||||
$this->resetPasswordAttemptService->createForAdminAppEmail(
|
||||
$administrator->email,
|
||||
@@ -50,10 +51,10 @@ class AdministratorService
|
||||
}
|
||||
|
||||
/** @param array<string, mixed> $data */
|
||||
public function update(Tenant $tenant, int $administratorId, array $data): User
|
||||
public function update(Tenant $tenant, int $administratorId, array $data, ?int $eventId = null): User
|
||||
{
|
||||
return DB::transaction(function () use ($tenant, $administratorId, $data): User {
|
||||
$administrator = $this->query($tenant)->lockForUpdate()->findOrFail($administratorId);
|
||||
return DB::transaction(function () use ($tenant, $administratorId, $data, $eventId): User {
|
||||
$administrator = $this->query($tenant, $eventId)->lockForUpdate()->findOrFail($administratorId);
|
||||
$administrator->update($this->attributes($data));
|
||||
|
||||
return $administrator->load('role');
|
||||
@@ -66,11 +67,11 @@ class AdministratorService
|
||||
// Serialize deletions for this tenant, including requests already authenticated
|
||||
// when another administrator removes their account.
|
||||
Tenant::query()->whereKey($tenant->getKey())->lockForUpdate()->firstOrFail();
|
||||
$administrator = $this->query($tenant)->lockForUpdate()->findOrFail($administratorId);
|
||||
$administrator = $this->query($tenant, $actor->event_id)->lockForUpdate()->findOrFail($administratorId);
|
||||
if ($administrator->is($actor)) {
|
||||
throw ValidationException::withMessages(['administrator' => 'No podés eliminar tu propio usuario.']);
|
||||
}
|
||||
$activeAdministrators = $this->query($tenant)->lockForUpdate()->get();
|
||||
$activeAdministrators = $this->query($tenant, $actor->event_id)->lockForUpdate()->get();
|
||||
if ($activeAdministrators->count() <= 1) {
|
||||
throw ValidationException::withMessages(['administrator' => 'El tenant debe conservar al menos un administrador.']);
|
||||
}
|
||||
@@ -80,10 +81,11 @@ class AdministratorService
|
||||
});
|
||||
}
|
||||
|
||||
private function query(Tenant $tenant): Builder
|
||||
private function query(Tenant $tenant, ?int $eventId = null): Builder
|
||||
{
|
||||
return User::query()->where('tenant_codigo', $tenant->codigo)
|
||||
->where('rol_codigo', RoleCode::AdminApp->value);
|
||||
->where('rol_codigo', RoleCode::AdminApp->value)
|
||||
->when($eventId !== null, fn (Builder $query): Builder => $query->where('event_id', $eventId));
|
||||
}
|
||||
|
||||
/** @param array<string, mixed> $data
|
||||
|
||||
@@ -55,6 +55,8 @@ No agrega tablas ni migraciones. No modifica el CRUD de escáneres ni el fronten
|
||||
|
||||
## Verificación
|
||||
|
||||
Cuando el actor tiene `event_id`, los nuevos administradores heredan su evento y el listado, la búsqueda, la edición y la baja se limitan a ese evento dentro del tenant. La comprobación de administradores activos también usa ese alcance. El evento se toma del usuario autenticado, no del cuerpo de la solicitud; sin `event_id` se conserva el comportamiento por tenant.
|
||||
|
||||
`php artisan test tests/Feature/Administrator/AdministratorControllerTest.php`
|
||||
|
||||
Las pruebas cubren CRUD, normalización y unicidad del email, establecimiento de
|
||||
|
||||
@@ -2,11 +2,12 @@
|
||||
|
||||
namespace App\Domains\Core\Auth\Models;
|
||||
|
||||
use App\Domains\Commerce\Catalog\Models\Category;
|
||||
use App\Domains\Core\Authorization\Enums\RoleCode;
|
||||
use App\Domains\Core\Authorization\Models\Role;
|
||||
use App\Domains\Commerce\Catalog\Models\Category;
|
||||
use App\Domains\Ticketing\Event\Models\EventDateChangeView;
|
||||
use App\Domains\Core\Tenant\Models\Tenant;
|
||||
use App\Domains\Ticketing\Event\Models\Event;
|
||||
use App\Domains\Ticketing\Event\Models\EventDateChangeView;
|
||||
use App\Domains\Ticketing\Ticket\Models\ScanAttempt;
|
||||
use Database\Factories\UserFactory;
|
||||
use Illuminate\Database\Eloquent\Attributes\Fillable;
|
||||
@@ -20,7 +21,7 @@ use Illuminate\Foundation\Auth\User as Authenticatable;
|
||||
use Illuminate\Notifications\Notifiable;
|
||||
use Laravel\Sanctum\HasApiTokens;
|
||||
|
||||
#[Fillable(['nombre_apellido', 'email', 'password', 'dni', 'telefono', 'google_id', 'rol_codigo', 'tenant_codigo'])]
|
||||
#[Fillable(['nombre_apellido', 'email', 'password', 'dni', 'telefono', 'google_id', 'rol_codigo', 'tenant_codigo', 'event_id'])]
|
||||
#[Hidden(['password', 'remember_token', 'active_email', 'active_google_id'])]
|
||||
class User extends Authenticatable
|
||||
{
|
||||
@@ -86,6 +87,12 @@ class User extends Authenticatable
|
||||
return $this->belongsTo(Tenant::class, 'tenant_codigo', 'codigo');
|
||||
}
|
||||
|
||||
/** @return BelongsTo<Event, $this> */
|
||||
public function event(): BelongsTo
|
||||
{
|
||||
return $this->belongsTo(Event::class);
|
||||
}
|
||||
|
||||
/** @return BelongsToMany<Category, $this> */
|
||||
public function scanCategories(): BelongsToMany
|
||||
{
|
||||
@@ -103,6 +110,7 @@ class User extends Authenticatable
|
||||
protected function casts(): array
|
||||
{
|
||||
return [
|
||||
'event_id' => 'integer',
|
||||
'email_verified_at' => 'datetime',
|
||||
'password' => 'hashed',
|
||||
'failed_login_attempts' => 'integer',
|
||||
|
||||
@@ -24,6 +24,7 @@ class UserResource extends JsonResource
|
||||
'telefono' => $this->telefono,
|
||||
'rol_codigo' => $this->rol_codigo,
|
||||
'tenant_codigo' => $this->tenant_codigo,
|
||||
'event_id' => $this->event_id,
|
||||
'categories' => $this->whenLoaded('scanCategories', fn () => $this->scanCategories
|
||||
->map(fn ($category) => [
|
||||
'id' => $category->id,
|
||||
|
||||
@@ -2,8 +2,9 @@
|
||||
|
||||
namespace App\Domains\Core\Client\Models;
|
||||
|
||||
use App\Shared\Integration\Models\ClientIntegration;
|
||||
use App\Domains\Core\Tenant\Models\Tenant;
|
||||
use App\Domains\Ticketing\Event\Models\Event;
|
||||
use App\Shared\Integration\Models\ClientIntegration;
|
||||
use Illuminate\Database\Eloquent\Attributes\Fillable;
|
||||
use Illuminate\Database\Eloquent\Model;
|
||||
use Illuminate\Database\Eloquent\Relations\HasMany;
|
||||
@@ -22,6 +23,12 @@ class Client extends Model
|
||||
return $this->hasMany(Tenant::class);
|
||||
}
|
||||
|
||||
/** @return HasMany<Event, $this> */
|
||||
public function events(): HasMany
|
||||
{
|
||||
return $this->hasMany(Event::class);
|
||||
}
|
||||
|
||||
/** @return HasMany<ClientIntegration, $this> */
|
||||
public function integrations(): HasMany
|
||||
{
|
||||
|
||||
@@ -26,6 +26,7 @@ class AdminAppStaffController extends Controller
|
||||
return StaffResource::collection($this->staffService->list(
|
||||
$request->user()->tenant()->firstOrFail(),
|
||||
$request->string('search')->trim()->toString() ?: null,
|
||||
$request->user()->event_id,
|
||||
));
|
||||
}
|
||||
|
||||
@@ -34,6 +35,7 @@ class AdminAppStaffController extends Controller
|
||||
return StaffResource::make($this->staffService->create(
|
||||
$request->user()->tenant()->firstOrFail(),
|
||||
$request->validated(),
|
||||
$request->user()->event_id,
|
||||
));
|
||||
}
|
||||
|
||||
@@ -43,12 +45,13 @@ class AdminAppStaffController extends Controller
|
||||
$request->user()->tenant()->firstOrFail(),
|
||||
$staff,
|
||||
$request->validated(),
|
||||
$request->user()->event_id,
|
||||
));
|
||||
}
|
||||
|
||||
public function destroy(Request $request, int $staff): Response
|
||||
{
|
||||
$this->staffService->delete($request->user()->tenant()->firstOrFail(), $staff);
|
||||
$this->staffService->delete($request->user()->tenant()->firstOrFail(), $staff, $request->user()->event_id);
|
||||
|
||||
return response()->noContent();
|
||||
}
|
||||
@@ -60,6 +63,7 @@ class AdminAppStaffController extends Controller
|
||||
$scanner = $this->staffService->find(
|
||||
$request->user()->tenant()->firstOrFail(),
|
||||
$staff,
|
||||
$request->user()->event_id,
|
||||
);
|
||||
|
||||
return ScanAttemptResource::collection(
|
||||
|
||||
@@ -18,6 +18,7 @@ class StaffResource extends JsonResource
|
||||
'dni' => $this->dni,
|
||||
'email' => $this->email,
|
||||
'rol_codigo' => $this->rol_codigo,
|
||||
'event_id' => $this->event_id,
|
||||
'role' => $this->whenLoaded('role', fn () => [
|
||||
'codigo' => $this->role?->codigo,
|
||||
'nombre' => $this->role?->nombre,
|
||||
|
||||
@@ -2,11 +2,11 @@
|
||||
|
||||
namespace App\Domains\Core\Staff\Services;
|
||||
|
||||
use App\Domains\Commerce\Catalog\Models\Category;
|
||||
use App\Domains\Core\Auth\Models\ResetPasswordAttempt;
|
||||
use App\Domains\Core\Auth\Models\User;
|
||||
use App\Domains\Core\Auth\Services\ResetPasswordAttemptService;
|
||||
use App\Domains\Core\Authorization\Enums\RoleCode;
|
||||
use App\Domains\Commerce\Catalog\Models\Category;
|
||||
use App\Domains\Core\Tenant\Models\Tenant;
|
||||
use Illuminate\Database\Eloquent\Builder;
|
||||
use Illuminate\Database\Eloquent\Collection;
|
||||
@@ -22,9 +22,9 @@ class StaffService
|
||||
) {}
|
||||
|
||||
/** @return Collection<int, User> */
|
||||
public function list(Tenant $tenant, ?string $search = null): Collection
|
||||
public function list(Tenant $tenant, ?string $search = null, ?int $eventId = null): Collection
|
||||
{
|
||||
return $this->staffQuery($tenant)
|
||||
return $this->staffQuery($tenant, $eventId)
|
||||
->with(['role', 'scanCategories' => fn ($query) => $query->orderBy('nombre')])
|
||||
->when($search, function (Builder $query, string $search): void {
|
||||
$query->where(function (Builder $query) use ($search): void {
|
||||
@@ -52,18 +52,19 @@ class StaffService
|
||||
}
|
||||
|
||||
/** @param array<string, mixed> $data */
|
||||
public function create(Tenant $tenant, array $data): User
|
||||
public function create(Tenant $tenant, array $data, ?int $eventId = null): User
|
||||
{
|
||||
$categoryIds = $this->categoryIdsFor($tenant, $data);
|
||||
$this->assertCategoriesBelongToTenant($tenant, $categoryIds);
|
||||
|
||||
return DB::transaction(function () use ($tenant, $data, $categoryIds): User {
|
||||
return DB::transaction(function () use ($tenant, $data, $categoryIds, $eventId): User {
|
||||
$staff = User::query()->create([
|
||||
...Arr::only($data, ['nombre_apellido', 'dni', 'email']),
|
||||
'email' => mb_strtolower(trim((string) $data['email'])),
|
||||
'password' => Str::random(64),
|
||||
'rol_codigo' => RoleCode::Scanner->value,
|
||||
'tenant_codigo' => $tenant->codigo,
|
||||
'event_id' => $eventId,
|
||||
]);
|
||||
$staff->scanCategories()->sync($categoryIds);
|
||||
$this->resetPasswordAttemptService->createForScannerEmail(
|
||||
@@ -76,9 +77,9 @@ class StaffService
|
||||
}
|
||||
|
||||
/** @param array<string, mixed> $data */
|
||||
public function update(Tenant $tenant, int $staffId, array $data): User
|
||||
public function update(Tenant $tenant, int $staffId, array $data, ?int $eventId = null): User
|
||||
{
|
||||
$staff = $this->find($tenant, $staffId);
|
||||
$staff = $this->find($tenant, $staffId, $eventId);
|
||||
$categoryIds = $this->categoryIdsFor($tenant, $data);
|
||||
$this->assertCategoriesBelongToTenant($tenant, $categoryIds);
|
||||
|
||||
@@ -92,9 +93,9 @@ class StaffService
|
||||
});
|
||||
}
|
||||
|
||||
public function delete(Tenant $tenant, int $staffId): void
|
||||
public function delete(Tenant $tenant, int $staffId, ?int $eventId = null): void
|
||||
{
|
||||
$staff = $this->find($tenant, $staffId);
|
||||
$staff = $this->find($tenant, $staffId, $eventId);
|
||||
|
||||
DB::transaction(function () use ($staff): void {
|
||||
$staff->tokens()->delete();
|
||||
@@ -102,16 +103,17 @@ class StaffService
|
||||
});
|
||||
}
|
||||
|
||||
public function find(Tenant $tenant, int $staffId): User
|
||||
public function find(Tenant $tenant, int $staffId, ?int $eventId = null): User
|
||||
{
|
||||
return $this->staffQuery($tenant)->findOrFail($staffId);
|
||||
return $this->staffQuery($tenant, $eventId)->findOrFail($staffId);
|
||||
}
|
||||
|
||||
private function staffQuery(Tenant $tenant): Builder
|
||||
private function staffQuery(Tenant $tenant, ?int $eventId = null): Builder
|
||||
{
|
||||
return User::query()
|
||||
->where('tenant_codigo', $tenant->codigo)
|
||||
->where('rol_codigo', RoleCode::Scanner->value);
|
||||
->where('rol_codigo', RoleCode::Scanner->value)
|
||||
->when($eventId !== null, fn (Builder $query): Builder => $query->where('event_id', $eventId));
|
||||
}
|
||||
|
||||
/**
|
||||
|
||||
@@ -18,3 +18,5 @@ Recurso REST `/v1/adminapp/tenant/staff`, excepto detalle individual, protegido
|
||||
## Dependencias y reglas
|
||||
|
||||
Usa `Auth/User` como entidad de personal, `Authorization` para su rol, `Catalog/Category` para asignaciones y `Tenant` para aislamiento. Toda búsqueda, edición o borrado debe comprobar que el usuario pertenece al tenant autenticado.
|
||||
|
||||
Si el administrador autenticado tiene `event_id`, el alta de scanners hereda ese valor y las búsquedas, ediciones, bajas y consultas de intentos de escaneo se limitan a personal del mismo evento. El cliente no puede elegir ni cambiar el evento. Sin `event_id`, se mantiene el alcance por tenant.
|
||||
|
||||
@@ -3,6 +3,7 @@
|
||||
namespace App\Domains\Ticketing\Event\Models;
|
||||
|
||||
use App\Domains\Commerce\Catalog\Models\CatalogItem;
|
||||
use App\Domains\Core\Client\Models\Client;
|
||||
use App\Domains\Core\Tenant\Models\SocialMedia;
|
||||
use App\Domains\Core\Tenant\Models\Tenant;
|
||||
use App\Domains\Ticketing\Ticket\Models\Ticket;
|
||||
@@ -14,14 +15,14 @@ use Illuminate\Database\Eloquent\Relations\BelongsTo;
|
||||
use Illuminate\Database\Eloquent\Relations\BelongsToMany;
|
||||
use Illuminate\Database\Eloquent\Relations\HasMany;
|
||||
|
||||
#[Fillable(['tenant_code', 'slug', 'event_category_id', 'title', 'subtitle', 'description', 'location', 'exact_location', 'date_text', 'published_at', 'attachment_id'])]
|
||||
#[Fillable(['client_id', 'tenant_code', 'slug', 'event_category_id', 'title', 'subtitle', 'description', 'location', 'exact_location', 'date_text', 'published_at', 'attachment_id'])]
|
||||
class Event extends Model
|
||||
{
|
||||
use HasFactory;
|
||||
|
||||
protected function casts(): array
|
||||
{
|
||||
return ['published_at' => 'datetime', 'exact_location' => 'array'];
|
||||
return ['client_id' => 'integer', 'published_at' => 'datetime', 'exact_location' => 'array'];
|
||||
}
|
||||
|
||||
/** @return BelongsTo<Tenant, $this> */
|
||||
@@ -30,6 +31,17 @@ class Event extends Model
|
||||
return $this->belongsTo(Tenant::class, 'tenant_code', 'codigo');
|
||||
}
|
||||
|
||||
/** @return BelongsTo<Client, $this> */
|
||||
public function client(): BelongsTo
|
||||
{
|
||||
return $this->belongsTo(Client::class);
|
||||
}
|
||||
|
||||
public function effectiveClient(): Client
|
||||
{
|
||||
return $this->client ?? $this->tenant->client;
|
||||
}
|
||||
|
||||
/** @return BelongsTo<EventCategory, $this> */
|
||||
public function eventCategory(): BelongsTo
|
||||
{
|
||||
|
||||
@@ -29,7 +29,7 @@ class TicketController extends Controller
|
||||
$tenant = $request->user()->tenant()->firstOrFail();
|
||||
|
||||
return new AdminAppTicketCollection(
|
||||
$this->ticketService->search($tenant, $request->validated())
|
||||
$this->ticketService->search($tenant, $request->validated(), $request->user()->event_id)
|
||||
);
|
||||
}
|
||||
|
||||
@@ -37,7 +37,7 @@ class TicketController extends Controller
|
||||
{
|
||||
$tenant = $request->user()->tenant()->firstOrFail();
|
||||
|
||||
return new AdminAppTicketResource($this->ticketService->cancel($tenant, $ticket));
|
||||
return new AdminAppTicketResource($this->ticketService->cancel($tenant, $ticket, $request->user()->event_id));
|
||||
}
|
||||
|
||||
public function calculateRefund(Request $request, int $ticket): AdminAppTicketRefundCalculationResource
|
||||
@@ -45,7 +45,7 @@ class TicketController extends Controller
|
||||
$tenant = $request->user()->tenant()->firstOrFail();
|
||||
|
||||
return new AdminAppTicketRefundCalculationResource(
|
||||
$this->ticketService->calculateRefund($tenant, $ticket)
|
||||
$this->ticketService->calculateRefund($tenant, $ticket, $request->user()->event_id)
|
||||
);
|
||||
}
|
||||
|
||||
@@ -69,7 +69,7 @@ class TicketController extends Controller
|
||||
|
||||
return $this->ticketPdfService->download(
|
||||
$tenant,
|
||||
$this->ticketService->ticketsForExport($tenant, $request->validated()),
|
||||
$this->ticketService->ticketsForExport($tenant, $request->validated(), $request->user()->event_id),
|
||||
$request->validated('timezone'),
|
||||
);
|
||||
}
|
||||
@@ -80,7 +80,7 @@ class TicketController extends Controller
|
||||
|
||||
return $this->ticketExcelService->download(
|
||||
$tenant,
|
||||
$this->ticketService->ticketsForExport($tenant, $request->validated()),
|
||||
$this->ticketService->ticketsForExport($tenant, $request->validated(), $request->user()->event_id),
|
||||
$request->validated('timezone'),
|
||||
);
|
||||
}
|
||||
|
||||
@@ -41,9 +41,9 @@ class AdminAppTicketService
|
||||
/**
|
||||
* @param array{q?: string|null, category?: string|null, product?: string|null, type?: string|null, date?: string|null, size?: string|null, status?: string|null, page?: int, per_page?: int, sort_by?: string|null, sort_direction?: string|null} $filters
|
||||
*/
|
||||
public function search(Tenant $tenant, array $filters = []): AdminAppTicketResult
|
||||
public function search(Tenant $tenant, array $filters = [], ?int $eventId = null): AdminAppTicketResult
|
||||
{
|
||||
$query = $this->baseQuery($tenant, $filters);
|
||||
$query = $this->baseQuery($tenant, $filters, $eventId);
|
||||
$countQuery = clone $query;
|
||||
|
||||
$databaseSorted = $this->applyDatabaseSort($query, $tenant, $filters);
|
||||
@@ -77,7 +77,7 @@ class AdminAppTicketService
|
||||
tickets: $tickets,
|
||||
scannedTickets: $scannedTickets,
|
||||
totalTickets: $totalTickets,
|
||||
refundedTotal: $this->refundSummaryService->totalForTenant($tenant),
|
||||
refundedTotal: $this->refundSummaryService->totalForTenant($tenant, $eventId),
|
||||
);
|
||||
}
|
||||
|
||||
@@ -85,9 +85,9 @@ class AdminAppTicketService
|
||||
* @param array{q?: string|null, category?: string|null, product?: string|null, type?: string|null, date?: string|null, size?: string|null, status?: string|null, sort_by?: string|null, sort_direction?: string|null} $filters
|
||||
* @return Collection<int, Ticket>
|
||||
*/
|
||||
public function ticketsForExport(Tenant $tenant, array $filters = []): Collection
|
||||
public function ticketsForExport(Tenant $tenant, array $filters = [], ?int $eventId = null): Collection
|
||||
{
|
||||
$query = $this->baseQuery($tenant, $filters);
|
||||
$query = $this->baseQuery($tenant, $filters, $eventId);
|
||||
$databaseSorted = $this->applyDatabaseSort($query, $tenant, $filters);
|
||||
$tickets = $query
|
||||
->with(self::RELATIONS)
|
||||
@@ -97,11 +97,10 @@ class AdminAppTicketService
|
||||
return $databaseSorted ? $tickets : $this->sortTickets($tickets, $tenant, $filters);
|
||||
}
|
||||
|
||||
public function cancel(Tenant $tenant, int $ticketId): Ticket
|
||||
public function cancel(Tenant $tenant, int $ticketId, ?int $eventId = null): Ticket
|
||||
{
|
||||
return DB::transaction(function () use ($tenant, $ticketId): Ticket {
|
||||
$ticket = Ticket::query()
|
||||
->where('tenant_code', $tenant->codigo)
|
||||
return DB::transaction(function () use ($tenant, $ticketId, $eventId): Ticket {
|
||||
$ticket = $this->ticketsQuery($tenant, $eventId)
|
||||
->lockForUpdate()
|
||||
->findOrFail($ticketId);
|
||||
|
||||
@@ -124,10 +123,9 @@ class AdminAppTicketService
|
||||
* partial: string|null,
|
||||
* }
|
||||
*/
|
||||
public function calculateRefund(Tenant $tenant, int $ticketId): array
|
||||
public function calculateRefund(Tenant $tenant, int $ticketId, ?int $eventId = null): array
|
||||
{
|
||||
$ticket = Ticket::query()
|
||||
->where('tenant_code', $tenant->codigo)
|
||||
$ticket = $this->ticketsQuery($tenant, $eventId)
|
||||
->findOrFail($ticketId);
|
||||
|
||||
if (! $ticket->can_refund()) {
|
||||
@@ -175,14 +173,13 @@ class AdminAppTicketService
|
||||
string $refundType,
|
||||
?User $createdBy = null,
|
||||
): Ticket {
|
||||
$this->ensureRefundIsAllowed($tenant, $refundType);
|
||||
|
||||
return DB::transaction(function () use ($tenant, $ticketId, $refundType, $createdBy): Ticket {
|
||||
$ticket = Ticket::query()
|
||||
->where('tenant_code', $tenant->codigo)
|
||||
$ticket = $this->ticketsQuery($tenant, $createdBy?->event_id)
|
||||
->lockForUpdate()
|
||||
->findOrFail($ticketId);
|
||||
|
||||
$this->ensureRefundIsAllowed($tenant, $refundType);
|
||||
|
||||
if (! $ticket->can_refund()) {
|
||||
if ($ticket->status !== Ticket::STATUS_ACTIVE) {
|
||||
throw ValidationException::withMessages([
|
||||
@@ -314,12 +311,11 @@ class AdminAppTicketService
|
||||
* @param array{q?: string|null, category?: string|null, product?: string|null, type?: string|null, date?: string|null, size?: string|null, status?: string|null, page?: int, per_page?: int} $filters
|
||||
* @return Builder<Ticket>
|
||||
*/
|
||||
private function baseQuery(Tenant $tenant, array $filters): Builder
|
||||
private function baseQuery(Tenant $tenant, array $filters, ?int $eventId = null): Builder
|
||||
{
|
||||
$search = trim((string) ($filters['q'] ?? ''));
|
||||
|
||||
$query = Ticket::query()
|
||||
->where('tenant_code', $tenant->codigo)
|
||||
$query = $this->ticketsQuery($tenant, $eventId)
|
||||
->when($search !== '', function (Builder $query) use ($search): void {
|
||||
$this->applySearchFilter($query, $search);
|
||||
})
|
||||
@@ -359,6 +355,14 @@ class AdminAppTicketService
|
||||
return $query;
|
||||
}
|
||||
|
||||
/** @return Builder<Ticket> */
|
||||
private function ticketsQuery(Tenant $tenant, ?int $eventId): Builder
|
||||
{
|
||||
return Ticket::query()
|
||||
->where('tenant_code', $tenant->codigo)
|
||||
->when($eventId !== null, fn (Builder $query): Builder => $query->where('tickets.event_id', $eventId));
|
||||
}
|
||||
|
||||
/** @param Builder<Ticket> $query */
|
||||
private function applySearchFilter(Builder $query, string $search): void
|
||||
{
|
||||
|
||||
@@ -89,6 +89,10 @@ Bajo `/v1/adminapp/tenant`, protegido por `auth:sanctum`, `adminapp.tenant` y el
|
||||
|
||||
`TicketPdfService` genera la descarga y `TicketResource`/`ValidityTimeResource` definen las respuestas.
|
||||
|
||||
Si el administrador autenticado tiene `event_id`, las consultas de Tickets y sus exportaciones se limitan a `tickets.event_id` dentro del tenant. Los contadores usan el mismo alcance y el total reembolsado se limita a las compras del evento. Sin `event_id`, se conserva el alcance por tenant.
|
||||
|
||||
La cancelación, el cálculo de reembolso y el reembolso buscan el ticket dentro de ese alcance antes de validar o ejecutar la operación. Un ticket de otro evento o sin evento devuelve 404 para un administrador con evento asignado. El alcance se obtiene del usuario autenticado, no de los parámetros del cliente.
|
||||
|
||||
## Dependencias y reglas
|
||||
|
||||
Depende de `Purchase`, `Catalog`, `Tenant` y `Auth`. La generación debe ser idempotente ante reintentos del evento. `TicketNotAvailableException` y `TicketGenerationException` separan indisponibilidad de errores de generación.
|
||||
|
||||
@@ -3,11 +3,12 @@
|
||||
namespace App\Shared\Integration\Services;
|
||||
|
||||
use App\Domains\Core\Client\Models\Client;
|
||||
use App\Domains\Core\Tenant\Models\Tenant;
|
||||
use App\Domains\Ticketing\Event\Models\Event;
|
||||
use App\Shared\Integration\Models\AdminWebsiteTypeIntegration;
|
||||
use App\Shared\Integration\Models\ClientIntegration;
|
||||
use App\Shared\Integration\Models\Integration;
|
||||
use App\Shared\Integration\Models\IntegrationInstance;
|
||||
use App\Shared\Integration\Models\AdminWebsiteTypeIntegration;
|
||||
use App\Domains\Core\Tenant\Models\Tenant;
|
||||
use Exception;
|
||||
use Illuminate\Http\Client\PendingRequest;
|
||||
use Illuminate\Support\Facades\Http;
|
||||
@@ -86,6 +87,17 @@ abstract class BaseIntegrationService
|
||||
return $this;
|
||||
}
|
||||
|
||||
public function forEvent(Event $event): self
|
||||
{
|
||||
$event->loadMissing(['client', 'tenant.client']);
|
||||
$this->tenant = $event->tenant;
|
||||
$this->tenantCode = $event->tenant_code;
|
||||
$this->clientContext = $event->effectiveClient();
|
||||
$this->loadIntegration();
|
||||
|
||||
return $this;
|
||||
}
|
||||
|
||||
/**
|
||||
* Load the integration definition and its effective instance configuration.
|
||||
*
|
||||
|
||||
@@ -3,8 +3,9 @@
|
||||
namespace App\Shared\Integration\Services;
|
||||
|
||||
use App\Domains\Core\Client\Models\Client;
|
||||
use App\Domains\Core\Tenant\Models\Tenant;
|
||||
use App\Domains\Core\Tenant\Models\AdminWebsiteType;
|
||||
use App\Domains\Core\Tenant\Models\Tenant;
|
||||
use App\Domains\Ticketing\Event\Models\Event;
|
||||
use Exception;
|
||||
use Illuminate\Contracts\Mail\Factory as MailFactory;
|
||||
use Illuminate\Contracts\Mail\Mailer;
|
||||
@@ -39,14 +40,7 @@ class MailService extends BaseIntegrationService
|
||||
public function forTenant(string $tenantCode): self
|
||||
{
|
||||
parent::forTenant($tenantCode);
|
||||
|
||||
if ($this->integrationInstance) {
|
||||
$this->mailer = $this->resolveMailer();
|
||||
$this->usesInstanceMailer = true;
|
||||
} else {
|
||||
$this->mailer = $this->mailFactory->mailer();
|
||||
$this->usesInstanceMailer = false;
|
||||
}
|
||||
$this->configureMailer();
|
||||
|
||||
return $this;
|
||||
}
|
||||
@@ -55,16 +49,30 @@ class MailService extends BaseIntegrationService
|
||||
{
|
||||
parent::forClient($client);
|
||||
$this->tenant = $this->clientContext?->tenants()->first();
|
||||
$this->configureMailer();
|
||||
|
||||
return $this;
|
||||
}
|
||||
|
||||
public function forEvent(Event $event): self
|
||||
{
|
||||
parent::forEvent($event);
|
||||
$this->configureMailer();
|
||||
|
||||
return $this;
|
||||
}
|
||||
|
||||
private function configureMailer(): void
|
||||
{
|
||||
if ($this->integrationInstance) {
|
||||
$this->mailer = $this->resolveMailer();
|
||||
$this->usesInstanceMailer = true;
|
||||
} else {
|
||||
$this->mailer = $this->mailFactory->mailer();
|
||||
$this->usesInstanceMailer = false;
|
||||
|
||||
return;
|
||||
}
|
||||
|
||||
return $this;
|
||||
$this->mailer = $this->mailFactory->mailer();
|
||||
$this->usesInstanceMailer = false;
|
||||
}
|
||||
|
||||
public function getHeaders(): array
|
||||
@@ -83,7 +91,7 @@ class MailService extends BaseIntegrationService
|
||||
array $attachments = [],
|
||||
): void {
|
||||
if (! $this->mailer || ! $this->tenant) {
|
||||
throw new Exception('MailService no está configurado. Llamá a forTenant() o forClient() primero.');
|
||||
throw new Exception('MailService no está configurado. Llamá a forTenant(), forClient() o forEvent() primero.');
|
||||
}
|
||||
|
||||
$brand ??= $this->tenant;
|
||||
@@ -160,7 +168,7 @@ class MailService extends BaseIntegrationService
|
||||
public function onSetup(): void
|
||||
{
|
||||
if (! $this->mailer || ! $this->clientContext) {
|
||||
throw new Exception('MailService no está configurado. Llamá a forTenant() o forClient() primero.');
|
||||
throw new Exception('MailService no está configurado. Llamá a forTenant(), forClient() o forEvent() primero.');
|
||||
}
|
||||
|
||||
$recipient = $this->getIntegrationSetting('MAIL_FROM_ADDRESS');
|
||||
|
||||
@@ -46,7 +46,7 @@ class TelepagosIntegrationService extends BaseIntegrationService
|
||||
public function getToken(): string
|
||||
{
|
||||
if (! $this->integrationInstance) {
|
||||
throw new Exception('Client integration is not loaded. Call forTenant() or forClient() first.');
|
||||
throw new Exception('Client integration is not loaded. Call forTenant(), forClient(), or forEvent() first.');
|
||||
}
|
||||
|
||||
$cacheKey = $this->integrationInstance->tokenCacheKey();
|
||||
|
||||
@@ -2,12 +2,12 @@
|
||||
|
||||
namespace App\Shared\Integration\Services;
|
||||
|
||||
use App\Domains\Core\Client\Models\Client;
|
||||
use App\Domains\Commerce\Purchase\Models\Purchase;
|
||||
use App\Domains\Commerce\Purchase\Models\TelepagosPayment;
|
||||
use App\Domains\Commerce\Purchase\Models\TelepagosQr;
|
||||
use App\Domains\Commerce\Purchase\Services\CheckoutService;
|
||||
use App\Domains\Commerce\Purchase\Services\DniDistanceService;
|
||||
use App\Domains\Core\Client\Models\Client;
|
||||
use Exception;
|
||||
use Illuminate\Database\Eloquent\Builder;
|
||||
use Illuminate\Database\Eloquent\Collection;
|
||||
@@ -75,9 +75,30 @@ class TelepagosWebhookService
|
||||
|
||||
$dni = substr($cuit, 2, -1);
|
||||
|
||||
$tenantCodes = $client->tenants()->pluck('codigo');
|
||||
$eligiblePurchases = Purchase::query()
|
||||
->whereIn('tenant_codigo', $tenantCodes)
|
||||
->where(function (Builder $purchases) use ($client): void {
|
||||
$purchases
|
||||
->whereHas('event', function (Builder $events) use ($client): void {
|
||||
$events
|
||||
->where('client_id', $client->id)
|
||||
->orWhere(function (Builder $fallback) use ($client): void {
|
||||
$fallback
|
||||
->whereNull('client_id')
|
||||
->whereHas(
|
||||
'tenant',
|
||||
fn (Builder $tenants): Builder => $tenants->where('client_id', $client->id),
|
||||
);
|
||||
});
|
||||
})
|
||||
->orWhere(function (Builder $legacy) use ($client): void {
|
||||
$legacy
|
||||
->whereNull('event_id')
|
||||
->whereHas(
|
||||
'tenant',
|
||||
fn (Builder $tenants): Builder => $tenants->where('client_id', $client->id),
|
||||
);
|
||||
});
|
||||
})
|
||||
->whereIn('status', [
|
||||
Purchase::STATUS_CREATED,
|
||||
Purchase::STATUS_PENDING_PAYMENT,
|
||||
@@ -170,7 +191,7 @@ class TelepagosWebhookService
|
||||
return;
|
||||
}
|
||||
|
||||
if (! $client->tenants()->where('codigo', $compra->tenant_codigo)->exists()) {
|
||||
if (! $this->purchaseBelongsToClient($compra, $client)) {
|
||||
Log::channel('telepagos')->warning('Telepagos webhook: Purchase does not belong to client.', [
|
||||
'client_code' => $client->code,
|
||||
'cashin_id' => $cashinId,
|
||||
@@ -244,6 +265,16 @@ class TelepagosWebhookService
|
||||
return number_format((float) $amount, 2, '.', '');
|
||||
}
|
||||
|
||||
private function purchaseBelongsToClient(Purchase $purchase, Client $client): bool
|
||||
{
|
||||
$purchase->loadMissing(['event.client', 'event.tenant.client', 'tenant.client']);
|
||||
|
||||
$effectiveClient = $purchase->event?->effectiveClient()
|
||||
?? $purchase->tenant?->client;
|
||||
|
||||
return $effectiveClient?->is($client) ?? false;
|
||||
}
|
||||
|
||||
/**
|
||||
* @param Builder<Purchase> $eligiblePurchases
|
||||
* @return Collection<int, Purchase>
|
||||
|
||||
@@ -2,16 +2,16 @@
|
||||
|
||||
namespace App\Shared\Notification\Services;
|
||||
|
||||
use App\Domains\Commerce\Purchase\Models\Purchase;
|
||||
use App\Domains\Core\Auth\Models\ResetPasswordAttempt;
|
||||
use App\Domains\Core\Auth\Models\User;
|
||||
use App\Shared\Integration\Services\MailService;
|
||||
use App\Shared\Notification\Events\PasswordResetRequested;
|
||||
use App\Domains\Commerce\Purchase\Models\Purchase;
|
||||
use App\Domains\Core\Tenant\Models\Tenant;
|
||||
use App\Domains\Ticketing\Ticket\Models\Ticket;
|
||||
use App\Domains\Ticketing\Ticket\Services\TicketPdfService;
|
||||
use App\Domains\Ticketing\Ticket\Services\TicketPresentationResolver;
|
||||
use App\Domains\Ticketing\Ticket\Services\TicketValidityResolver;
|
||||
use App\Shared\Integration\Services\MailService;
|
||||
use App\Shared\Notification\Events\PasswordResetRequested;
|
||||
use Closure;
|
||||
use Illuminate\Support\Collection;
|
||||
use Illuminate\Support\Facades\Log;
|
||||
@@ -158,7 +158,7 @@ class NotificationMailService
|
||||
$context = ['purchase_id' => $purchaseId];
|
||||
|
||||
$purchase = Purchase::query()
|
||||
->with(['tenant', 'user', 'items'])
|
||||
->with(['event', 'tenant', 'user', 'items'])
|
||||
->find($purchaseId);
|
||||
|
||||
if ($purchase === null) {
|
||||
@@ -197,8 +197,7 @@ class NotificationMailService
|
||||
'mime' => 'application/pdf',
|
||||
]];
|
||||
|
||||
$this->mailService
|
||||
->forTenant($purchase->tenant_codigo)
|
||||
$this->mailForPurchase($purchase)
|
||||
->send(
|
||||
$recipient,
|
||||
"Compra confirmada - Compra #{$purchase->getKey()}",
|
||||
@@ -286,7 +285,6 @@ class NotificationMailService
|
||||
$context,
|
||||
$recipient,
|
||||
function () use (
|
||||
$tenantCode,
|
||||
$purchase,
|
||||
$recipient,
|
||||
$previousDate,
|
||||
@@ -295,8 +293,7 @@ class NotificationMailService
|
||||
): array {
|
||||
$brand = $purchase->tenant;
|
||||
|
||||
$this->mailService
|
||||
->forTenant($tenantCode)
|
||||
$this->mailForPurchase($purchase)
|
||||
->send(
|
||||
$recipient,
|
||||
"Tu evento fue reprogramado - N° de Orden #{$purchase->getKey()}",
|
||||
@@ -387,7 +384,6 @@ class NotificationMailService
|
||||
$context,
|
||||
$recipient,
|
||||
function () use (
|
||||
$tenantCode,
|
||||
$purchase,
|
||||
$recipient,
|
||||
$date,
|
||||
@@ -396,8 +392,7 @@ class NotificationMailService
|
||||
): array {
|
||||
$brand = $purchase->tenant;
|
||||
|
||||
$this->mailService
|
||||
->forTenant($tenantCode)
|
||||
$this->mailForPurchase($purchase)
|
||||
->send(
|
||||
$recipient,
|
||||
"Una fecha de tu evento fue suspendida - N° de Orden #{$purchase->getKey()}",
|
||||
@@ -421,10 +416,17 @@ class NotificationMailService
|
||||
{
|
||||
return Purchase::query()
|
||||
->where('tenant_codigo', $tenantCode)
|
||||
->with(['tenant', 'user'])
|
||||
->with(['event', 'tenant', 'user'])
|
||||
->find($purchaseId);
|
||||
}
|
||||
|
||||
private function mailForPurchase(Purchase $purchase): MailService
|
||||
{
|
||||
return $purchase->event
|
||||
? $this->mailService->forEvent($purchase->event)
|
||||
: $this->mailService->forTenant($purchase->tenant_codigo);
|
||||
}
|
||||
|
||||
private function recipientFor(Purchase $purchase): string
|
||||
{
|
||||
return (string) ($purchase->email ?: $purchase->user?->email);
|
||||
|
||||
@@ -0,0 +1,26 @@
|
||||
<?php
|
||||
|
||||
use Illuminate\Database\Migrations\Migration;
|
||||
use Illuminate\Database\Schema\Blueprint;
|
||||
use Illuminate\Support\Facades\Schema;
|
||||
|
||||
return new class extends Migration
|
||||
{
|
||||
public function up(): void
|
||||
{
|
||||
Schema::table('events', function (Blueprint $table): void {
|
||||
$table->foreignId('client_id')
|
||||
->nullable()
|
||||
->after('id')
|
||||
->constrained('clients')
|
||||
->restrictOnDelete();
|
||||
});
|
||||
}
|
||||
|
||||
public function down(): void
|
||||
{
|
||||
Schema::table('events', function (Blueprint $table): void {
|
||||
$table->dropConstrainedForeignId('client_id');
|
||||
});
|
||||
}
|
||||
};
|
||||
@@ -0,0 +1,44 @@
|
||||
<?php
|
||||
|
||||
use Illuminate\Database\Migrations\Migration;
|
||||
use Illuminate\Database\Schema\Blueprint;
|
||||
use Illuminate\Support\Facades\DB;
|
||||
use Illuminate\Support\Facades\Schema;
|
||||
|
||||
return new class extends Migration
|
||||
{
|
||||
public function up(): void
|
||||
{
|
||||
Schema::table('compras', function (Blueprint $table): void {
|
||||
$table->foreignId('event_id')
|
||||
->nullable()
|
||||
->after('tenant_codigo')
|
||||
->constrained('events')
|
||||
->nullOnDelete();
|
||||
});
|
||||
|
||||
DB::table('compras')
|
||||
->orderBy('id')
|
||||
->each(function (object $purchase): void {
|
||||
$eventIds = DB::table('compra_items')
|
||||
->join('catalog_items', 'catalog_items.id', '=', 'compra_items.source_catalog_item_id')
|
||||
->where('compra_items.compra_id', $purchase->id)
|
||||
->whereNotNull('catalog_items.event_id')
|
||||
->distinct()
|
||||
->pluck('catalog_items.event_id');
|
||||
|
||||
if ($eventIds->count() === 1) {
|
||||
DB::table('compras')
|
||||
->where('id', $purchase->id)
|
||||
->update(['event_id' => $eventIds->first()]);
|
||||
}
|
||||
});
|
||||
}
|
||||
|
||||
public function down(): void
|
||||
{
|
||||
Schema::table('compras', function (Blueprint $table): void {
|
||||
$table->dropConstrainedForeignId('event_id');
|
||||
});
|
||||
}
|
||||
};
|
||||
@@ -0,0 +1,42 @@
|
||||
<?php
|
||||
|
||||
use Illuminate\Database\Migrations\Migration;
|
||||
use Illuminate\Support\Facades\DB;
|
||||
|
||||
return new class extends Migration
|
||||
{
|
||||
private const EVENT_TITLE = '26.º Fiesta de la Tradición y 4.º Encuentro de Agrupaciones Gauchas';
|
||||
|
||||
public function up(): void
|
||||
{
|
||||
$clientId = DB::table('clients')
|
||||
->where('code', 'pyme_rural')
|
||||
->value('id');
|
||||
|
||||
if ($clientId === null) {
|
||||
return;
|
||||
}
|
||||
|
||||
DB::table('events')
|
||||
->where('tenant_code', 'onticket')
|
||||
->where('title', self::EVENT_TITLE)
|
||||
->update(['client_id' => $clientId]);
|
||||
}
|
||||
|
||||
public function down(): void
|
||||
{
|
||||
$clientId = DB::table('clients')
|
||||
->where('code', 'pyme_rural')
|
||||
->value('id');
|
||||
|
||||
if ($clientId === null) {
|
||||
return;
|
||||
}
|
||||
|
||||
DB::table('events')
|
||||
->where('tenant_code', 'onticket')
|
||||
->where('title', self::EVENT_TITLE)
|
||||
->where('client_id', $clientId)
|
||||
->update(['client_id' => null]);
|
||||
}
|
||||
};
|
||||
@@ -0,0 +1,28 @@
|
||||
<?php
|
||||
|
||||
use Illuminate\Database\Migrations\Migration;
|
||||
use Illuminate\Database\Schema\Blueprint;
|
||||
use Illuminate\Support\Facades\Schema;
|
||||
|
||||
return new class extends Migration
|
||||
{
|
||||
public function up(): void
|
||||
{
|
||||
Schema::table('users', function (Blueprint $table): void {
|
||||
$table->foreignId('event_id')
|
||||
->nullable()
|
||||
->after('tenant_codigo')
|
||||
->constrained('events')
|
||||
->cascadeOnUpdate()
|
||||
->restrictOnDelete();
|
||||
});
|
||||
}
|
||||
|
||||
public function down(): void
|
||||
{
|
||||
Schema::table('users', function (Blueprint $table): void {
|
||||
$table->dropForeign(['event_id']);
|
||||
$table->dropColumn('event_id');
|
||||
});
|
||||
}
|
||||
};
|
||||
@@ -6,6 +6,7 @@ use App\Domains\Commerce\Catalog\Enums\InventoryPolicy;
|
||||
use App\Domains\Commerce\Catalog\Models\Attribute;
|
||||
use App\Domains\Commerce\Catalog\Models\CatalogItem;
|
||||
use App\Domains\Commerce\Catalog\Services\CatalogService;
|
||||
use App\Domains\Core\Client\Models\Client;
|
||||
use App\Domains\Core\Tenant\Models\Tenant;
|
||||
use App\Domains\Ticketing\Event\Models\Event;
|
||||
use App\Shared\Attachable\Services\AttachmentService;
|
||||
@@ -35,6 +36,12 @@ class FiestaTradicionArrufoSeeder extends Seeder
|
||||
throw new RuntimeException("Tenant 'onticket' no encontrado.");
|
||||
}
|
||||
|
||||
$client = Client::query()->where('code', 'pyme_rural')->first();
|
||||
|
||||
if ($client === null) {
|
||||
throw new RuntimeException("Client 'pyme_rural' no encontrado.");
|
||||
}
|
||||
|
||||
Attribute::query()->firstOrCreate(
|
||||
['tenant_codigo' => $tenant->codigo, 'codigo' => 'event_date'],
|
||||
['nombre' => 'Fecha', 'type' => FieldType::EventDate, 'is_required' => true],
|
||||
@@ -45,6 +52,7 @@ class FiestaTradicionArrufoSeeder extends Seeder
|
||||
['published_at' => now()],
|
||||
);
|
||||
$event->update([
|
||||
'client_id' => $client->id,
|
||||
'subtitle' => 'Una noche para celebrar nuestras raíces y mantener viva la tradición gaucha.',
|
||||
'description' => 'La 26.º Fiesta de la Tradición y 4.º Encuentro de Agrupaciones Gauchas reunirá a agrupaciones, artesanos, pilcheros y público en general para compartir una jornada dedicada a nuestras costumbres y cultura.'
|
||||
."\n\n".'Un encuentro para disfrutar de la tradición, la identidad gaucha y el espíritu de camaradería, en el Predio de Doma del Club Unión Deportiva Arrufó.'
|
||||
|
||||
@@ -17,6 +17,7 @@ class UserAuthorizationRelationsTest extends TestCase
|
||||
$this->assertTrue(Schema::hasColumns('users', [
|
||||
'rol_codigo',
|
||||
'tenant_codigo',
|
||||
'event_id',
|
||||
]));
|
||||
}
|
||||
|
||||
@@ -28,5 +29,7 @@ class UserAuthorizationRelationsTest extends TestCase
|
||||
$this->assertNull($user->tenant_codigo);
|
||||
$this->assertSame(RoleCode::User->value, $user->role->codigo);
|
||||
$this->assertNull($user->tenant);
|
||||
$this->assertNull($user->event_id);
|
||||
$this->assertNull($user->event);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -2,20 +2,22 @@
|
||||
|
||||
namespace Tests\Feature\Integration;
|
||||
|
||||
use App\Shared\Attachable\Enums\AttachmentType;
|
||||
use App\Shared\Attachable\Models\Attachment;
|
||||
use App\Domains\Core\Auth\Models\User;
|
||||
use App\Domains\Commerce\Cart\Models\Cart;
|
||||
use App\Domains\Commerce\Catalog\Enums\InventoryPolicy;
|
||||
use App\Domains\Commerce\Catalog\Models\CatalogItem;
|
||||
use App\Domains\Commerce\Catalog\Models\Category;
|
||||
use App\Domains\Commerce\Catalog\Models\Inventory;
|
||||
use App\Domains\Commerce\Catalog\Models\Variant;
|
||||
use App\Shared\Integration\Models\Integration;
|
||||
use App\Domains\Commerce\Purchase\Models\Purchase;
|
||||
use App\Domains\Commerce\Purchase\Models\TelepagosPayment;
|
||||
use App\Domains\Commerce\Purchase\Services\CheckoutService;
|
||||
use App\Domains\Core\Auth\Models\User;
|
||||
use App\Domains\Core\Client\Models\Client;
|
||||
use App\Domains\Core\Tenant\Models\Tenant;
|
||||
use App\Domains\Ticketing\Event\Models\Event;
|
||||
use App\Shared\Attachable\Enums\AttachmentType;
|
||||
use App\Shared\Attachable\Models\Attachment;
|
||||
use App\Shared\Integration\Models\Integration;
|
||||
use Illuminate\Foundation\Testing\RefreshDatabase;
|
||||
use Illuminate\Support\Facades\Cache;
|
||||
use Illuminate\Support\Facades\Http;
|
||||
@@ -227,6 +229,77 @@ class TelepagosWebhookTest extends TestCase
|
||||
]);
|
||||
}
|
||||
|
||||
public function test_transfer_webhook_matches_the_client_configured_on_the_event(): void
|
||||
{
|
||||
$tenant = $this->createTenant('multi-event', 'Multi Event', 'multi-event.com.ar');
|
||||
$eventClient = Client::query()->create([
|
||||
'code' => 'event-client',
|
||||
'name' => 'Event Client',
|
||||
]);
|
||||
Integration::query()->create([
|
||||
'integration_code' => 'telepagos_homo',
|
||||
'name' => 'Telepagos',
|
||||
'url' => 'https://api.telepagos.com.ar',
|
||||
'integration_data_schema' => [
|
||||
'username' => 'required|string',
|
||||
'password' => 'required|string',
|
||||
],
|
||||
]);
|
||||
$this->createClientIntegration([
|
||||
'client_id' => $eventClient->id,
|
||||
'integration_code' => 'telepagos_homo',
|
||||
'integration_data' => ['username' => 'event-user', 'password' => 'event-password'],
|
||||
]);
|
||||
$event = Event::query()->create([
|
||||
'client_id' => $eventClient->id,
|
||||
'tenant_code' => $tenant->codigo,
|
||||
'title' => 'Event with its own client',
|
||||
]);
|
||||
$tenant->update(['active_event_id' => $event->id]);
|
||||
|
||||
$user = User::factory()->create();
|
||||
$variant = $this->createVariantForTenant($tenant->codigo, 10, '50.00');
|
||||
$purchase = $this->createPendingTransferPurchase(
|
||||
$tenant,
|
||||
$user->id,
|
||||
$variant->id,
|
||||
1,
|
||||
'12345678',
|
||||
);
|
||||
|
||||
Http::fake([
|
||||
'https://api.telepagos.com.ar/v2/auth/token' => Http::response([
|
||||
'status' => 'ok',
|
||||
'token' => 'event-client-token',
|
||||
'expires_at' => now()->addHour()->toIso8601String(),
|
||||
]),
|
||||
'https://api.telepagos.com.ar/v2/payment/cashin/event-client-payment' => Http::response([
|
||||
'status' => 'ok',
|
||||
'data' => [
|
||||
'amount' => 50,
|
||||
'operation_id' => 1,
|
||||
'transaction_id' => 'tx-event-client',
|
||||
'buyer' => ['cuit' => '20123456789'],
|
||||
],
|
||||
]),
|
||||
]);
|
||||
|
||||
$this->postJson('/api/webhooks/telepagos/event-client', [
|
||||
'id' => 'event-client-payment',
|
||||
])->assertOk()->assertJsonPath('status', 'success');
|
||||
|
||||
$this->assertSame($event->id, $purchase->event_id);
|
||||
$this->assertDatabaseHas('compras', [
|
||||
'id' => $purchase->id,
|
||||
'event_id' => $event->id,
|
||||
'status' => Purchase::STATUS_PAID,
|
||||
]);
|
||||
$this->assertDatabaseHas('telepagos_payments', [
|
||||
'compra_id' => $purchase->id,
|
||||
'transaction_id' => 'tx-event-client',
|
||||
]);
|
||||
}
|
||||
|
||||
public function test_transfer_webhook_buys_unlimited_inventory_without_reducing_real_stock(): void
|
||||
{
|
||||
$tenant = $this->createTenant('unlimited', 'Unlimited', 'unlimited.com.ar');
|
||||
|
||||
76
tests/Feature/Menu/TicketMenuAccessTest.php
Normal file
76
tests/Feature/Menu/TicketMenuAccessTest.php
Normal file
@@ -0,0 +1,76 @@
|
||||
<?php
|
||||
|
||||
namespace Tests\Feature\Menu;
|
||||
|
||||
use App\Domains\Core\Auth\Models\User;
|
||||
use App\Http\Middleware\EnsureTenantHasMenu;
|
||||
use Illuminate\Database\Schema\Blueprint;
|
||||
use Illuminate\Http\Request;
|
||||
use Illuminate\Support\Facades\DB;
|
||||
use Illuminate\Support\Facades\Route;
|
||||
use Illuminate\Support\Facades\Schema;
|
||||
use PHPUnit\Framework\Attributes\DataProvider;
|
||||
use Symfony\Component\HttpKernel\Exception\HttpException;
|
||||
use Tests\TestCase;
|
||||
|
||||
class TicketMenuAccessTest extends TestCase
|
||||
{
|
||||
public static function menuAssignments(): array
|
||||
{
|
||||
return [
|
||||
'new code' => ['onticket.adminapp.tickets', 'current', false],
|
||||
'old code' => ['adminapp.tickets', 'current', true],
|
||||
'another tenant' => ['adminapp.tickets', 'other', false],
|
||||
'unrelated menu' => ['adminapp.ventas', 'current', false],
|
||||
];
|
||||
}
|
||||
|
||||
#[DataProvider('menuAssignments')]
|
||||
public function test_ticket_menu_requires_an_association_with_the_authenticated_tenant(string $menuCode, string $assignedTenant, bool $allowed): void
|
||||
{
|
||||
Schema::create('tenants', function (Blueprint $table): void {
|
||||
$table->id();
|
||||
$table->string('codigo');
|
||||
});
|
||||
Schema::create('menues', function (Blueprint $table): void {
|
||||
$table->id();
|
||||
$table->string('code');
|
||||
});
|
||||
Schema::create('tenants_menues', function (Blueprint $table): void {
|
||||
$table->string('tenant_code');
|
||||
$table->string('menu_code');
|
||||
});
|
||||
DB::table('tenants')->insert(['codigo' => 'current']);
|
||||
DB::table('menues')->insert(['code' => $menuCode]);
|
||||
DB::table('tenants_menues')->insert(['tenant_code' => $assignedTenant, 'menu_code' => $menuCode]);
|
||||
|
||||
$user = new User(['tenant_codigo' => 'current']);
|
||||
$request = Request::create('/api/v1/adminapp/tenant/tickets');
|
||||
$request->setUserResolver(fn () => $user);
|
||||
if (! $allowed) {
|
||||
$this->expectException(HttpException::class);
|
||||
$this->expectExceptionCode(0);
|
||||
}
|
||||
|
||||
try {
|
||||
$response = (new EnsureTenantHasMenu)->handle($request, fn () => response('allowed'), 'adminapp.tickets');
|
||||
$this->assertSame('allowed', $response->getContent());
|
||||
} catch (HttpException $exception) {
|
||||
$this->assertSame(404, $exception->getStatusCode());
|
||||
throw $exception;
|
||||
}
|
||||
}
|
||||
|
||||
public function test_all_ticket_routes_and_filter_form_use_the_updated_menu_codes(): void
|
||||
{
|
||||
foreach ([
|
||||
'adminapp.tickets.index', 'adminapp.tickets.cancel',
|
||||
'adminapp.tickets.calculate-refund', 'adminapp.tickets.refund',
|
||||
'adminapp.tickets.pdf', 'adminapp.tickets.excel', 'adminapp.forms.tickets-filter',
|
||||
] as $name) {
|
||||
$route = Route::getRoutes()->getByName($name);
|
||||
$this->assertNotNull($route);
|
||||
$this->assertContains('tenant.menu:adminapp.tickets', $route->gatherMiddleware());
|
||||
}
|
||||
}
|
||||
}
|
||||
57
tests/Feature/Migrations/AddClientIdToEventsTest.php
Normal file
57
tests/Feature/Migrations/AddClientIdToEventsTest.php
Normal file
@@ -0,0 +1,57 @@
|
||||
<?php
|
||||
|
||||
namespace Tests\Feature\Migrations;
|
||||
|
||||
use App\Domains\Core\Client\Models\Client;
|
||||
use App\Domains\Ticketing\Event\Models\Event;
|
||||
use Illuminate\Database\Schema\Blueprint;
|
||||
use Illuminate\Support\Facades\DB;
|
||||
use Illuminate\Support\Facades\Schema;
|
||||
use Tests\TestCase;
|
||||
|
||||
class AddClientIdToEventsTest extends TestCase
|
||||
{
|
||||
public function test_event_client_overrides_the_tenant_client_when_configured(): void
|
||||
{
|
||||
Schema::create('clients', function (Blueprint $table): void {
|
||||
$table->id();
|
||||
$table->string('code');
|
||||
$table->string('name');
|
||||
});
|
||||
Schema::create('tenants', function (Blueprint $table): void {
|
||||
$table->id();
|
||||
$table->foreignId('client_id');
|
||||
$table->string('codigo');
|
||||
});
|
||||
Schema::create('events', function (Blueprint $table): void {
|
||||
$table->id();
|
||||
$table->string('tenant_code');
|
||||
$table->string('title');
|
||||
$table->timestamps();
|
||||
});
|
||||
|
||||
DB::table('clients')->insert([
|
||||
['id' => 10, 'code' => 'tenant-client', 'name' => 'Tenant Client'],
|
||||
['id' => 11, 'code' => 'event-client', 'name' => 'Event Client'],
|
||||
]);
|
||||
DB::table('tenants')->insert(['id' => 20, 'client_id' => 10, 'codigo' => 'tenant']);
|
||||
DB::table('events')->insert([
|
||||
'id' => 30,
|
||||
'tenant_code' => 'tenant',
|
||||
'title' => 'Event',
|
||||
'created_at' => now(),
|
||||
'updated_at' => now(),
|
||||
]);
|
||||
|
||||
$migration = require database_path('migrations/2026_09_28_000000_add_client_id_to_events.php');
|
||||
$migration->up();
|
||||
|
||||
$event = Event::query()->findOrFail(30);
|
||||
$this->assertSame(10, $event->effectiveClient()->id);
|
||||
|
||||
$event->update(['client_id' => 11]);
|
||||
|
||||
$this->assertSame(11, $event->fresh()->effectiveClient()->id);
|
||||
$this->assertTrue(Client::query()->findOrFail(11)->events()->whereKey(30)->exists());
|
||||
}
|
||||
}
|
||||
44
tests/Feature/Migrations/AddEventIdToPurchasesTest.php
Normal file
44
tests/Feature/Migrations/AddEventIdToPurchasesTest.php
Normal file
@@ -0,0 +1,44 @@
|
||||
<?php
|
||||
|
||||
namespace Tests\Feature\Migrations;
|
||||
|
||||
use Illuminate\Database\Schema\Blueprint;
|
||||
use Illuminate\Support\Facades\DB;
|
||||
use Illuminate\Support\Facades\Schema;
|
||||
use Tests\TestCase;
|
||||
|
||||
class AddEventIdToPurchasesTest extends TestCase
|
||||
{
|
||||
public function test_it_backfills_the_event_from_purchase_items(): void
|
||||
{
|
||||
Schema::create('events', fn (Blueprint $table) => $table->id());
|
||||
Schema::create('compras', fn (Blueprint $table) => $table->id());
|
||||
Schema::create('catalog_items', function (Blueprint $table): void {
|
||||
$table->id();
|
||||
$table->foreignId('event_id')->nullable();
|
||||
});
|
||||
Schema::create('compra_items', function (Blueprint $table): void {
|
||||
$table->id();
|
||||
$table->foreignId('compra_id');
|
||||
$table->foreignId('source_catalog_item_id');
|
||||
});
|
||||
|
||||
DB::table('events')->insert([['id' => 10], ['id' => 11]]);
|
||||
DB::table('compras')->insert([['id' => 20], ['id' => 21]]);
|
||||
DB::table('catalog_items')->insert([
|
||||
['id' => 30, 'event_id' => 10],
|
||||
['id' => 31, 'event_id' => 11],
|
||||
]);
|
||||
DB::table('compra_items')->insert([
|
||||
['compra_id' => 20, 'source_catalog_item_id' => 30],
|
||||
['compra_id' => 21, 'source_catalog_item_id' => 30],
|
||||
['compra_id' => 21, 'source_catalog_item_id' => 31],
|
||||
]);
|
||||
|
||||
$migration = require database_path('migrations/2026_09_28_000100_add_event_id_to_compras.php');
|
||||
$migration->up();
|
||||
|
||||
$this->assertDatabaseHas('compras', ['id' => 20, 'event_id' => 10]);
|
||||
$this->assertDatabaseHas('compras', ['id' => 21, 'event_id' => null]);
|
||||
}
|
||||
}
|
||||
57
tests/Feature/Migrations/AddEventIdToUsersTest.php
Normal file
57
tests/Feature/Migrations/AddEventIdToUsersTest.php
Normal file
@@ -0,0 +1,57 @@
|
||||
<?php
|
||||
|
||||
namespace Tests\Feature\Migrations;
|
||||
|
||||
use App\Domains\Core\Administrator\Resources\AdministratorResource;
|
||||
use App\Domains\Core\Auth\Models\User;
|
||||
use App\Domains\Core\Auth\Resources\UserResource;
|
||||
use Illuminate\Database\QueryException;
|
||||
use Illuminate\Database\Schema\Blueprint;
|
||||
use Illuminate\Http\Request;
|
||||
use Illuminate\Support\Facades\DB;
|
||||
use Illuminate\Support\Facades\Schema;
|
||||
use Tests\TestCase;
|
||||
|
||||
class AddEventIdToUsersTest extends TestCase
|
||||
{
|
||||
public function test_event_assignment_preserves_existing_users_and_restricts_event_deletion(): void
|
||||
{
|
||||
Schema::create('events', function (Blueprint $table): void {
|
||||
$table->id();
|
||||
});
|
||||
Schema::create('users', function (Blueprint $table): void {
|
||||
$table->id();
|
||||
$table->string('tenant_codigo')->nullable();
|
||||
$table->softDeletes();
|
||||
$table->timestamps();
|
||||
});
|
||||
DB::table('users')->insert(['id' => 1, 'tenant_codigo' => 'legacy']);
|
||||
DB::table('events')->insert(['id' => 42]);
|
||||
|
||||
$migration = require database_path('migrations/2026_10_01_000000_add_event_id_to_users_table.php');
|
||||
$migration->up();
|
||||
|
||||
$legacy = User::query()->findOrFail(1);
|
||||
$this->assertNull($legacy->event_id);
|
||||
$this->assertNull($legacy->event);
|
||||
$this->assertSame('legacy', $legacy->tenant_codigo);
|
||||
|
||||
$legacy->update(['event_id' => '42']);
|
||||
$user = $legacy->fresh();
|
||||
$this->assertSame(42, $user->event_id);
|
||||
$this->assertSame(42, $user->event->id);
|
||||
$this->assertSame(42, UserResource::make($user)->resolve(new Request)['event_id']);
|
||||
$this->assertSame(42, AdministratorResource::make($user)->resolve(new Request)['event_id']);
|
||||
|
||||
try {
|
||||
DB::table('events')->where('id', 42)->delete();
|
||||
$this->fail('An assigned event must not be deleted.');
|
||||
} catch (QueryException $exception) {
|
||||
$this->assertStringContainsString('FOREIGN KEY', $exception->getMessage());
|
||||
}
|
||||
|
||||
$migration->down();
|
||||
$this->assertFalse(Schema::hasColumn('users', 'event_id'));
|
||||
$this->assertSame('legacy', DB::table('users')->where('id', 1)->value('tenant_codigo'));
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,50 @@
|
||||
<?php
|
||||
|
||||
namespace Tests\Feature\Migrations;
|
||||
|
||||
use Illuminate\Database\Schema\Blueprint;
|
||||
use Illuminate\Support\Facades\DB;
|
||||
use Illuminate\Support\Facades\Schema;
|
||||
use Tests\TestCase;
|
||||
|
||||
class AssignArrufoEventToPymeRuralClientTest extends TestCase
|
||||
{
|
||||
public function test_it_assigns_only_the_arrufo_event_to_pyme_rural(): void
|
||||
{
|
||||
Schema::create('clients', function (Blueprint $table): void {
|
||||
$table->id();
|
||||
$table->string('code');
|
||||
});
|
||||
Schema::create('events', function (Blueprint $table): void {
|
||||
$table->id();
|
||||
$table->foreignId('client_id')->nullable();
|
||||
$table->string('tenant_code');
|
||||
$table->string('title');
|
||||
});
|
||||
|
||||
DB::table('clients')->insert([
|
||||
['id' => 10, 'code' => 'pyme_rural'],
|
||||
['id' => 11, 'code' => 'onticket'],
|
||||
]);
|
||||
DB::table('events')->insert([
|
||||
[
|
||||
'id' => 20,
|
||||
'client_id' => null,
|
||||
'tenant_code' => 'onticket',
|
||||
'title' => '26.º Fiesta de la Tradición y 4.º Encuentro de Agrupaciones Gauchas',
|
||||
],
|
||||
[
|
||||
'id' => 21,
|
||||
'client_id' => 11,
|
||||
'tenant_code' => 'onticket',
|
||||
'title' => 'Otro evento',
|
||||
],
|
||||
]);
|
||||
|
||||
$migration = require database_path('migrations/2026_09_28_000200_assign_arrufo_event_to_pyme_rural_client.php');
|
||||
$migration->up();
|
||||
|
||||
$this->assertDatabaseHas('events', ['id' => 20, 'client_id' => 10]);
|
||||
$this->assertDatabaseHas('events', ['id' => 21, 'client_id' => 11]);
|
||||
}
|
||||
}
|
||||
183
tests/Feature/Sale/AdminAppSaleEventScopeTest.php
Normal file
183
tests/Feature/Sale/AdminAppSaleEventScopeTest.php
Normal file
@@ -0,0 +1,183 @@
|
||||
<?php
|
||||
|
||||
namespace Tests\Feature\Sale;
|
||||
|
||||
use App\Domains\Commerce\Purchase\Models\Purchase;
|
||||
use App\Domains\Commerce\Purchase\Services\CheckoutService;
|
||||
use App\Domains\Commerce\Sale\Services\AdminAppSaleExcelService;
|
||||
use App\Domains\Commerce\Sale\Services\AdminAppSalePdfService;
|
||||
use App\Domains\Core\Auth\Models\User;
|
||||
use App\Domains\Core\Authorization\Enums\RoleCode;
|
||||
use Illuminate\Database\Schema\Blueprint;
|
||||
use Illuminate\Support\Collection;
|
||||
use Illuminate\Support\Facades\DB;
|
||||
use Illuminate\Support\Facades\Schema;
|
||||
use Laravel\Sanctum\Sanctum;
|
||||
use Mockery\MockInterface;
|
||||
use Symfony\Component\HttpFoundation\StreamedResponse;
|
||||
use Tests\TestCase;
|
||||
|
||||
class AdminAppSaleEventScopeTest extends TestCase
|
||||
{
|
||||
protected function setUp(): void
|
||||
{
|
||||
parent::setUp();
|
||||
|
||||
// Isolated schema: the full legacy migration chain cannot run on SQLite.
|
||||
Schema::create('tenants', function (Blueprint $table): void {
|
||||
$table->id();
|
||||
$table->string('codigo');
|
||||
});
|
||||
Schema::create('users', function (Blueprint $table): void {
|
||||
$table->id();
|
||||
$table->softDeletes();
|
||||
});
|
||||
Schema::create('compras', function (Blueprint $table): void {
|
||||
$table->id();
|
||||
$table->string('tenant_codigo');
|
||||
$table->unsignedBigInteger('event_id')->nullable();
|
||||
$table->string('nombre_apellido');
|
||||
$table->string('status');
|
||||
$table->decimal('total', 12, 2);
|
||||
$table->timestamps();
|
||||
});
|
||||
Schema::create('compra_items', function (Blueprint $table): void {
|
||||
$table->id();
|
||||
$table->unsignedBigInteger('compra_id');
|
||||
$table->integer('cantidad');
|
||||
});
|
||||
Schema::create('tickets', function (Blueprint $table): void {
|
||||
$table->id();
|
||||
$table->unsignedBigInteger('source_purchase_item_id');
|
||||
});
|
||||
Schema::create('ticket_refunds', function (Blueprint $table): void {
|
||||
$table->id();
|
||||
$table->unsignedBigInteger('purchase_item_id');
|
||||
$table->decimal('amount', 12, 2);
|
||||
});
|
||||
Schema::create('value_changes', function (Blueprint $table): void {
|
||||
$table->id();
|
||||
$table->string('tenant_code');
|
||||
$table->string('trackable_type');
|
||||
$table->unsignedBigInteger('trackable_id');
|
||||
$table->string('attribute');
|
||||
$table->string('old_value');
|
||||
$table->string('new_value');
|
||||
$table->timestamp('changed_at');
|
||||
$table->string('actor_type');
|
||||
$table->unsignedBigInteger('user_id')->nullable();
|
||||
});
|
||||
|
||||
DB::table('tenants')->insert(['codigo' => 'onticket']);
|
||||
foreach ([1 => ['onticket', 10], 2 => ['onticket', 20], 3 => ['onticket', null], 4 => ['other', 10]] as $id => [$tenant, $event]) {
|
||||
DB::table('compras')->insert([
|
||||
'id' => $id,
|
||||
'tenant_codigo' => $tenant,
|
||||
'event_id' => $event,
|
||||
'nombre_apellido' => 'Cliente',
|
||||
'status' => Purchase::STATUS_PAID,
|
||||
'total' => $id * 100,
|
||||
'created_at' => now(),
|
||||
'updated_at' => now(),
|
||||
]);
|
||||
DB::table('compra_items')->insert(['id' => $id, 'compra_id' => $id, 'cantidad' => 1]);
|
||||
DB::table('ticket_refunds')->insert(['purchase_item_id' => $id, 'amount' => $id * 10]);
|
||||
DB::table('value_changes')->insert([
|
||||
'id' => $id,
|
||||
'tenant_code' => $tenant,
|
||||
'trackable_type' => (new Purchase)->getMorphClass(),
|
||||
'trackable_id' => $id,
|
||||
'attribute' => 'status',
|
||||
'old_value' => Purchase::STATUS_PENDING_PAYMENT,
|
||||
'new_value' => Purchase::STATUS_PAID,
|
||||
'changed_at' => now(),
|
||||
'actor_type' => 'system',
|
||||
]);
|
||||
}
|
||||
$this->actingAsAdministrator(10);
|
||||
}
|
||||
|
||||
public function test_list_totals_and_filters_cannot_escape_the_authenticated_event(): void
|
||||
{
|
||||
$this->getJson('/api/v1/adminapp/tenant/sales?event_id=20&q=Cliente')
|
||||
->assertOk()
|
||||
->assertJsonCount(1, 'data')
|
||||
->assertJsonPath('data.0.id', 1)
|
||||
->assertJsonPath('confirmed_sales_total', '100.00')
|
||||
->assertJsonPath('refunded_total', '10.00');
|
||||
$this->getJson('/api/v1/adminapp/tenant/sales?id=2')->assertOk()->assertJsonCount(0, 'data');
|
||||
$this->getJson('/api/v1/adminapp/tenant/sales/modifications?q=Cliente')
|
||||
->assertOk()->assertJsonCount(1, 'data')->assertJsonPath('data.0.sale_id', 1);
|
||||
}
|
||||
|
||||
public function test_unscoped_administrators_keep_access_to_all_sales_in_their_tenant(): void
|
||||
{
|
||||
$this->actingAsAdministrator(null);
|
||||
$this->getJson('/api/v1/adminapp/tenant/sales')->assertOk()->assertJsonCount(3, 'data')
|
||||
->assertJsonPath('confirmed_sales_total', '600.00')->assertJsonPath('refunded_total', '60.00');
|
||||
$this->getJson('/api/v1/adminapp/tenant/sales/modifications')->assertOk()->assertJsonCount(3, 'data');
|
||||
$this->getJson('/api/v1/adminapp/tenant/sales/2')->assertOk();
|
||||
$this->getJson('/api/v1/adminapp/tenant/sales/3')->assertOk();
|
||||
}
|
||||
|
||||
public function test_foreign_and_unassigned_sales_are_inaccessible_before_any_checkout_action(): void
|
||||
{
|
||||
$this->mock(CheckoutService::class, function (MockInterface $mock): void {
|
||||
$mock->shouldNotReceive('confirmPaidPurchase');
|
||||
$mock->shouldNotReceive('cancelPurchaseFromAdmin');
|
||||
});
|
||||
foreach ([2, 3, 4] as $id) {
|
||||
$this->getJson("/api/v1/adminapp/tenant/sales/{$id}")->assertNotFound();
|
||||
$this->getJson("/api/v1/adminapp/tenant/sales/{$id}/tickets")->assertNotFound();
|
||||
$this->postJson("/api/v1/adminapp/tenant/sales/{$id}/confirm", ['event_id' => 20])->assertNotFound();
|
||||
$this->postJson("/api/v1/adminapp/tenant/sales/{$id}/cancel", ['event_id' => 20])->assertNotFound();
|
||||
}
|
||||
$this->assertSame(Purchase::STATUS_PAID, DB::table('compras')->where('id', 2)->value('status'));
|
||||
}
|
||||
|
||||
public function test_own_event_allows_detail_tickets_and_checkout_actions(): void
|
||||
{
|
||||
// Empty snapshots keep this fixture focused on authorization.
|
||||
DB::table('compra_items')->where('compra_id', 1)->delete();
|
||||
$this->mock(CheckoutService::class, function (MockInterface $mock): void {
|
||||
foreach (['confirmPaidPurchase', 'cancelPurchaseFromAdmin'] as $method) {
|
||||
$mock->shouldReceive($method)->once()->withArgs(fn (Purchase $sale): bool => $sale->id === 1)
|
||||
->andReturnUsing(fn (Purchase $sale): Purchase => $sale);
|
||||
}
|
||||
});
|
||||
$this->getJson('/api/v1/adminapp/tenant/sales/1')->assertOk()->assertJsonPath('data.id', 1);
|
||||
$this->getJson('/api/v1/adminapp/tenant/sales/1/tickets')->assertOk();
|
||||
$this->postJson('/api/v1/adminapp/tenant/sales/1/confirm')->assertOk()->assertJsonPath('data.id', 1);
|
||||
$this->postJson('/api/v1/adminapp/tenant/sales/1/cancel')->assertOk()->assertJsonPath('data.id', 1);
|
||||
}
|
||||
|
||||
public function test_pdf_and_excel_exports_only_receive_sales_and_history_for_the_own_event(): void
|
||||
{
|
||||
foreach ([AdminAppSalePdfService::class, AdminAppSaleExcelService::class] as $class) {
|
||||
$this->mock($class, function (MockInterface $mock) use ($class): void {
|
||||
foreach (['downloadSales', 'downloadModifications'] as $method) {
|
||||
$mock->shouldReceive($method)->once()->withArgs(
|
||||
fn ($tenant, Collection $rows, $timezone): bool => $tenant->codigo === 'onticket'
|
||||
&& $rows->pluck('id')->all() === [1] && $timezone === 'UTC'
|
||||
)->andReturn($class === AdminAppSalePdfService::class
|
||||
? response('pdf') : new StreamedResponse(fn () => print ('excel')));
|
||||
}
|
||||
});
|
||||
}
|
||||
foreach (['pdf', 'excel', 'modifications/pdf', 'modifications/excel'] as $path) {
|
||||
$this->getJson("/api/v1/adminapp/tenant/sales/{$path}?timezone=UTC&event_id=20")->assertOk();
|
||||
}
|
||||
}
|
||||
|
||||
private function actingAsAdministrator(?int $eventId): void
|
||||
{
|
||||
$user = new User;
|
||||
$user->setRawAttributes([
|
||||
'id' => 1,
|
||||
'rol_codigo' => RoleCode::AdminApp->value,
|
||||
'tenant_codigo' => 'onticket',
|
||||
'event_id' => $eventId,
|
||||
]);
|
||||
Sanctum::actingAs($user);
|
||||
}
|
||||
}
|
||||
158
tests/Feature/Staff/StaffEventScopeTest.php
Normal file
158
tests/Feature/Staff/StaffEventScopeTest.php
Normal file
@@ -0,0 +1,158 @@
|
||||
<?php
|
||||
|
||||
namespace Tests\Feature\Staff;
|
||||
|
||||
use App\Domains\Core\Auth\Models\User;
|
||||
use App\Domains\Core\Auth\Services\ResetPasswordAttemptService;
|
||||
use Illuminate\Database\Schema\Blueprint;
|
||||
use Illuminate\Support\Facades\DB;
|
||||
use Illuminate\Support\Facades\Schema;
|
||||
use Laravel\Sanctum\Sanctum;
|
||||
use Mockery\MockInterface;
|
||||
use Tests\TestCase;
|
||||
|
||||
class StaffEventScopeTest extends TestCase
|
||||
{
|
||||
protected function setUp(): void
|
||||
{
|
||||
parent::setUp();
|
||||
|
||||
// Exercise HTTP authorization on SQLite without the incompatible legacy migrations.
|
||||
Schema::create('tenants', function (Blueprint $table): void {
|
||||
$table->id();
|
||||
$table->string('codigo');
|
||||
$table->boolean('scanner_category_validation_enabled')->default(false);
|
||||
});
|
||||
Schema::create('roles', function (Blueprint $table): void {
|
||||
$table->id();
|
||||
$table->string('codigo');
|
||||
$table->string('nombre');
|
||||
});
|
||||
Schema::create('users', function (Blueprint $table): void {
|
||||
$table->id();
|
||||
$table->string('rol_codigo');
|
||||
$table->string('tenant_codigo');
|
||||
$table->unsignedBigInteger('event_id')->nullable();
|
||||
$table->string('nombre_apellido');
|
||||
$table->string('dni');
|
||||
$table->string('email');
|
||||
$table->string('active_email')->nullable();
|
||||
$table->string('password')->nullable();
|
||||
$table->timestamps();
|
||||
$table->softDeletes();
|
||||
});
|
||||
Schema::create('categorias', function (Blueprint $table): void {
|
||||
$table->id();
|
||||
$table->string('nombre');
|
||||
$table->string('tenant_code')->nullable();
|
||||
$table->unsignedBigInteger('categoria_id')->nullable();
|
||||
});
|
||||
Schema::create('catalog_items', function (Blueprint $table): void {
|
||||
$table->id();
|
||||
$table->unsignedBigInteger('category_id');
|
||||
$table->string('tenant_code');
|
||||
$table->softDeletes();
|
||||
});
|
||||
Schema::create('category_scanners', function (Blueprint $table): void {
|
||||
$table->unsignedBigInteger('user_id');
|
||||
$table->unsignedBigInteger('categoria_id');
|
||||
$table->timestamps();
|
||||
});
|
||||
Schema::create('personal_access_tokens', function (Blueprint $table): void {
|
||||
$table->id();
|
||||
$table->string('tokenable_type');
|
||||
$table->unsignedBigInteger('tokenable_id');
|
||||
});
|
||||
|
||||
DB::table('tenants')->insert(['codigo' => 'onticket']);
|
||||
foreach (['adminapp', 'scanner'] as $role) {
|
||||
DB::table('roles')->insert(['codigo' => $role, 'nombre' => $role]);
|
||||
foreach ([10, 20, null] as $eventId) {
|
||||
$this->insertUser($role, 'onticket', $eventId);
|
||||
}
|
||||
$this->insertUser($role, 'other', 10);
|
||||
}
|
||||
Sanctum::actingAs(User::query()->findOrFail(1));
|
||||
}
|
||||
|
||||
public function test_lists_and_searches_are_restricted_to_the_authenticated_event(): void
|
||||
{
|
||||
foreach (['administrators' => 1, 'staff' => 5] as $path => $id) {
|
||||
foreach (['', '?search=Persona&event_id=20'] as $query) {
|
||||
$this->getJson("/api/v1/adminapp/tenant/{$path}{$query}")
|
||||
->assertOk()->assertJsonCount(1, 'data')
|
||||
->assertJsonPath('data.0.id', $id)->assertJsonPath('data.0.event_id', 10);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
public function test_creation_inherits_the_actor_event_even_if_the_client_supplies_another(): void
|
||||
{
|
||||
$this->mock(ResetPasswordAttemptService::class, function (MockInterface $mock): void {
|
||||
$mock->shouldReceive('createForAdminAppEmail')->once();
|
||||
$mock->shouldReceive('createForScannerEmail')->once();
|
||||
});
|
||||
foreach (['administrators' => 'adminapp', 'staff' => 'scanner'] as $path => $role) {
|
||||
$this->postJson("/api/v1/adminapp/tenant/{$path}", [
|
||||
...$this->payload("new-{$role}@example.com"), 'event_id' => 20,
|
||||
])->assertSuccessful()->assertJsonPath('data.event_id', 10);
|
||||
$this->assertDatabaseHas('users', ['email' => "new-{$role}@example.com", 'event_id' => 10, 'rol_codigo' => $role]);
|
||||
}
|
||||
}
|
||||
|
||||
public function test_foreign_and_unassigned_staff_cannot_be_edited_deleted_or_inspected(): void
|
||||
{
|
||||
foreach (['administrators' => [2, 3, 4], 'staff' => [6, 7, 8]] as $path => $ids) {
|
||||
foreach ($ids as $id) {
|
||||
$this->putJson("/api/v1/adminapp/tenant/{$path}/{$id}", $this->payload("update-{$id}@example.com"))->assertNotFound();
|
||||
$this->deleteJson("/api/v1/adminapp/tenant/{$path}/{$id}")->assertNotFound();
|
||||
$this->assertDatabaseHas('users', ['id' => $id, 'deleted_at' => null, 'email' => "person-{$id}@example.com"]);
|
||||
if ($path === 'staff') {
|
||||
$this->getJson("/api/v1/adminapp/tenant/staff/{$id}/scan-attempts")->assertNotFound();
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
public function test_own_staff_can_be_edited_and_deleted_without_changing_its_event(): void
|
||||
{
|
||||
$adminId = $this->insertUser('adminapp', 'onticket', 10);
|
||||
foreach (['administrators' => $adminId, 'staff' => 5] as $path => $id) {
|
||||
$this->putJson("/api/v1/adminapp/tenant/{$path}/{$id}", [
|
||||
...$this->payload("updated-{$id}@example.com"), 'event_id' => 20,
|
||||
])->assertOk()->assertJsonPath('data.event_id', 10);
|
||||
$this->deleteJson("/api/v1/adminapp/tenant/{$path}/{$id}")->assertNoContent();
|
||||
$this->assertSoftDeleted('users', ['id' => $id]);
|
||||
}
|
||||
}
|
||||
|
||||
public function test_unscoped_actor_keeps_tenant_lists_and_creates_without_an_event(): void
|
||||
{
|
||||
Sanctum::actingAs(User::query()->findOrFail(3));
|
||||
$this->mock(ResetPasswordAttemptService::class, function (MockInterface $mock): void {
|
||||
$mock->shouldReceive('createForAdminAppEmail')->once();
|
||||
$mock->shouldReceive('createForScannerEmail')->once();
|
||||
});
|
||||
foreach (['administrators', 'staff'] as $path) {
|
||||
$this->getJson("/api/v1/adminapp/tenant/{$path}")->assertOk()->assertJsonCount(3, 'data');
|
||||
$this->postJson("/api/v1/adminapp/tenant/{$path}", $this->payload("legacy-{$path}@example.com"))
|
||||
->assertSuccessful()->assertJsonPath('data.event_id', null);
|
||||
}
|
||||
}
|
||||
|
||||
private function insertUser(string $role, string $tenant, ?int $eventId): int
|
||||
{
|
||||
$id = DB::table('users')->count() + 1;
|
||||
|
||||
return DB::table('users')->insertGetId([
|
||||
'id' => $id, 'rol_codigo' => $role, 'tenant_codigo' => $tenant,
|
||||
'event_id' => $eventId, 'nombre_apellido' => 'Persona', 'dni' => '12345678',
|
||||
'email' => "person-{$id}@example.com", 'active_email' => "person-{$id}@example.com",
|
||||
]);
|
||||
}
|
||||
|
||||
private function payload(string $email): array
|
||||
{
|
||||
return ['nombre_apellido' => 'Persona editada', 'dni' => '87654321', 'email' => $email];
|
||||
}
|
||||
}
|
||||
178
tests/Feature/Ticket/AdminAppTicketEventScopeTest.php
Normal file
178
tests/Feature/Ticket/AdminAppTicketEventScopeTest.php
Normal file
@@ -0,0 +1,178 @@
|
||||
<?php
|
||||
|
||||
namespace Tests\Feature\Ticket;
|
||||
|
||||
use App\Domains\Core\Auth\Models\User;
|
||||
use App\Domains\Ticketing\Ticket\Services\AdminAppTicketExcelService;
|
||||
use App\Domains\Ticketing\Ticket\Services\AdminAppTicketPdfService;
|
||||
use Illuminate\Database\Schema\Blueprint;
|
||||
use Illuminate\Support\Collection;
|
||||
use Illuminate\Support\Facades\DB;
|
||||
use Illuminate\Support\Facades\Schema;
|
||||
use Laravel\Sanctum\Sanctum;
|
||||
use Mockery\MockInterface;
|
||||
use Symfony\Component\HttpFoundation\StreamedResponse;
|
||||
use Tests\TestCase;
|
||||
|
||||
class AdminAppTicketEventScopeTest extends TestCase
|
||||
{
|
||||
protected function setUp(): void
|
||||
{
|
||||
parent::setUp();
|
||||
|
||||
// Keep HTTP tests isolated from legacy migrations incompatible with SQLite.
|
||||
Schema::create('tenants', function (Blueprint $table): void {
|
||||
$table->id();
|
||||
$table->string('codigo');
|
||||
$table->string('timezone')->default('UTC');
|
||||
$table->boolean('allow_ticket_refund')->default(false);
|
||||
$table->boolean('allow_ticket_total_refund')->default(false);
|
||||
$table->boolean('allow_ticket_partial_refund')->default(false);
|
||||
});
|
||||
Schema::create('menues', function (Blueprint $table): void {
|
||||
$table->id();
|
||||
$table->string('code');
|
||||
});
|
||||
Schema::create('tenants_menues', function (Blueprint $table): void {
|
||||
$table->string('tenant_code');
|
||||
$table->string('menu_code');
|
||||
});
|
||||
Schema::create('users', function (Blueprint $table): void {
|
||||
$table->id();
|
||||
$table->string('nombre_apellido');
|
||||
$table->softDeletes();
|
||||
});
|
||||
Schema::create('tickets', function (Blueprint $table): void {
|
||||
$table->id();
|
||||
$table->string('tenant_code');
|
||||
$table->unsignedBigInteger('event_id')->nullable();
|
||||
$table->string('ticket');
|
||||
foreach (['source_variant_id', 'source_catalog_item_id', 'source_purchase_item_id', 'scanner_user_id', 'user_id'] as $column) {
|
||||
$table->unsignedBigInteger($column)->nullable();
|
||||
}
|
||||
foreach (['used_at', 'disabled_at', 'cancelled_at', 'refunded_at'] as $column) {
|
||||
$table->timestamp($column)->nullable();
|
||||
}
|
||||
$table->timestamps();
|
||||
});
|
||||
Schema::create('compras', function (Blueprint $table): void {
|
||||
$table->id();
|
||||
$table->string('tenant_codigo');
|
||||
$table->unsignedBigInteger('event_id')->nullable();
|
||||
$table->string('nombre_apellido');
|
||||
});
|
||||
Schema::create('compra_items', function (Blueprint $table): void {
|
||||
$table->id();
|
||||
$table->unsignedBigInteger('compra_id');
|
||||
$table->decimal('precio_unitario', 12, 2);
|
||||
});
|
||||
Schema::create('ticket_refunds', function (Blueprint $table): void {
|
||||
$table->id();
|
||||
$table->unsignedBigInteger('ticket_id')->nullable();
|
||||
$table->unsignedBigInteger('purchase_item_id');
|
||||
$table->decimal('amount', 12, 2);
|
||||
});
|
||||
Schema::create('desfile_entry_reservations', function (Blueprint $table): void {
|
||||
$table->id();
|
||||
$table->unsignedBigInteger('ticket_id');
|
||||
$table->softDeletes();
|
||||
});
|
||||
Schema::create('value_changes', function (Blueprint $table): void {
|
||||
$table->id();
|
||||
$table->string('tenant_code');
|
||||
$table->string('trackable_type');
|
||||
$table->unsignedBigInteger('trackable_id');
|
||||
$table->string('attribute');
|
||||
$table->string('old_value')->nullable();
|
||||
$table->string('new_value')->nullable();
|
||||
$table->timestamp('changed_at');
|
||||
$table->string('actor_type');
|
||||
$table->unsignedBigInteger('user_id')->nullable();
|
||||
});
|
||||
|
||||
DB::table('tenants')->insert(['codigo' => 'onticket']);
|
||||
DB::table('menues')->insert(['code' => 'adminapp.tickets']);
|
||||
DB::table('tenants_menues')->insert(['tenant_code' => 'onticket', 'menu_code' => 'adminapp.tickets']);
|
||||
foreach ([1 => ['onticket', 10], 2 => ['onticket', 20], 3 => ['onticket', null], 4 => ['other', 10]] as $id => [$tenant, $event]) {
|
||||
DB::table('tickets')->insert([
|
||||
'id' => $id, 'tenant_code' => $tenant, 'event_id' => $event,
|
||||
'ticket' => "ticket-{$id}", 'used_at' => now(),
|
||||
]);
|
||||
DB::table('compras')->insert(['id' => $id, 'tenant_codigo' => $tenant, 'event_id' => $event, 'nombre_apellido' => 'Cliente']);
|
||||
DB::table('compra_items')->insert(['id' => $id, 'compra_id' => $id, 'precio_unitario' => 100]);
|
||||
DB::table('ticket_refunds')->insert(['purchase_item_id' => $id, 'amount' => $id * 10]);
|
||||
}
|
||||
$this->actingAsAdmin(10);
|
||||
}
|
||||
|
||||
public function test_list_counts_refunded_total_and_search_cannot_escape_the_user_event(): void
|
||||
{
|
||||
$this->getJson('/api/v1/adminapp/tenant/tickets?sort_by=id&event_id=20')
|
||||
->assertOk()->assertJsonCount(1, 'data')->assertJsonPath('data.0.id', 1)
|
||||
->assertJsonPath('scanned_tickets', 1)->assertJsonPath('total_tickets', 1)
|
||||
->assertJsonPath('refunded_total', '10.00');
|
||||
$this->getJson('/api/v1/adminapp/tenant/tickets?q=2')->assertOk()->assertJsonCount(0, 'data');
|
||||
// Status uses sorting in memory rather than the database.
|
||||
$this->getJson('/api/v1/adminapp/tenant/tickets?sort_by=status')
|
||||
->assertOk()->assertJsonCount(1, 'data')->assertJsonPath('data.0.id', 1);
|
||||
DB::table('tickets')->where('id', 1)->update(['used_at' => null]);
|
||||
$this->getJson('/api/v1/adminapp/tenant/tickets?status=active')
|
||||
->assertOk()->assertJsonCount(1, 'data')
|
||||
->assertJsonPath('scanned_tickets', 0)->assertJsonPath('total_tickets', 1);
|
||||
}
|
||||
|
||||
public function test_foreign_unassigned_and_other_tenant_tickets_cannot_be_modified_or_refunded(): void
|
||||
{
|
||||
foreach ([2, 3, 4] as $id) {
|
||||
$this->postJson("/api/v1/adminapp/tenant/tickets/{$id}/cancel", ['event_id' => 20])->assertNotFound();
|
||||
$this->getJson("/api/v1/adminapp/tenant/tickets/{$id}/refund")->assertNotFound();
|
||||
$this->postJson("/api/v1/adminapp/tenant/tickets/{$id}/refund", ['refund_type' => 'total', 'event_id' => 20])->assertNotFound();
|
||||
$this->assertDatabaseHas('tickets', ['id' => $id, 'cancelled_at' => null, 'refunded_at' => null]);
|
||||
}
|
||||
$this->assertDatabaseCount('value_changes', 0);
|
||||
$this->assertDatabaseCount('ticket_refunds', 4);
|
||||
}
|
||||
|
||||
public function test_own_ticket_can_be_cancelled_and_refund_requests_reach_business_validation(): void
|
||||
{
|
||||
DB::table('tickets')->where('id', 1)->update(['used_at' => null]);
|
||||
$this->getJson('/api/v1/adminapp/tenant/tickets/1/refund')->assertUnprocessable();
|
||||
$this->postJson('/api/v1/adminapp/tenant/tickets/1/refund', ['refund_type' => 'total'])->assertUnprocessable();
|
||||
$this->postJson('/api/v1/adminapp/tenant/tickets/1/cancel')->assertOk();
|
||||
$this->assertNotNull(DB::table('tickets')->where('id', 1)->value('cancelled_at'));
|
||||
}
|
||||
|
||||
public function test_unscoped_admin_keeps_the_tenant_scope(): void
|
||||
{
|
||||
$this->actingAsAdmin(null);
|
||||
$this->getJson('/api/v1/adminapp/tenant/tickets?sort_by=id')
|
||||
->assertOk()->assertJsonCount(3, 'data')->assertJsonPath('total_tickets', 3)
|
||||
->assertJsonPath('refunded_total', '60.00');
|
||||
DB::table('tickets')->where('id', 3)->update(['used_at' => null]);
|
||||
$this->postJson('/api/v1/adminapp/tenant/tickets/3/cancel')->assertOk();
|
||||
$this->postJson('/api/v1/adminapp/tenant/tickets/4/cancel')->assertNotFound();
|
||||
}
|
||||
|
||||
public function test_pdf_and_excel_receive_only_the_tickets_of_the_user_event(): void
|
||||
{
|
||||
foreach ([AdminAppTicketPdfService::class, AdminAppTicketExcelService::class] as $class) {
|
||||
$this->mock($class, function (MockInterface $mock) use ($class): void {
|
||||
$mock->shouldReceive('download')->once()->withArgs(
|
||||
fn ($tenant, Collection $tickets, $timezone): bool => $tenant->codigo === 'onticket'
|
||||
&& $tickets->pluck('id')->all() === [1] && $timezone === 'UTC'
|
||||
)->andReturn($class === AdminAppTicketPdfService::class
|
||||
? response('pdf') : new StreamedResponse(fn () => print ('excel')));
|
||||
});
|
||||
}
|
||||
foreach (['pdf', 'excel'] as $format) {
|
||||
$this->getJson("/api/v1/adminapp/tenant/tickets/{$format}?timezone=UTC&event_id=20")->assertOk();
|
||||
}
|
||||
}
|
||||
|
||||
private function actingAsAdmin(?int $eventId): void
|
||||
{
|
||||
$user = new User;
|
||||
$user->setRawAttributes(['id' => 1, 'rol_codigo' => 'adminapp', 'tenant_codigo' => 'onticket', 'event_id' => $eventId]);
|
||||
Sanctum::actingAs($user);
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user