Compare commits

...

31 Commits

Author SHA1 Message Date
09faa22920 feat(event-admin): remove menu restrictions for non-admin users and add test for shared menus among event admins 2026-09-30 16:14:47 -03:00
bebf6a7ed5 feat(scanner): scope login tickets scanning and history by event 2026-09-30 15:31:56 -03:00
86ca57a3ad chore(menus): remove deprecated combos and categories admin menus 2026-09-30 15:31:56 -03:00
e64393812c feat(staff): scope scanner management and category assignments by event 2026-09-30 15:31:56 -03:00
655364bfec feat(sales): scope sales actions totals history and exports by event 2026-09-30 15:31:55 -03:00
55c28f33ef feat(events): authorize event editing and date changes by assigned event 2026-09-30 15:31:54 -03:00
5a0ce08adb feat(refunds): persist and apply refund configuration per event 2026-09-30 15:31:54 -03:00
a770d435eb feat(auth): enable event-scoped admin access and backfill staff assignments 2026-09-30 15:31:53 -03:00
44bf67bd12 feat(admin): add admin scope management for users and events
- Introduced AdminScope enum for tenant and event scopes.
- Updated User model to include admin_scope and event_id attributes.
- Enhanced AdminAppAccessService to validate user scopes.
- Modified AdminAppMeResource and UserResource to include event data.
- Implemented middleware to ensure valid tenant access.
- Created migration to add admin_scope and event_id to users table.
- Added tests for event admin functionality and scope validation.
2026-09-30 15:02:10 -03:00
6e1f0d731c Merge pull request 'homo' (#12) from homo into main
Reviewed-on: https://gitea.quo.ar/tbianchini/shopit-back/pulls/12
2026-09-30 11:37:24 +00:00
82c18e9e91 Merge branch 'tenant/smep' into homo 2026-09-28 19:27:39 +00:00
dfad6fb4b0 Merge pull request 'fix/events_integrations' (#11) from fix/events_integrations into homo
Reviewed-on: https://gitea.quo.ar/tbianchini/shopit-back/pulls/11
2026-09-28 19:15:30 +00:00
3f9b773367 feat(integrations): resolve payment context from events 2026-09-28 19:14:23 +00:00
7996d53e12 feat(events): associate purchases and integrations with events 2026-09-28 19:13:36 +00:00
a40a2065a9 Merge branch 'tenant/smep' of https://gitea.quo.ar/tbianchini/shopit-back into tenant/smep 2026-09-25 11:37:51 -03:00
57677f55e6 feat(category): include products from all descendant categories in paginated response 2026-09-25 11:37:32 -03:00
a8afd92f46 feat(migration): optimize product images size for improved loading speed 2026-09-25 11:37:32 -03:00
1df0d2e2ef optimized storefront page and images 2026-09-25 11:37:32 -03:00
d3cac7a590 feat(migration): add comprehensive migration report for Mutual SMEP WhatsApp catalog to online store 2026-09-25 11:37:31 -03:00
df13a636ba feat(migration): enhance Mutual SMEP catalog seeding with featured groups and highlighted products 2026-09-25 11:37:31 -03:00
d85841742e feat(carousel): add migration and test for Mutual SMEP carousel images 2026-09-25 11:37:31 -03:00
0e3fdc5460 Add new product images and implement SeedMutualSmepCatalogTest for catalog migration
- Added multiple new product images for smart TVs, audio devices, and accessories in WEBP format.
- Created a new test class SeedMutualSmepCatalogTest to validate the catalog migration process.
- Implemented setup and teardown methods to manage database schema and data during tests.
- Verified the integrity of catalog items, inventories, and associated attributes after migration.
2026-09-25 11:37:31 -03:00
0dc2675dae feat(seeder): implement Mutual SMEP attribute seeder and associated tests 2026-09-25 11:37:30 -03:00
28d1de072c feat(seeder): add Mutual SMEP category seeder and test cases 2026-09-25 11:37:30 -03:00
b09e8a4b96 feat(tenant): provision Mutual SMEP tenant with branding and menu setup 2026-09-25 11:37:30 -03:00
7f754037bb feat(ticket): enhance ticket details with entry reservation amount and product naming for desfile 2026-09-25 11:31:54 -03:00
f29c5692b9 feat(ticket): add entry reservation handling to ticket refund logic and tests 2026-09-25 11:20:12 -03:00
57d278336d feat(desfile): associate tickets menu with desfile tenant and add migration test 2026-09-25 11:15:52 -03:00
b309738222 Merge branch 'homo' 2026-09-25 10:03:21 -03:00
b3eb59983a Merge pull request 'homo' (#10) from homo into main
Reviewed-on: https://gitea.quo.ar/tbianchini/shopit-back/pulls/10
2026-09-24 19:55:03 +00:00
bd77727f58 Merge pull request 'homo' (#8) from homo into main
Reviewed-on: https://gitea.quo.ar/tbianchini/shopit-back/pulls/8
2026-09-17 17:52:21 +00:00
78 changed files with 2261 additions and 192 deletions

View File

@@ -34,3 +34,8 @@ Bajo `/v1/adminapp/tenant/featured-groups`, con `auth:sanctum` y `adminapp.tenan
## Dependencias y reglas
Usa `Attachable` para imágenes/archivos, `Tenant` para aislamiento y `Ticket`/`Event` para vigencia y fechas. `Cart` y `Purchase` consumen sus precios, variantes e inventario. Los cambios de stock deben pasar por `CatalogInventoryService` para conservar reservas y disponibilidad.
## Menús deprecados
Los menús `adminapp.combos` y `adminapp.categories` están retirados; las
categorías del catálogo y sus datos comerciales no se eliminan.

View File

@@ -2,7 +2,6 @@
namespace App\Domains\Commerce\Purchase\Controllers;
use App\Shared\Integration\Services\TelepagosIntegrationService;
use App\Domains\Commerce\Purchase\Models\Purchase;
use App\Domains\Commerce\Purchase\Requests\PaymentIntentRequest;
use App\Domains\Commerce\Purchase\Requests\StartCheckoutRequest;
@@ -13,6 +12,7 @@ use App\Domains\Commerce\Purchase\Services\CheckoutService;
use App\Domains\Commerce\Purchase\Services\PurchaseStateGuard;
use App\Domains\Core\Tenant\Models\Tenant;
use App\Http\Controllers\Controller;
use App\Shared\Integration\Services\TelepagosIntegrationService;
use Illuminate\Http\JsonResponse;
use Illuminate\Http\Request;
use Illuminate\Support\Facades\DB;
@@ -151,11 +151,14 @@ class PurchaseController extends Controller
}
$compra->refresh();
$compra->loadMissing('event');
$totalAmount = (float) $compra->total;
if ($method === 'transfer') {
$telepagosService = new TelepagosIntegrationService;
$telepagosService->forTenant($tenant->codigo);
$compra->event
? $telepagosService->forEvent($compra->event)
: $telepagosService->forTenant($tenant->codigo);
try {
$accountInfo = $telepagosService->getAccountInfo();
@@ -191,7 +194,9 @@ class PurchaseController extends Controller
if ($method === 'qr') {
$telepagosService = new TelepagosIntegrationService;
$telepagosService->forTenant($tenant->codigo);
$compra->event
? $telepagosService->forEvent($compra->event)
: $telepagosService->forTenant($tenant->codigo);
try {
Log::channel('telepagos')->info('Generating Telepagos QR.', [

View File

@@ -2,13 +2,14 @@
namespace App\Domains\Commerce\Purchase\Models;
use App\Domains\Core\Auth\Models\User;
use App\Domains\Commerce\Cart\Models\Cart;
use App\Domains\Commerce\Catalog\Models\StockReservation;
use App\Shared\Logging\Models\Concerns\LogsValueChanges;
use App\Domains\Commerce\Purchase\Events\PurchasePaid;
use App\Domains\Core\Auth\Models\User;
use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Ticketing\Event\Models\Event;
use App\Domains\Ticketing\Ticket\Models\Ticket;
use App\Shared\Logging\Models\Concerns\LogsValueChanges;
use Illuminate\Database\Eloquent\Attributes\Fillable;
use Illuminate\Database\Eloquent\Factories\HasFactory;
use Illuminate\Database\Eloquent\Model;
@@ -21,6 +22,7 @@ use Illuminate\Support\Facades\DB;
#[Fillable([
'cart_id',
'stock_reservation_id',
'event_id',
'tenant_codigo',
'user_id',
'status',
@@ -149,6 +151,7 @@ class Purchase extends Model
return [
'cart_id' => 'integer',
'stock_reservation_id' => 'integer',
'event_id' => 'integer',
'user_id' => 'integer',
'total' => 'decimal:2',
];
@@ -162,6 +165,12 @@ class Purchase extends Model
return $this->belongsTo(Tenant::class, 'tenant_codigo', 'codigo');
}
/** @return BelongsTo<Event, $this> */
public function event(): BelongsTo
{
return $this->belongsTo(Event::class);
}
/**
* @return BelongsTo<User, $this>
*/

View File

@@ -36,11 +36,11 @@ class PurchaseResource extends JsonResource
=== StorefrontWebsiteType::CHECKOUT_SUMMARY_EVENT;
/** @var Event|null $checkoutEvent */
$checkoutEvent = $usesEventSummary
? $items
? ($this->event ?? $items
->map(fn (PurchaseItem $item) => $item->sourceCatalogItem?->event)
->filter()
->unique('id')
->first()
->first())
: null;
$subtotal = $items->isNotEmpty()
@@ -62,6 +62,7 @@ class PurchaseResource extends JsonResource
return [
'id' => $this->id,
'cart_id' => $this->cart_id,
'event_id' => $this->event_id,
'tenant_codigo' => $this->tenant_codigo,
'user_id' => $this->user_id,
'created_at' => $this->created_at,

View File

@@ -14,6 +14,7 @@ class PurchaseResponseLoader
=== StorefrontWebsiteType::CHECKOUT_SUMMARY_EVENT;
$relations = [
'tenant',
'event.attachment',
'items.sourceCatalogItem.event.attachment',
'stockReservation',
];

View File

@@ -206,6 +206,7 @@ class StartCheckoutService
fn (array $line): float => $line['selection']->getPrice() * $line['quantity'],
),
$cart->getKey(),
$cartItems->first()?->catalogItem?->event_id,
);
$cart->update(['current_purchase_id' => $purchase->getKey()]);
$this->reservations->attachToPurchase($cart, $purchase, $this->checkoutExpiration());
@@ -273,6 +274,7 @@ class StartCheckoutService
$purchaseData,
$cart->getTotalAmount(),
$cart->getKey(),
$cartItems->first()?->catalogItem?->event_id,
);
$cart->update(['current_purchase_id' => $purchase->getKey()]);
$this->reservations->attachToPurchase($cart, $purchase, $this->checkoutExpiration());
@@ -410,10 +412,12 @@ class StartCheckoutService
array $purchaseData,
float $total,
?int $cartId,
?int $eventId,
): Purchase {
return Purchase::query()->create([
...$purchaseData,
'cart_id' => $cartId,
'event_id' => $eventId,
'tenant_codigo' => $tenant->codigo,
'user_id' => $userId,
'status' => Purchase::STATUS_CREATED,

View File

@@ -8,12 +8,13 @@ use Illuminate\Database\Eloquent\Builder;
class PurchaseRefundSummaryService
{
public function totalForTenant(Tenant $tenant): string
public function totalForTenant(Tenant $tenant, ?int $eventId = null): string
{
$total = TicketRefund::query()
->whereHas(
'purchaseItem.purchase',
fn (Builder $query): Builder => $query->where('tenant_codigo', $tenant->codigo)
->when($eventId !== null, fn (Builder $purchase) => $purchase->where('event_id', $eventId))
)
->sum('amount');

View File

@@ -13,6 +13,7 @@ use App\Domains\Commerce\Sale\Resources\AdminApp\SaleTicketResource;
use App\Domains\Commerce\Sale\Services\AdminAppSaleExcelService;
use App\Domains\Commerce\Sale\Services\AdminAppSalePdfService;
use App\Domains\Commerce\Sale\Services\AdminAppSaleService;
use App\Domains\Core\Auth\Services\EventScopeService;
use App\Http\Controllers\Controller;
use Illuminate\Http\Request;
use Illuminate\Http\Resources\Json\AnonymousResourceCollection;
@@ -27,15 +28,20 @@ class SaleController extends Controller
protected AdminAppSaleExcelService $saleExcelService,
) {}
private function eventId(Request $request): ?int
{
return app(EventScopeService::class)->eventId($request->user());
}
public function index(AdminAppSaleIndexRequest $request): AnonymousResourceCollection
{
$tenant = $request->user()->tenant()->firstOrFail();
return SaleResource::collection(
$this->saleService->sales($tenant, $request->validated())
$this->saleService->sales($tenant, $request->validated(), $this->eventId($request))
)->additional([
'confirmed_sales_total' => $this->saleService->confirmedSalesTotal($tenant),
'refunded_total' => $this->saleService->refundedTotal($tenant),
'confirmed_sales_total' => $this->saleService->confirmedSalesTotal($tenant, $this->eventId($request)),
'refunded_total' => $this->saleService->refundedTotal($tenant, $this->eventId($request)),
]);
}
@@ -43,7 +49,7 @@ class SaleController extends Controller
{
$tenant = $request->user()->tenant()->firstOrFail();
return new SaleDetailResource($this->saleService->detail($tenant, $sale));
return new SaleDetailResource($this->saleService->detail($tenant, $sale, $this->eventId($request)));
}
public function tickets(Request $request, int $sale): AnonymousResourceCollection
@@ -51,7 +57,7 @@ class SaleController extends Controller
$tenant = $request->user()->tenant()->firstOrFail();
return SaleTicketResource::collection(
$this->saleService->tickets($tenant, $sale)
$this->saleService->tickets($tenant, $sale, $this->eventId($request))
);
}
@@ -59,14 +65,14 @@ class SaleController extends Controller
{
$tenant = $request->user()->tenant()->firstOrFail();
return new SaleResource($this->saleService->confirm($tenant, $sale));
return new SaleResource($this->saleService->confirm($tenant, $sale, $this->eventId($request)));
}
public function cancel(Request $request, int $sale): SaleResource
{
$tenant = $request->user()->tenant()->firstOrFail();
return new SaleResource($this->saleService->cancel($tenant, $sale));
return new SaleResource($this->saleService->cancel($tenant, $sale, $this->eventId($request)));
}
public function modifications(
@@ -76,6 +82,7 @@ class SaleController extends Controller
$this->saleService->modifications(
$request->user()->tenant()->firstOrFail(),
$request->validated(),
$this->eventId($request),
)
);
}
@@ -86,7 +93,7 @@ class SaleController extends Controller
return $this->salePdfService->downloadSales(
$tenant,
$this->saleService->salesForExport($tenant, $request->validated()),
$this->saleService->salesForExport($tenant, $request->validated(), $this->eventId($request)),
$request->validated('timezone'),
);
}
@@ -97,7 +104,7 @@ class SaleController extends Controller
return $this->salePdfService->downloadModifications(
$tenant,
$this->saleService->modificationsForExport($tenant, $request->validated()),
$this->saleService->modificationsForExport($tenant, $request->validated(), $this->eventId($request)),
$request->validated('timezone'),
);
}
@@ -108,7 +115,7 @@ class SaleController extends Controller
return $this->saleExcelService->downloadSales(
$tenant,
$this->saleService->salesForExport($tenant, $request->validated()),
$this->saleService->salesForExport($tenant, $request->validated(), $this->eventId($request)),
$request->validated('timezone'),
);
}
@@ -120,7 +127,7 @@ class SaleController extends Controller
return $this->saleExcelService->downloadModifications(
$tenant,
$this->saleService->modificationsForExport($tenant, $request->validated()),
$this->saleService->modificationsForExport($tenant, $request->validated(), $this->eventId($request)),
$request->validated('timezone'),
);
}

View File

@@ -2,7 +2,6 @@
namespace App\Domains\Commerce\Sale\Services;
use App\Shared\Logging\Models\ValueChange;
use App\Domains\Commerce\Purchase\Models\Purchase;
use App\Domains\Commerce\Purchase\Services\CheckoutService;
use App\Domains\Commerce\Purchase\Services\PurchaseRefundSummaryService;
@@ -10,6 +9,7 @@ use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Ticketing\Ticket\Models\Ticket;
use App\Domains\Ticketing\Ticket\Services\TicketPresentationResolver;
use App\Domains\Ticketing\Ticket\Services\TicketValidityResolver;
use App\Shared\Logging\Models\ValueChange;
use Illuminate\Database\Eloquent\Builder;
use Illuminate\Pagination\LengthAwarePaginator;
use Illuminate\Support\Collection;
@@ -21,19 +21,20 @@ class AdminAppSaleService
protected PurchaseRefundSummaryService $refundSummaryService,
) {}
public function confirmedSalesTotal(Tenant $tenant): string
public function confirmedSalesTotal(Tenant $tenant, ?int $eventId = null): string
{
$total = Purchase::query()
->where('tenant_codigo', $tenant->codigo)
->when($eventId !== null, fn (Builder $query) => $query->where('event_id', $eventId))
->where('status', Purchase::STATUS_PAID)
->sum('total');
return number_format((float) $total, 2, '.', '');
}
public function refundedTotal(Tenant $tenant): string
public function refundedTotal(Tenant $tenant, ?int $eventId = null): string
{
return $this->refundSummaryService->totalForTenant($tenant);
return $this->refundSummaryService->totalForTenant($tenant, $eventId);
}
/**
@@ -47,43 +48,44 @@ class AdminAppSaleService
* } $filters
* @return LengthAwarePaginator<Purchase>
*/
public function sales(Tenant $tenant, array $filters = []): LengthAwarePaginator
public function sales(Tenant $tenant, array $filters = [], ?int $eventId = null): LengthAwarePaginator
{
return $this->salesQuery($tenant, $filters)
return $this->salesQuery($tenant, $filters, $eventId)
->paginateFromRequest()
->withQueryString();
}
public function detail(Tenant $tenant, int $saleId): Purchase
public function detail(Tenant $tenant, int $saleId, ?int $eventId = null): Purchase
{
return Purchase::query()
->where('tenant_codigo', $tenant->codigo)
->when($eventId !== null, fn (Builder $query) => $query->where('event_id', $eventId))
->with('items')
->findOrFail($saleId);
}
/** @return Collection<int, Ticket> */
public function tickets(Tenant $tenant, int $saleId): Collection
public function tickets(Tenant $tenant, int $saleId, ?int $eventId = null): Collection
{
return $this->findForTenant($tenant, $saleId)
return $this->findForTenant($tenant, $saleId, $eventId)
->tickets()
->with([...TicketValidityResolver::RELATIONS, ...TicketPresentationResolver::RELATIONS, 'refund'])
->orderBy('id')
->get();
}
public function confirm(Tenant $tenant, int $saleId): Purchase
public function confirm(Tenant $tenant, int $saleId, ?int $eventId = null): Purchase
{
$sale = $this->findForTenant($tenant, $saleId);
$sale = $this->findForTenant($tenant, $saleId, $eventId);
return $this->saleForResponse(
$this->checkoutService->confirmPaidPurchase($sale)
);
}
public function cancel(Tenant $tenant, int $saleId): Purchase
public function cancel(Tenant $tenant, int $saleId, ?int $eventId = null): Purchase
{
$sale = $this->findForTenant($tenant, $saleId);
$sale = $this->findForTenant($tenant, $saleId, $eventId);
return $this->saleForResponse(
$this->checkoutService->cancelPurchaseFromAdmin($sale)
@@ -94,18 +96,18 @@ class AdminAppSaleService
* @param array<string, mixed> $filters
* @return Collection<int, Purchase>
*/
public function salesForExport(Tenant $tenant, array $filters = []): Collection
public function salesForExport(Tenant $tenant, array $filters = [], ?int $eventId = null): Collection
{
return $this->salesQuery($tenant, $filters)->get();
return $this->salesQuery($tenant, $filters, $eventId)->get();
}
/**
* @param array<string, mixed> $filters
* @return LengthAwarePaginator<ValueChange>
*/
public function modifications(Tenant $tenant, array $filters = []): LengthAwarePaginator
public function modifications(Tenant $tenant, array $filters = [], ?int $eventId = null): LengthAwarePaginator
{
return $this->modificationsQuery($tenant, $filters)
return $this->modificationsQuery($tenant, $filters, $eventId)
->paginateFromRequest()
->withQueryString();
}
@@ -114,13 +116,13 @@ class AdminAppSaleService
* @param array<string, mixed> $filters
* @return Collection<int, ValueChange>
*/
public function modificationsForExport(Tenant $tenant, array $filters = []): Collection
public function modificationsForExport(Tenant $tenant, array $filters = [], ?int $eventId = null): Collection
{
return $this->modificationsQuery($tenant, $filters)->get();
return $this->modificationsQuery($tenant, $filters, $eventId)->get();
}
/** @param array<string, mixed> $filters */
protected function salesQuery(Tenant $tenant, array $filters): Builder
protected function salesQuery(Tenant $tenant, array $filters, ?int $eventId = null): Builder
{
$sortColumns = [
'id' => 'id',
@@ -139,6 +141,7 @@ class AdminAppSaleService
return Purchase::query()
->where('tenant_codigo', $tenant->codigo)
->when($eventId !== null, fn (Builder $query) => $query->where('event_id', $eventId))
->when($filters['q'] ?? null, function (Builder $query, string $search): void {
$term = trim($search);
@@ -176,11 +179,14 @@ class AdminAppSaleService
* @param array<string, mixed> $filters
* @return Builder<ValueChange>
*/
protected function modificationsQuery(Tenant $tenant, array $filters): Builder
protected function modificationsQuery(Tenant $tenant, array $filters, ?int $eventId = null): Builder
{
return ValueChange::query()
->where('tenant_code', $tenant->codigo)
->where('trackable_type', (new Purchase)->getMorphClass())
->when($eventId !== null, fn (Builder $query) => $query->whereHasMorph(
'trackable', [Purchase::class],
fn (Builder $sales) => $sales->where('event_id', $eventId)))
->when($filters['q'] ?? null, function (Builder $query, string $search): void {
$term = trim($search);
@@ -221,10 +227,11 @@ class AdminAppSaleService
->orderByDesc('id');
}
protected function findForTenant(Tenant $tenant, int $saleId): Purchase
protected function findForTenant(Tenant $tenant, int $saleId, ?int $eventId = null): Purchase
{
return Purchase::query()
->where('tenant_codigo', $tenant->codigo)
->when($eventId !== null, fn (Builder $query) => $query->where('event_id', $eventId))
->findOrFail($saleId);
}

View File

@@ -30,3 +30,10 @@ Consume compras de `Purchase`, datos del tenant y entradas de `Logging`. No es d
La consulta paginada y la colección de exportación deben aplicar los mismos filtros para evitar diferencias entre pantalla, PDF y Excel.
El historial comparte con ventas los filtros de búsqueda, ID, fecha de venta y estado. En el historial, el estado se evalúa sobre `ValueChange.new_value`: representa el resultado de esa modificación y no el estado actual de la venta.
## Alcance por evento
Las rutas usan `adminapp.tenant:event`. Para admins de evento, listados, totales,
detalles, tickets de compras, confirmación, cancelación, historial y exportaciones
se filtran por `user.event_id` además del tenant. Las compras pertenecen a un
único evento. Un admin de tenant conserva acceso a sus compras de todos los eventos.

View File

@@ -4,7 +4,7 @@ use App\Domains\Commerce\Sale\Controllers\AdminApp\SaleController;
use Illuminate\Support\Facades\Route;
Route::prefix('v1/adminapp/tenant')
->middleware(['auth:sanctum', 'adminapp.tenant'])
->middleware(['auth:sanctum', 'adminapp.tenant:event'])
->group(function (): void {
Route::get('sales', [SaleController::class, 'index']);
Route::get('sales/pdf', [SaleController::class, 'downloadPdf']);

View File

@@ -0,0 +1,9 @@
<?php
namespace App\Domains\Core\Auth\Enums;
enum AdminScope: string
{
case Tenant = 'tenant';
case Event = 'event';
}

View File

@@ -2,11 +2,13 @@
namespace App\Domains\Core\Auth\Models;
use App\Domains\Commerce\Catalog\Models\Category;
use App\Domains\Core\Auth\Enums\AdminScope;
use App\Domains\Core\Authorization\Enums\RoleCode;
use App\Domains\Core\Authorization\Models\Role;
use App\Domains\Commerce\Catalog\Models\Category;
use App\Domains\Ticketing\Event\Models\EventDateChangeView;
use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Ticketing\Event\Models\Event;
use App\Domains\Ticketing\Event\Models\EventDateChangeView;
use App\Domains\Ticketing\Ticket\Models\ScanAttempt;
use Database\Factories\UserFactory;
use Illuminate\Database\Eloquent\Attributes\Fillable;
@@ -20,7 +22,7 @@ use Illuminate\Foundation\Auth\User as Authenticatable;
use Illuminate\Notifications\Notifiable;
use Laravel\Sanctum\HasApiTokens;
#[Fillable(['nombre_apellido', 'email', 'password', 'dni', 'telefono', 'google_id', 'rol_codigo', 'tenant_codigo'])]
#[Fillable(['nombre_apellido', 'email', 'password', 'dni', 'telefono', 'google_id', 'rol_codigo', 'tenant_codigo', 'admin_scope', 'event_id'])]
#[Hidden(['password', 'remember_token', 'active_email', 'active_google_id'])]
class User extends Authenticatable
{
@@ -29,6 +31,7 @@ class User extends Authenticatable
protected $attributes = [
'rol_codigo' => RoleCode::User->value,
'admin_scope' => AdminScope::Tenant->value,
];
protected static function newFactory(): UserFactory
@@ -86,6 +89,19 @@ class User extends Authenticatable
return $this->belongsTo(Tenant::class, 'tenant_codigo', 'codigo');
}
/** @return BelongsTo<Event, $this> */
public function event(): BelongsTo
{
return $this->belongsTo(Event::class);
}
public function isTenantAdministrator(): bool
{
return $this->rol_codigo === RoleCode::AdminApp->value
&& $this->admin_scope === AdminScope::Tenant->value
&& $this->event_id === null;
}
/** @return BelongsToMany<Category, $this> */
public function scanCategories(): BelongsToMany
{
@@ -103,6 +119,7 @@ class User extends Authenticatable
protected function casts(): array
{
return [
'event_id' => 'integer',
'email_verified_at' => 'datetime',
'password' => 'hashed',
'failed_login_attempts' => 'integer',

View File

@@ -20,6 +20,11 @@ class AdminAppMeResource extends JsonResource
return [
'user' => UserResource::make($this->resource),
'tenant' => TenantResource::make($this->tenant),
'event' => $this->whenLoaded('event', fn () => $this->event === null ? null : [
'id' => $this->event->id,
'title' => $this->event->title,
'tenant_code' => $this->event->tenant_code,
]),
];
}
}

View File

@@ -16,6 +16,9 @@ class ScannerMeResource extends JsonResource
return [
'user' => UserResource::make($this->resource),
'tenant' => TenantResource::make($this->tenant),
'event' => $this->whenLoaded('event', fn () => $this->event === null ? null : [
'id' => $this->event->id, 'title' => $this->event->title,
]),
];
}
}

View File

@@ -3,6 +3,7 @@
namespace App\Domains\Core\Auth\Resources;
use App\Domains\Core\Auth\Models\User;
use App\Domains\Core\Authorization\Enums\RoleCode;
use Illuminate\Http\Request;
use Illuminate\Http\Resources\Json\JsonResource;
@@ -24,6 +25,8 @@ class UserResource extends JsonResource
'telefono' => $this->telefono,
'rol_codigo' => $this->rol_codigo,
'tenant_codigo' => $this->tenant_codigo,
'admin_scope' => $this->when($this->rol_codigo === RoleCode::AdminApp->value, $this->admin_scope),
'event_id' => $this->when(in_array($this->rol_codigo, [RoleCode::AdminApp->value, RoleCode::Scanner->value], true), $this->event_id),
'categories' => $this->whenLoaded('scanCategories', fn () => $this->scanCategories
->map(fn ($category) => [
'id' => $category->id,

View File

@@ -0,0 +1,27 @@
<?php
namespace App\Domains\Core\Auth\Services;
use App\Domains\Core\Auth\Enums\AdminScope;
use App\Domains\Core\Auth\Models\User;
use App\Domains\Core\Authorization\Enums\RoleCode;
class AdminAppAccessService
{
public function hasValidScope(User $user): bool
{
if ($user->rol_codigo !== RoleCode::AdminApp->value
|| ! $user->tenant_codigo
|| ! $user->tenant()->exists()) {
return false;
}
if ($user->isTenantAdministrator()) {
return true;
}
return $user->admin_scope === AdminScope::Event->value
&& $user->event_id !== null
&& $user->event()->where('tenant_code', $user->tenant_codigo)->exists();
}
}

View File

@@ -20,6 +20,7 @@ class AdminAppContextService
->firstOrFail();
$user->setRelation('tenant', $tenant);
$user->load('event');
return $user;
}

View File

@@ -0,0 +1,24 @@
<?php
namespace App\Domains\Core\Auth\Services;
use App\Domains\Core\Auth\Enums\AdminScope;
use App\Domains\Core\Auth\Models\User;
use Illuminate\Auth\Access\AuthorizationException;
class EventScopeService
{
public function eventId(User $user): ?int
{
if ($user->admin_scope === AdminScope::Event->value || $user->event_id !== null) {
if ($user->event_id === null
|| ! $user->event()->where('tenant_code', $user->tenant_codigo)->exists()) {
throw new AuthorizationException;
}
return $user->event_id;
}
return null;
}
}

View File

@@ -10,6 +10,7 @@ use App\Domains\Core\Authorization\Enums\PermissionCode;
use App\Domains\Core\Authorization\Enums\RoleCode;
use App\Shared\Notification\Events\PasswordResetRequested;
use Carbon\CarbonImmutable;
use Illuminate\Auth\Access\AuthorizationException;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Hash;
use Illuminate\Support\Facades\Log;
@@ -19,6 +20,7 @@ class PasswordLoginService
{
public function __construct(
private readonly ResetPasswordAttemptService $resetPasswordAttemptService,
private readonly AdminAppAccessService $adminAppAccessService,
) {}
/**
@@ -196,6 +198,26 @@ class PasswordLoginService
];
}
if ($requiredRole === RoleCode::AdminApp && ! $this->adminAppAccessService->hasValidScope($user)) {
$this->recordAttempt(
$user, $normalizedEmail, $attemptTenantCode,
LoginAttempt::OUTCOME_INVALID_CREDENTIALS, $ipAddress, $userAgent,
);
return ['outcome' => LoginAttempt::OUTCOME_INVALID_CREDENTIALS, 'user' => $user, 'locked_until' => null];
}
if ($requiredRole === RoleCode::Scanner) {
try {
app(EventScopeService::class)->eventId($user);
} catch (AuthorizationException) {
$this->recordAttempt($user, $normalizedEmail, $attemptTenantCode,
LoginAttempt::OUTCOME_INVALID_CREDENTIALS, $ipAddress, $userAgent);
return ['outcome' => LoginAttempt::OUTCOME_INVALID_CREDENTIALS, 'user' => $user, 'locked_until' => null];
}
}
$user->forceFill([
'failed_login_attempts' => 0,
'last_failed_login_at' => null,

View File

@@ -18,6 +18,7 @@ class ScannerContextService
->firstOrFail();
$user->setRelation('tenant', $tenant);
$user->load('event');
if ($tenant->requiresScannerCategoryValidation()) {
$categories = $user->scanCategories()

View File

@@ -17,6 +17,6 @@ Route::prefix('v1/adminapp')->group(function (): void {
Route::post('password/reset', ResetPasswordController::class)
->defaults('reset_role', 'adminapp')
->middleware('throttle:5,1');
Route::middleware(['auth:sanctum', 'adminapp.tenant'])
Route::middleware(['auth:sanctum', 'adminapp.tenant:context'])
->get('me', AdminAppMeController::class);
});

View File

@@ -2,8 +2,9 @@
namespace App\Domains\Core\Client\Models;
use App\Shared\Integration\Models\ClientIntegration;
use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Ticketing\Event\Models\Event;
use App\Shared\Integration\Models\ClientIntegration;
use Illuminate\Database\Eloquent\Attributes\Fillable;
use Illuminate\Database\Eloquent\Model;
use Illuminate\Database\Eloquent\Relations\HasMany;
@@ -22,6 +23,12 @@ class Client extends Model
return $this->hasMany(Tenant::class);
}
/** @return HasMany<Event, $this> */
public function events(): HasMany
{
return $this->hasMany(Event::class);
}
/** @return HasMany<ClientIntegration, $this> */
public function integrations(): HasMany
{

View File

@@ -2,6 +2,7 @@
namespace App\Domains\Core\Staff\Controllers;
use App\Domains\Core\Auth\Services\EventScopeService;
use App\Domains\Core\Staff\Requests\StoreStaffRequest;
use App\Domains\Core\Staff\Requests\UpdateStaffRequest;
use App\Domains\Core\Staff\Resources\StaffResource;
@@ -21,11 +22,17 @@ class AdminAppStaffController extends Controller
private readonly ScannerTicketService $scannerTicketService,
) {}
private function eventId(Request $request): ?int
{
return app(EventScopeService::class)->eventId($request->user());
}
public function index(Request $request): AnonymousResourceCollection
{
return StaffResource::collection($this->staffService->list(
$request->user()->tenant()->firstOrFail(),
$request->string('search')->trim()->toString() ?: null,
$this->eventId($request),
));
}
@@ -34,6 +41,7 @@ class AdminAppStaffController extends Controller
return StaffResource::make($this->staffService->create(
$request->user()->tenant()->firstOrFail(),
$request->validated(),
$this->eventId($request),
));
}
@@ -43,12 +51,13 @@ class AdminAppStaffController extends Controller
$request->user()->tenant()->firstOrFail(),
$staff,
$request->validated(),
$this->eventId($request),
));
}
public function destroy(Request $request, int $staff): Response
{
$this->staffService->delete($request->user()->tenant()->firstOrFail(), $staff);
$this->staffService->delete($request->user()->tenant()->firstOrFail(), $staff, $this->eventId($request));
return response()->noContent();
}
@@ -60,6 +69,7 @@ class AdminAppStaffController extends Controller
$scanner = $this->staffService->find(
$request->user()->tenant()->firstOrFail(),
$staff,
$this->eventId($request),
);
return ScanAttemptResource::collection(

View File

@@ -14,6 +14,7 @@ class StaffResource extends JsonResource
{
return [
'id' => $this->id,
'event_id' => $this->event_id,
'nombre_apellido' => $this->nombre_apellido,
'dni' => $this->dni,
'email' => $this->email,

View File

@@ -2,12 +2,13 @@
namespace App\Domains\Core\Staff\Services;
use App\Domains\Commerce\Catalog\Models\Category;
use App\Domains\Core\Auth\Models\ResetPasswordAttempt;
use App\Domains\Core\Auth\Models\User;
use App\Domains\Core\Auth\Services\ResetPasswordAttemptService;
use App\Domains\Core\Authorization\Enums\RoleCode;
use App\Domains\Commerce\Catalog\Models\Category;
use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Ticketing\Event\Models\Event;
use Illuminate\Database\Eloquent\Builder;
use Illuminate\Database\Eloquent\Collection;
use Illuminate\Support\Arr;
@@ -22,9 +23,9 @@ class StaffService
) {}
/** @return Collection<int, User> */
public function list(Tenant $tenant, ?string $search = null): Collection
public function list(Tenant $tenant, ?string $search = null, ?int $eventId = null): Collection
{
return $this->staffQuery($tenant)
return $this->staffQuery($tenant, $eventId)
->with(['role', 'scanCategories' => fn ($query) => $query->orderBy('nombre')])
->when($search, function (Builder $query, string $search): void {
$query->where(function (Builder $query) use ($search): void {
@@ -38,7 +39,7 @@ class StaffService
}
/** @return Collection<int, Category> */
private function assignableCategories(Tenant $tenant): Collection
private function assignableCategories(Tenant $tenant, ?int $eventId = null): Collection
{
return Category::query()
->whereNull('categoria_id')
@@ -47,23 +48,30 @@ class StaffService
->orWhereHas('catalogItems', fn (Builder $items) => $items
->where('tenant_code', $tenant->codigo));
})
->when($eventId !== null, fn (Builder $query) => $query->whereHas(
'catalogItems', fn (Builder $items) => $items->where('tenant_code', $tenant->codigo)->where('event_id', $eventId)))
->orderBy('nombre')
->get();
}
/** @param array<string, mixed> $data */
public function create(Tenant $tenant, array $data): User
public function create(Tenant $tenant, array $data, ?int $eventId = null): User
{
$eventId ??= $tenant->active_event_id;
Event::query()
->where('tenant_code', $tenant->codigo)->findOrFail($eventId);
$categoryIds = $this->categoryIdsFor($tenant, $data);
$this->assertCategoriesBelongToTenant($tenant, $categoryIds);
$this->assertCategoriesBelongToTenant($tenant, $categoryIds, $eventId);
return DB::transaction(function () use ($tenant, $data, $categoryIds): User {
return DB::transaction(function () use ($tenant, $data, $categoryIds, $eventId): User {
$staff = User::query()->create([
...Arr::only($data, ['nombre_apellido', 'dni', 'email']),
'email' => mb_strtolower(trim((string) $data['email'])),
'password' => Str::random(64),
'rol_codigo' => RoleCode::Scanner->value,
'tenant_codigo' => $tenant->codigo,
'event_id' => $eventId,
'admin_scope' => $eventId === null ? 'tenant' : 'event',
]);
$staff->scanCategories()->sync($categoryIds);
$this->resetPasswordAttemptService->createForScannerEmail(
@@ -76,11 +84,11 @@ class StaffService
}
/** @param array<string, mixed> $data */
public function update(Tenant $tenant, int $staffId, array $data): User
public function update(Tenant $tenant, int $staffId, array $data, ?int $eventId = null): User
{
$staff = $this->find($tenant, $staffId);
$staff = $this->find($tenant, $staffId, $eventId);
$categoryIds = $this->categoryIdsFor($tenant, $data);
$this->assertCategoriesBelongToTenant($tenant, $categoryIds);
$this->assertCategoriesBelongToTenant($tenant, $categoryIds, $eventId);
return DB::transaction(function () use ($staff, $data, $categoryIds): User {
$attributes = Arr::only($data, ['nombre_apellido', 'dni', 'email']);
@@ -92,9 +100,9 @@ class StaffService
});
}
public function delete(Tenant $tenant, int $staffId): void
public function delete(Tenant $tenant, int $staffId, ?int $eventId = null): void
{
$staff = $this->find($tenant, $staffId);
$staff = $this->find($tenant, $staffId, $eventId);
DB::transaction(function () use ($staff): void {
$staff->tokens()->delete();
@@ -102,23 +110,24 @@ class StaffService
});
}
public function find(Tenant $tenant, int $staffId): User
public function find(Tenant $tenant, int $staffId, ?int $eventId = null): User
{
return $this->staffQuery($tenant)->findOrFail($staffId);
return $this->staffQuery($tenant, $eventId)->findOrFail($staffId);
}
private function staffQuery(Tenant $tenant): Builder
private function staffQuery(Tenant $tenant, ?int $eventId = null): Builder
{
return User::query()
->where('tenant_codigo', $tenant->codigo)
->where('rol_codigo', RoleCode::Scanner->value);
->where('rol_codigo', RoleCode::Scanner->value)
->when($eventId !== null, fn (Builder $query) => $query->where('event_id', $eventId));
}
/**
* @param array<string, mixed> $data
* @return array<int, int>
*/
private function categoryIdsFor(Tenant $tenant, array $data): array
private function categoryIdsFor(Tenant $tenant, array $data, ?int $eventId = null): array
{
if (! $tenant->requiresScannerCategoryValidation()) {
return [];
@@ -128,9 +137,9 @@ class StaffService
}
/** @param array<int, int> $categoryIds */
private function assertCategoriesBelongToTenant(Tenant $tenant, array $categoryIds): void
private function assertCategoriesBelongToTenant(Tenant $tenant, array $categoryIds, ?int $eventId = null): void
{
$validIds = $this->assignableCategories($tenant)
$validIds = $this->assignableCategories($tenant, $eventId)
->whereIn('id', $categoryIds)
->pluck('id');

View File

@@ -18,3 +18,13 @@ Recurso REST `/v1/adminapp/tenant/staff`, excepto detalle individual, protegido
## Dependencias y reglas
Usa `Auth/User` como entidad de personal, `Authorization` para su rol, `Catalog/Category` para asignaciones y `Tenant` para aislamiento. Toda búsqueda, edición o borrado debe comprobar que el usuario pertenece al tenant autenticado.
## Alcance por evento
Los endpoints de Staff y su formulario aceptan `adminapp.tenant:event`. Un admin
de evento lista, edita, elimina y consulta el historial solo de scanners de su
evento. El backend asigna el evento al crear un scanner y no acepta cambios de
asignación desde el formulario. Las categorías autorizables se limitan a las
usadas por productos del evento. Los scanners aplican además su evento en
lectura de tickets, escaneo e historial. Los intentos registran `event_id` para
conservar el aislamiento aunque cambie la asignación del scanner.

View File

@@ -4,7 +4,7 @@ use App\Domains\Core\Staff\Controllers\AdminAppStaffController;
use Illuminate\Support\Facades\Route;
Route::prefix('v1/adminapp/tenant')
->middleware(['auth:sanctum', 'adminapp.tenant'])
->middleware(['auth:sanctum', 'adminapp.tenant:event'])
->group(function (): void {
Route::get('staff/{staff}/scan-attempts', [AdminAppStaffController::class, 'scanAttempts']);
Route::apiResource('staff', AdminAppStaffController::class)->except('show');

View File

@@ -2,6 +2,7 @@
namespace App\Domains\Ticketing\Event\Controllers\AdminApp;
use App\Domains\Core\Auth\Services\EventScopeService;
use App\Domains\Ticketing\Event\Models\EventDate;
use App\Domains\Ticketing\Event\Requests\RescheduleEventDateRequest;
use App\Domains\Ticketing\Event\Requests\StoreEventDateRequest;
@@ -19,7 +20,8 @@ class EventController extends Controller
public function show(Request $request): EventResource
{
return EventResource::make(
$this->eventService->forTenant($request->user()->tenant()->firstOrFail())
$this->eventService->forTenant($request->user()->tenant()->firstOrFail(),
app(EventScopeService::class)->eventId($request->user()))
);
}
@@ -28,7 +30,8 @@ class EventController extends Controller
return EventResource::make(
$this->eventService->updateForTenant(
$request->user()->tenant()->firstOrFail(),
$request->validated()
$request->validated(),
app(EventScopeService::class)->eventId($request->user())
)
);
}
@@ -39,6 +42,7 @@ class EventController extends Controller
$this->eventService->createDateForTenant(
$request->user()->tenant()->firstOrFail(),
$request->validated(),
app(EventScopeService::class)->eventId($request->user()),
)
);
}

View File

@@ -3,6 +3,7 @@
namespace App\Domains\Ticketing\Event\Models;
use App\Domains\Commerce\Catalog\Models\CatalogItem;
use App\Domains\Core\Client\Models\Client;
use App\Domains\Core\Tenant\Models\SocialMedia;
use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Ticketing\Ticket\Models\Ticket;
@@ -14,14 +15,27 @@ use Illuminate\Database\Eloquent\Relations\BelongsTo;
use Illuminate\Database\Eloquent\Relations\BelongsToMany;
use Illuminate\Database\Eloquent\Relations\HasMany;
#[Fillable(['tenant_code', 'slug', 'event_category_id', 'title', 'subtitle', 'description', 'location', 'exact_location', 'date_text', 'published_at', 'attachment_id'])]
#[Fillable(['client_id', 'tenant_code', 'slug', 'event_category_id', 'title', 'subtitle', 'description', 'location', 'exact_location', 'date_text', 'published_at', 'attachment_id', 'allow_ticket_refund', 'allow_ticket_total_refund', 'allow_ticket_partial_refund', 'ticket_partial_refund_percentage'])]
class Event extends Model
{
use HasFactory;
protected function casts(): array
{
return ['published_at' => 'datetime', 'exact_location' => 'array'];
return ['allow_ticket_refund' => 'boolean', 'allow_ticket_total_refund' => 'boolean',
'allow_ticket_partial_refund' => 'boolean', 'ticket_partial_refund_percentage' => 'decimal:2', 'client_id' => 'integer', 'published_at' => 'datetime', 'exact_location' => 'array'];
}
public function allow_refund(): bool
{
return (bool) $this->allow_ticket_refund
&& ((bool) $this->allow_ticket_total_refund || $this->allow_partial_refund());
}
public function allow_partial_refund(): bool
{
return (bool) $this->allow_ticket_refund && (bool) $this->allow_ticket_partial_refund
&& (float) $this->ticket_partial_refund_percentage > 0;
}
/** @return BelongsTo<Tenant, $this> */
@@ -30,6 +44,17 @@ class Event extends Model
return $this->belongsTo(Tenant::class, 'tenant_code', 'codigo');
}
/** @return BelongsTo<Client, $this> */
public function client(): BelongsTo
{
return $this->belongsTo(Client::class);
}
public function effectiveClient(): Client
{
return $this->client ?? $this->tenant->client;
}
/** @return BelongsTo<EventCategory, $this> */
public function eventCategory(): BelongsTo
{

View File

@@ -26,10 +26,10 @@ class EventResource extends JsonResource
'date_text' => $this->date_text,
'published_at' => $this->published_at?->toIso8601String(),
'attachment_id' => $this->attachment_id,
'allow_ticket_refund' => $this->tenant->allow_ticket_refund,
'allow_ticket_total_refund' => $this->tenant->allow_ticket_total_refund,
'allow_ticket_partial_refund' => $this->tenant->allow_ticket_partial_refund,
'ticket_partial_refund_percentage' => $this->tenant->ticket_partial_refund_percentage,
'allow_ticket_refund' => $this->allow_ticket_refund,
'allow_ticket_total_refund' => $this->allow_ticket_total_refund,
'allow_ticket_partial_refund' => $this->allow_ticket_partial_refund,
'ticket_partial_refund_percentage' => $this->ticket_partial_refund_percentage,
'dates' => EventDateResource::collection(
app(EventDateGroupingService::class)->group($this->dates)
),

View File

@@ -2,18 +2,19 @@
namespace App\Domains\Ticketing\Event\Services;
use App\Domains\Core\Auth\Models\User;
use App\Domains\Commerce\Cart\Services\InvalidateEventDateCartsService;
use App\Domains\Commerce\Catalog\Models\Variant;
use App\Domains\Commerce\Catalog\Services\StockReservationService;
use App\Domains\Commerce\Catalog\Services\VariantReplacementService;
use App\Domains\Core\Auth\Models\User;
use App\Domains\Core\Auth\Services\EventScopeService;
use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Ticketing\Event\Enums\EventDateChangeType;
use App\Domains\Ticketing\Event\Events\EventDateRescheduled;
use App\Domains\Ticketing\Event\Events\EventDateSuspended;
use App\Domains\Ticketing\Event\Models\Event;
use App\Domains\Ticketing\Event\Models\EventDate;
use App\Domains\Ticketing\Event\Models\EventDateChange;
use App\Domains\Ticketing\Event\Models\Event;
use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Ticketing\Ticket\Models\Ticket;
use Illuminate\Support\Collection;
use Illuminate\Support\Facades\DB;
@@ -34,22 +35,22 @@ class EventService
private readonly InvalidateEventDateCartsService $invalidateEventDateCarts,
) {}
public function forTenant(Tenant $tenant): Event
public function forTenant(Tenant $tenant, ?int $eventId = null): Event
{
return $tenant->activeEvent->load(['dates.validityTime', 'socialMedia']);
return $this->resolveEvent($tenant, $eventId)->load(['dates.validityTime', 'socialMedia']);
}
/** @param array<string, mixed> $data */
public function updateForTenant(Tenant $tenant, array $data): Event
public function updateForTenant(Tenant $tenant, array $data, ?int $eventId = null): Event
{
return DB::transaction(function () use ($tenant, $data): Event {
$event = $tenant->activeEvent;
return DB::transaction(function () use ($tenant, $data, $eventId): Event {
$event = $this->resolveEvent($tenant, $eventId);
$event->update([
'title' => $data['title'],
'location' => $data['location'],
...array_intersect_key($data, ['attachment_id' => true, 'exact_location' => true]),
]);
$tenant->update([
$event->update([
...array_intersect_key($data, array_flip([
'allow_ticket_refund',
'allow_ticket_total_refund',
@@ -69,10 +70,10 @@ class EventService
}
/** @param array{date: string, start_time: string, end_time: string} $data */
public function createDateForTenant(Tenant $tenant, array $data): EventDate
public function createDateForTenant(Tenant $tenant, array $data, ?int $eventId = null): EventDate
{
return DB::transaction(function () use ($tenant, $data): EventDate {
$event = $tenant->activeEvent;
return DB::transaction(function () use ($tenant, $data, $eventId): EventDate {
$event = $this->resolveEvent($tenant, $eventId);
$attributes = $this->dateAttributes($data);
if ($event->dates()->where($attributes)->exists()) {
@@ -93,7 +94,7 @@ class EventService
?User $createdBy = null,
): EventDate {
return DB::transaction(function () use ($tenant, $eventDate, $data, $createdBy): EventDate {
$source = $this->lockedDateForTenant($tenant, $eventDate);
$source = $this->lockedDateForTenant($tenant, $eventDate, $createdBy);
if ($source->suspended_at !== null) {
throw ValidationException::withMessages([
@@ -172,7 +173,7 @@ class EventService
?User $createdBy = null,
): EventDate {
return DB::transaction(function () use ($tenant, $eventDate, $createdBy): EventDate {
$date = $this->lockedDateForTenant($tenant, $eventDate);
$date = $this->lockedDateForTenant($tenant, $eventDate, $createdBy);
if ($date->rescheduled_to_event_date_id !== null) {
throw ValidationException::withMessages([
@@ -216,10 +217,18 @@ class EventService
});
}
private function lockedDateForTenant(Tenant $tenant, EventDate $eventDate): EventDate
private function resolveEvent(Tenant $tenant, ?int $eventId): Event
{
return Event::query()->where('tenant_code', $tenant->codigo)
->findOrFail($eventId ?? $tenant->active_event_id);
}
private function lockedDateForTenant(Tenant $tenant, EventDate $eventDate, ?User $actor = null): EventDate
{
return $tenant->eventDates()
->whereKey($eventDate->getKey())
->when($actor !== null && ! $actor->isTenantAdministrator(),
fn ($query) => $query->where('event_id', app(EventScopeService::class)->eventId($actor)))
->lockForUpdate()
->firstOrFail();
}

View File

@@ -37,10 +37,10 @@ se guardan en el evento. Sin evento activo se conservan las redes propias del te
## API
Los endpoints de AdminApp usan `auth:sanctum` y `adminapp.tenant`:
Los endpoints de AdminApp usan `auth:sanctum` y `adminapp.tenant:event`:
- `GET/PUT /v1/adminapp/tenant/event`: acceso al evento seleccionado para el
storefront de evento único.
- `GET/PUT /v1/adminapp/tenant/event`: acceso al evento asociado al usuario con scope de evento;
para admins de tenant se conserva el evento activo.
- `POST /v1/adminapp/tenant/event-dates`: crea una fecha para ese evento.
- `POST /v1/adminapp/tenant/event-dates/{eventDate}/reschedule` y
`POST /v1/adminapp/tenant/event-dates/{eventDate}/suspend`: cambios de fecha.
@@ -53,3 +53,8 @@ una lista de eventos ni existe todavía una pantalla para gestionarlos.
Las fechas se vinculan con variantes de `Catalog`, que a su vez pueden generar
tickets. Los avisos por suspensión y reprogramación se construyen dinámicamente
después de excluir los cambios que el usuario ya vio tres veces.
La configuración de devoluciones se persiste en `events`, se entrega en
`EventResource` y se aplica al evento de cada ticket. La migración inicial copia
los valores anteriores del tenant a sus eventos. Las fechas se autorizan por
tenant y por evento antes de cualquier suspensión o reprogramación.

View File

@@ -4,7 +4,7 @@ use App\Domains\Ticketing\Event\Controllers\AdminApp\EventController;
use Illuminate\Support\Facades\Route;
Route::prefix('v1/adminapp/tenant')
->middleware(['auth:sanctum', 'adminapp.tenant'])
->middleware(['auth:sanctum', 'adminapp.tenant:event'])
->group(function (): void {
Route::get('event', [EventController::class, 'show']);
Route::put('event', [EventController::class, 'update']);

View File

@@ -11,6 +11,7 @@ use Illuminate\Database\Eloquent\Relations\BelongsTo;
#[Fillable([
'tenant_code',
'event_id',
'scanner_user_id',
'ticket_id',
'data',
@@ -43,6 +44,7 @@ class ScanAttempt extends Model
{
return [
'scanner_user_id' => 'integer',
'event_id' => 'integer',
'ticket_id' => 'integer',
'result' => ScanAttemptResult::class,
'created_at' => 'datetime',

View File

@@ -7,6 +7,7 @@ use App\Domains\Commerce\Catalog\Models\Variant;
use App\Domains\Commerce\Purchase\Models\PurchaseItem;
use App\Domains\Core\Auth\Models\User;
use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Ticketing\Desfile\Models\EntryReservation;
use App\Domains\Ticketing\Event\Models\Event;
use App\Domains\Ticketing\Ticket\Services\ResolvedTicketValidity;
use App\Domains\Ticketing\Ticket\Services\ResolvedValidityGroup;
@@ -147,7 +148,9 @@ class Ticket extends Model
public function allow_refund(): bool
{
return $this->tenant?->allow_refund() ?? false;
return $this->event_id === null
? ($this->tenant?->allow_refund() ?? false)
: ($this->event?->allow_refund() ?? false);
}
public function allowRefund(): bool
@@ -192,7 +195,9 @@ class Ticket extends Model
public function can_refund(): bool
{
return $this->is_active() && $this->allow_refund();
return $this->is_active()
&& $this->allow_refund()
&& ! $this->hasEntryReservation();
}
public function canRefund(): bool
@@ -235,6 +240,12 @@ class Ticket extends Model
return $this->hasOne(TicketRefund::class);
}
/** @return HasOne<EntryReservation, $this> */
public function entryReservation(): HasOne
{
return $this->hasOne(EntryReservation::class);
}
/** @return BelongsTo<CatalogItem, $this> */
public function sourceCatalogItem(): BelongsTo
{
@@ -247,6 +258,15 @@ class Ticket extends Model
return $this->belongsTo(Variant::class, 'source_variant_id')->withTrashed();
}
private function hasEntryReservation(): bool
{
if ($this->relationLoaded('entryReservation')) {
return $this->getRelation('entryReservation') instanceof EntryReservation;
}
return $this->exists && $this->entryReservation()->exists();
}
public function isValid(): bool
{
if ($this->hasTerminalStatus() || $this->used_at !== null) {

View File

@@ -3,6 +3,7 @@
namespace App\Domains\Ticketing\Ticket\Requests;
use App\Domains\Ticketing\Ticket\Models\Ticket;
use App\Domains\Ticketing\Ticket\Services\AdminAppTicketAttributeService;
use App\Domains\Ticketing\Ticket\Services\AdminAppTicketColumnService;
use Illuminate\Foundation\Http\FormRequest;
use Illuminate\Validation\Rule;
@@ -22,7 +23,7 @@ class AdminAppTicketIndexRequest extends FormRequest
? []
: app(AdminAppTicketColumnService::class)->sortableKeys($tenant);
return [
$rules = [
'q' => ['sometimes', 'nullable', 'string', 'max:255'],
'category' => ['sometimes', 'nullable', 'string', 'max:255'],
'product' => ['sometimes', 'nullable', 'string', 'max:255'],
@@ -39,5 +40,18 @@ class AdminAppTicketIndexRequest extends FormRequest
'sort_by' => ['sometimes', 'nullable', 'string', Rule::in($sortableKeys)],
'sort_direction' => ['sometimes', 'nullable', 'string', Rule::in(['asc', 'desc'])],
];
if ($tenant !== null) {
foreach (app(AdminAppTicketAttributeService::class)->attributes($tenant) as $attribute) {
$rules[$attribute['code']] = [
'sometimes',
'nullable',
'string',
Rule::in(array_column($attribute['options'], 'value')),
];
}
}
return $rules;
}
}

View File

@@ -32,7 +32,7 @@ class ScanAttemptResource extends JsonResource
ScanAttemptResult::Processing => 'Error',
ScanAttemptResult::Accepted => 'Verificado',
ScanAttemptResult::InvalidQr => 'QR no pertenece al evento',
ScanAttemptResult::TicketNotFound => 'Error',
ScanAttemptResult::TicketNotFound => 'QR no pertenece al evento',
ScanAttemptResult::CategoryForbidden => 'Error',
ScanAttemptResult::AlreadyScanned => 'Usado',
ScanAttemptResult::Expired => 'Vencido',

View File

@@ -0,0 +1,92 @@
<?php
namespace App\Domains\Ticketing\Ticket\Services;
use App\Domains\Commerce\Catalog\Models\CatalogItem;
use App\Domains\Core\Tenant\Models\Tenant;
use Illuminate\Database\Eloquent\Builder;
class AdminAppTicketAttributeService
{
private const DESFILE_PURA_TENDENCIA = 'desfile_pura_tendencia';
/**
* @return list<array{
* code: string,
* label: string,
* options: list<array{value: string, label: string}>
* }>
*/
public function attributes(Tenant $tenant): array
{
if ($tenant->codigo !== self::DESFILE_PURA_TENDENCIA) {
return [];
}
$items = CatalogItem::withTrashed()
->where('tenant_code', $tenant->codigo)
->where(function (Builder $query): void {
$query
->where(function (Builder $activeQuery): void {
$activeQuery
->whereNull('catalog_items.deleted_at')
->where('has_tickets', true);
})
->orWhereHas('sourceTickets');
})
->with([
'itemAttributes' => fn ($query) => $query->orderBy('sort_order')->orderBy('id'),
'itemAttributes.attribute.options',
'variants' => fn ($query) => $query
->withTrashed()
->where(fn (Builder $variantQuery): Builder => $variantQuery
->whereNull('variantes.deleted_at')
->orWhereHas('sourceTickets'))
->orderBy('id'),
'variants.definitions.itemAttribute.attribute.options',
])
->get();
$attributes = [];
foreach ($items as $item) {
foreach ($item->itemAttributes as $itemAttribute) {
$attribute = $itemAttribute->attribute;
if ($attribute === null) {
continue;
}
$code = $attribute->codigo;
$attributes[$code] ??= [
'code' => $code,
'label' => $itemAttribute->ticket_label ?: $attribute->nombre,
'sort_order' => $itemAttribute->sort_order,
'options' => [],
];
foreach ($item->variants as $variant) {
$definition = $variant->definitions->firstWhere('item_attribute_id', $itemAttribute->id);
if ($definition === null) {
continue;
}
$value = (string) $definition->value;
$option = $attribute->options->firstWhere('value', $value);
$attributes[$code]['options'][$value] = [
'value' => $value,
'label' => (string) ($option?->label ?: $value),
];
}
}
}
uasort($attributes, fn (array $left, array $right): int => $left['sort_order'] <=> $right['sort_order']
?: $left['label'] <=> $right['label']);
return array_values(array_map(fn (array $attribute): array => [
'code' => $attribute['code'],
'label' => $attribute['label'],
'options' => array_values($attribute['options']),
], $attributes));
}
}

View File

@@ -8,9 +8,17 @@ class AdminAppTicketColumnService
{
private const FIESTA_FUTBOL_INFANTIL = 'fiesta_futbol_infantil';
private const DESFILE_PURA_TENDENCIA = 'desfile_pura_tendencia';
public function __construct(private readonly AdminAppTicketAttributeService $attributeService) {}
/** @return list<array{key: string, label: string, type: string, sortable: bool, sort_param: string, width: string, excel_width: int}> */
public function columns(Tenant $tenant): array
{
if ($tenant->codigo === self::DESFILE_PURA_TENDENCIA) {
return $this->desfileColumns($tenant);
}
$keys = $tenant->codigo === self::FIESTA_FUTBOL_INFANTIL
? ['order_number', 'category', 'product', 'type', 'date', 'size', 'amount', 'client', 'id', 'status', 'scanned_by']
: ['order_number', 'product', 'amount', 'client', 'id', 'status', 'scanned_by'];
@@ -45,6 +53,31 @@ class AdminAppTicketColumnService
return $columns;
}
/** @return list<array{key: string, label: string, type: string, sortable: bool, sort_param: string, width: string, excel_width: int}> */
private function desfileColumns(Tenant $tenant): array
{
$attributeColumns = array_map(fn (array $attribute): array => [
'key' => $attribute['code'],
'label' => $attribute['label'],
'type' => 'text',
'sortable' => false,
'sort_param' => $attribute['code'],
'width' => '8%',
'excel_width' => 15,
], $this->attributeService->attributes($tenant));
return [
$this->definitions()['order_number'],
$this->definitions()['product'],
...$attributeColumns,
$this->definitions()['amount'],
$this->definitions()['client'],
$this->definitions()['id'],
$this->definitions()['status'],
$this->definitions()['scanned_by'],
];
}
/** @return list<array{key: string, label: string, type: string, sortable: bool, sort_param: string, width: string}> */
public function publicColumns(Tenant $tenant): array
{

View File

@@ -11,6 +11,8 @@ class AdminAppTicketRowService
{
private const FIESTA_FUTBOL_INFANTIL = 'fiesta_futbol_infantil';
private const DESFILE_PURA_TENDENCIA = 'desfile_pura_tendencia';
private const CATEGORY_PRESENTATIONS = [
'alojamientos' => ['category' => 'Camping', 'product' => 'tipo_alojamiento', 'type' => null, 'size' => null],
'camping' => ['category' => null, 'product' => 'tipo_alojamiento', 'type' => null, 'size' => null],
@@ -25,31 +27,65 @@ class AdminAppTicketRowService
{
$purchaseItem = $ticket->sourcePurchaseItem;
$refund = $ticket->refund;
$variantProperties = $this->variantProperties($ticket);
return [
'source_purchase_item_id' => $ticket->source_purchase_item_id,
'order_number' => $purchaseItem?->compra_id,
'product' => $purchaseItem?->item_nombre
?? $ticket->sourceCatalogItem?->nombre
?? $ticket->name,
'amount' => $purchaseItem?->precio_unitario,
'product' => $this->productName($ticket, $purchaseItem?->item_nombre, $variantProperties),
'amount' => $purchaseItem?->precio_unitario ?? $ticket->entryReservation?->importe,
'refund_type' => $refund?->type,
'refund_type_label' => $refund?->typeLabel(),
'client' => $purchaseItem?->purchase?->nombre_apellido ?? $ticket->user?->nombre_apellido,
'status' => $ticket->status,
'scanned_by' => $ticket->scannerUser?->nombre_apellido,
'variant_properties' => $this->variantProperties($ticket),
'variant_properties' => $variantProperties,
'allow_refund' => $ticket->allow_refund(),
];
}
/**
* @param list<array{code: string, label: string, values: list<array{value: string, label: string}>}> $properties
*/
private function productName(Ticket $ticket, ?string $snapshotName, array $properties): string
{
$baseName = $ticket->sourceCatalogItem?->nombre ?: $ticket->name;
if ($ticket->tenant_code !== self::DESFILE_PURA_TENDENCIA) {
return $snapshotName ?: $baseName;
}
$seatDescription = collect(['sector', 'fila', 'asiento'])
->map(function (string $code) use ($properties): ?string {
$property = collect($properties)->firstWhere('code', $code);
$values = collect($property['values'] ?? [])->pluck('label')->filter()->implode(', ');
return $property === null || $values === ''
? null
: $property['label'].' '.$values;
})
->filter()
->implode(', ');
return $seatDescription === '' ? ($snapshotName ?: $baseName) : "{$baseName} ({$seatDescription})";
}
/** @param array<string, mixed>|null $details */
public function values(Ticket $ticket, ?array $details = null): array
{
$details ??= $this->details($ticket);
$presentation = $this->presentation($ticket, $details);
$attributeValues = collect($details['variant_properties'] ?? [])
->mapWithKeys(fn (array $property): array => [
$property['code'] => collect($property['values'] ?? [])
->pluck('label')
->filter()
->implode(', ') ?: '-',
])
->all();
return [
...$attributeValues,
'order_number' => $details['order_number'],
'category' => $presentation['category'],
'product' => $presentation['product'],

View File

@@ -2,13 +2,14 @@
namespace App\Domains\Ticketing\Ticket\Services;
use App\Domains\Core\Auth\Models\User;
use App\Domains\Commerce\Catalog\Enums\InventoryPolicy;
use App\Domains\Commerce\Catalog\Models\Inventory;
use App\Domains\Commerce\Catalog\Models\Variant;
use App\Domains\Commerce\Purchase\Models\PurchaseItem;
use App\Domains\Commerce\Purchase\Services\PurchaseRefundSummaryService;
use App\Domains\Core\Auth\Models\User;
use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Ticketing\Event\Models\Event;
use App\Domains\Ticketing\Ticket\Models\Ticket;
use App\Domains\Ticketing\Ticket\Models\TicketRefund;
use Illuminate\Database\Eloquent\Builder;
@@ -23,15 +24,18 @@ class AdminAppTicketService
...TicketValidityResolver::RELATIONS,
...TicketPresentationResolver::RELATIONS,
'tenant',
'event',
'user',
'scannerUser',
'sourceCatalogItem.category',
'sourcePurchaseItem.purchase',
'entryReservation',
'refund.createdBy',
];
public function __construct(
private readonly AdminAppTicketColumnService $columnService,
private readonly AdminAppTicketAttributeService $attributeService,
private readonly AdminAppTicketRowService $rowService,
private readonly PurchaseRefundSummaryService $refundSummaryService,
) {}
@@ -143,19 +147,20 @@ class AdminAppTicketService
]);
}
$configuration = $ticket->event_id === null ? $tenant : $ticket->event;
$unitPrice = (float) $purchaseItem->precio_unitario;
$itemTotal = (float) $purchaseItem->total;
$itemRefundedAmount = $this->refundedAmountForPurchaseItem($purchaseItem);
$remainingItemAmount = max(0.0, round($itemTotal - $itemRefundedAmount, 2));
$total = null;
if ($tenant->allow_refund() && $tenant->allow_ticket_total_refund && $unitPrice <= $remainingItemAmount) {
if ($configuration->allow_refund() && $configuration->allow_ticket_total_refund && $unitPrice <= $remainingItemAmount) {
$total = number_format($unitPrice, 2, '.', '');
}
$partial = null;
if ($tenant->allow_refund() && $tenant->allow_partial_refund()) {
$partialAmount = $this->refundAmount($purchaseItem, $tenant, 'partial');
if ($configuration->allow_refund() && $configuration->allow_partial_refund()) {
$partialAmount = $this->refundAmount($purchaseItem, $configuration, 'partial');
if ($partialAmount <= $remainingItemAmount) {
$partial = number_format($partialAmount, 2, '.', '');
}
@@ -173,14 +178,15 @@ class AdminAppTicketService
string $refundType,
?User $createdBy = null,
): Ticket {
$this->ensureRefundIsAllowed($tenant, $refundType);
return DB::transaction(function () use ($tenant, $ticketId, $refundType, $createdBy): Ticket {
$ticket = Ticket::query()
->where('tenant_code', $tenant->codigo)
->lockForUpdate()
->findOrFail($ticketId);
$configuration = $ticket->event_id === null ? $tenant : $ticket->event;
$this->ensureRefundIsAllowed($configuration, $refundType);
if (! $ticket->can_refund()) {
if ($ticket->status !== Ticket::STATUS_ACTIVE) {
throw ValidationException::withMessages([
@@ -203,7 +209,7 @@ class AdminAppTicketService
]);
}
$refundAmount = $this->refundAmount($purchaseItem, $tenant, $refundType);
$refundAmount = $this->refundAmount($purchaseItem, $configuration, $refundType);
$refundedAmount = round(
$this->refundedAmountForPurchaseItem($purchaseItem) + $refundAmount,
2,
@@ -284,7 +290,7 @@ class AdminAppTicketService
->sum('amount'), 2);
}
private function ensureRefundIsAllowed(Tenant $tenant, string $refundType): void
private function ensureRefundIsAllowed(Tenant|Event $tenant, string $refundType): void
{
$isAllowed = match ($refundType) {
TicketRefund::TYPE_PARTIAL => $tenant->allow_refund() && $tenant->allow_partial_refund(),
@@ -298,7 +304,7 @@ class AdminAppTicketService
}
}
private function refundAmount(PurchaseItem $purchaseItem, Tenant $tenant, string $refundType): float
private function refundAmount(PurchaseItem $purchaseItem, Tenant|Event $tenant, string $refundType): float
{
$ticketAmount = (float) $purchaseItem->precio_unitario;
@@ -347,6 +353,13 @@ class AdminAppTicketService
$this->applyStatusFilter($query, $filters['status'] ?? null);
foreach ($this->attributeService->attributes($tenant) as $attribute) {
$value = $filters[$attribute['code']] ?? null;
if ($value !== null && $value !== '') {
$this->whereVariantDefinition($query, $attribute['code'], (string) $value);
}
}
return $query;
}

View File

@@ -3,6 +3,7 @@
namespace App\Domains\Ticketing\Ticket\Services;
use App\Domains\Core\Auth\Models\User;
use App\Domains\Core\Auth\Services\EventScopeService;
use App\Domains\Ticketing\Ticket\Enums\ScanAttemptResult;
use App\Domains\Ticketing\Ticket\Models\ScanAttempt;
use App\Domains\Ticketing\Ticket\Models\Ticket;
@@ -27,6 +28,7 @@ class ScannerTicketService
->with('ticket.sourceCatalogItem.category')
->where('tenant_code', $scanner->tenant_codigo)
->where('scanner_user_id', $scanner->getKey())
->when($this->eventId($scanner) !== null, fn (Builder $query) => $query->where('event_id', $this->eventId($scanner)))
->when($search !== '', function (Builder $query) use ($search): void {
$attemptedAtDate = $this->parseSearchDate($search);
@@ -60,6 +62,7 @@ class ScannerTicketService
->with('ticket.sourceCatalogItem.category')
->where('tenant_code', $scanner->tenant_codigo)
->where('scanner_user_id', $scanner->getKey())
->when($this->eventId($scanner) !== null, fn (Builder $query) => $query->where('event_id', $this->eventId($scanner)))
->when($search !== '', function (Builder $query) use ($search): void {
$attemptedAtDate = $this->parseSearchDate($search);
$attemptedAtDayMonth = $this->parseSearchDayMonth($search);
@@ -106,6 +109,7 @@ class ScannerTicketService
->with('ticket')
->where('tenant_code', $scanner->tenant_codigo)
->where('scanner_user_id', $scanner->getKey())
->when($this->eventId($scanner) !== null, fn (Builder $query) => $query->where('event_id', $this->eventId($scanner)))
->findOrFail($scanAttemptId);
$scanAttempt->ticket?->loadMissing($this->relations());
@@ -113,6 +117,11 @@ class ScannerTicketService
return $scanAttempt;
}
private function eventId(User $scanner): ?int
{
return app(EventScopeService::class)->eventId($scanner);
}
private function parseSearchDate(string $search): ?string
{
if (preg_match('/^(\d{4})-(\d{2})-(\d{2})$/', $search, $matches) === 1) {
@@ -154,7 +163,8 @@ class ScannerTicketService
{
$query = $this->baseQuery()
->where('tenant_code', $scanner->tenant_codigo)
->where('ticket', $ticketUuid);
->where('ticket', $ticketUuid)
->when($this->eventId($scanner) !== null, fn (Builder $query) => $query->where('event_id', $this->eventId($scanner)));
if ($this->requiresCategoryValidation($scanner)) {
$categoryIds = $this->scannerCategoryIds($scanner);
@@ -178,6 +188,7 @@ class ScannerTicketService
$scanAttempt = ScanAttempt::query()->create([
'tenant_code' => $scanner->tenant_codigo,
'scanner_user_id' => $scanner->getKey(),
'event_id' => $this->eventId($scanner),
'data' => $this->serializeScannedData($scannedData),
'result' => ScanAttemptResult::Processing,
]);
@@ -200,6 +211,7 @@ class ScannerTicketService
$ticket = $this->baseQuery()
->where('tenant_code', $scanner->tenant_codigo)
->where('ticket', $scannedData)
->when($this->eventId($scanner) !== null, fn (Builder $query) => $query->where('event_id', $this->eventId($scanner)))
->lockForUpdate()
->firstOrFail();
$ticketId = (int) $ticket->getKey();

View File

@@ -2,6 +2,7 @@
namespace App\Http\Middleware;
use App\Domains\Core\Auth\Services\AdminAppAccessService;
use App\Domains\Core\Authorization\Enums\RoleCode;
use Closure;
use Illuminate\Auth\Access\AuthorizationException;
@@ -10,10 +11,12 @@ use Symfony\Component\HttpFoundation\Response;
class EnsureAdminAppTenant
{
public function __construct(private readonly AdminAppAccessService $accessService) {}
/**
* Ensure the authenticated user is an AdminApp user bound to a tenant.
*/
public function handle(Request $request, Closure $next): Response
public function handle(Request $request, Closure $next, string $access = 'tenant'): Response
{
$user = $request->user();
@@ -21,6 +24,9 @@ class EnsureAdminAppTenant
! $user
|| $user->rol_codigo !== RoleCode::AdminApp->value
|| ! $user->tenant_codigo
|| ! $this->accessService->hasValidScope($user)
// Only routes implementing event authorization may accept event administrators.
|| (! in_array($access, ['context', 'event'], true) && ! $user->isTenantAdministrator())
) {
throw new AuthorizationException;
}

View File

@@ -2,6 +2,7 @@
namespace App\Http\Middleware;
use App\Domains\Core\Auth\Services\EventScopeService;
use App\Domains\Core\Authorization\Enums\PermissionCode;
use App\Domains\Core\Authorization\Enums\RoleCode;
use Closure;
@@ -27,6 +28,8 @@ class EnsureScannerTenant
throw new AuthorizationException;
}
app(EventScopeService::class)->eventId($user);
return $next($request);
}
}

View File

@@ -2,9 +2,10 @@
namespace App\Shared\Forms\Controllers\AdminApp;
use App\Domains\Core\Auth\Services\EventScopeService;
use App\Http\Controllers\Controller;
use App\Shared\Forms\Resources\EventFormResource;
use App\Shared\Forms\Services\EventFormService;
use App\Http\Controllers\Controller;
use Illuminate\Http\Request;
class EventFormController extends Controller
@@ -15,7 +16,8 @@ class EventFormController extends Controller
{
return EventFormResource::make(
$this->eventFormService->get(
$request->user('sanctum')->tenant()->firstOrFail()
$request->user('sanctum')->tenant()->firstOrFail(),
app(EventScopeService::class)->eventId($request->user())
)
);
}

View File

@@ -2,9 +2,10 @@
namespace App\Shared\Forms\Controllers\AdminApp;
use App\Domains\Core\Auth\Services\EventScopeService;
use App\Http\Controllers\Controller;
use App\Shared\Forms\Resources\StaffFormResource;
use App\Shared\Forms\Services\StaffFormService;
use App\Http\Controllers\Controller;
use Illuminate\Http\Request;
class StaffFormController extends Controller
@@ -15,7 +16,8 @@ class StaffFormController extends Controller
{
return StaffFormResource::make(
$this->staffFormService->get(
$request->user('sanctum')->tenant()->firstOrFail()
$request->user('sanctum')->tenant()->firstOrFail(),
app(EventScopeService::class)->eventId($request->user())
)
);
}

View File

@@ -4,14 +4,17 @@ namespace App\Shared\Forms\Services;
use App\Domains\Core\Tenant\Models\SocialMedia;
use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Ticketing\Event\Models\Event;
use Illuminate\Database\Eloquent\Collection;
class EventFormService
{
/** @return array{social_media: Collection<int, SocialMedia>} */
public function get(Tenant $tenant): array
public function get(Tenant $tenant, ?int $eventId = null): array
{
$event = $tenant->activeEvent;
$event = $eventId === null ? $tenant->activeEvent
: Event::query()
->where('tenant_code', $tenant->codigo)->findOrFail($eventId);
$urls = $event?->socialMedia()
->pluck('event_social_media.url', 'social_media.code') ?? collect();

View File

@@ -10,7 +10,7 @@ use Illuminate\Database\Eloquent\Collection;
class StaffFormService
{
/** @return array{categories: Collection<int, Category>} */
public function get(Tenant $tenant): array
public function get(Tenant $tenant, ?int $eventId = null): array
{
return [
'categories' => Category::query()
@@ -20,6 +20,8 @@ class StaffFormService
->orWhereHas('catalogItems', fn (Builder $items) => $items
->where('tenant_code', $tenant->codigo));
})
->when($eventId !== null, fn (Builder $query) => $query->whereHas(
'catalogItems', fn (Builder $items) => $items->where('tenant_code', $tenant->codigo)->where('event_id', $eventId)))
->orderBy('nombre')
->get(),
];

View File

@@ -4,15 +4,19 @@ namespace App\Shared\Forms\Services;
use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Ticketing\Ticket\Models\Ticket;
use App\Domains\Ticketing\Ticket\Services\AdminAppTicketAttributeService;
use App\Domains\Ticketing\Ticket\Services\AdminAppTicketColumnService;
class TicketFilterFormService
{
private const FIESTA_FUTBOL_INFANTIL = 'fiesta_futbol_infantil';
private const DESFILE_PURA_TENDENCIA = 'desfile_pura_tendencia';
public function __construct(
private readonly TicketFormService $ticketFormService,
private readonly AdminAppTicketColumnService $columnService,
private readonly AdminAppTicketAttributeService $attributeService,
) {}
/** @return array<string, mixed> */
@@ -27,6 +31,13 @@ class TicketFilterFormService
];
}
if ($tenant->codigo === self::DESFILE_PURA_TENDENCIA) {
$fields = [
...$this->desfileFields($tenant),
...$this->commonFields(),
];
}
return [
'code' => 'tickets_filter',
'action' => '/api/v1/adminapp/tenant/tickets',
@@ -36,6 +47,21 @@ class TicketFilterFormService
];
}
/** @return list<array<string, mixed>> */
private function desfileFields(Tenant $tenant): array
{
return array_map(fn (array $attribute): array => [
'name' => $attribute['code'],
'query_param' => $attribute['code'],
'label' => $attribute['label'],
'type' => 'select',
'required' => false,
'default' => null,
'placeholder' => $attribute['label'],
'options' => $attribute['options'],
], $this->attributeService->attributes($tenant));
}
/** @return list<array<string, mixed>> */
private function fiestaFutbolInfantilFields(Tenant $tenant): array
{

View File

@@ -12,33 +12,33 @@ use App\Shared\Forms\Controllers\AdminApp\TicketFormController;
use Illuminate\Support\Facades\Route;
Route::prefix('v1/adminapp/forms')
->middleware(['auth:sanctum', 'adminapp.tenant'])
->middleware(['auth:sanctum', 'adminapp.tenant:event'])
->group(function (): void {
Route::get('event', EventFormController::class);
Route::get(
'desfile/entry-reservation',
DesfileEntryReservationFormController::class
)->middleware('tenant.menu:adminapp.desfile.reservas')
)->middleware('adminapp.tenant')->middleware('tenant.menu:adminapp.desfile.reservas')
->name('adminapp.forms.desfile.entry-reservation');
Route::get('sale', SaleFormController::class);
Route::get('staff', StaffFormController::class);
Route::get('tickets-filter', TicketFilterFormController::class)
Route::get('tickets-filter', TicketFilterFormController::class)->middleware('adminapp.tenant')
->middleware('tenant.menu:adminapp.tickets')
->name('adminapp.forms.tickets-filter');
Route::get(
'fiesta-futbol-infantil/ticket',
TicketFormController::class
);
)->middleware('adminapp.tenant');
Route::get(
'fiesta-futbol-infantil/entry',
EntryFormController::class
);
)->middleware('adminapp.tenant');
Route::get(
'fiesta-futbol-infantil/merchandise',
MerchandiseFormController::class
);
)->middleware('adminapp.tenant');
Route::get(
'fiesta-futbol-infantil/food',
FoodFormController::class
);
)->middleware('adminapp.tenant');
});

View File

@@ -3,11 +3,12 @@
namespace App\Shared\Integration\Services;
use App\Domains\Core\Client\Models\Client;
use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Ticketing\Event\Models\Event;
use App\Shared\Integration\Models\AdminWebsiteTypeIntegration;
use App\Shared\Integration\Models\ClientIntegration;
use App\Shared\Integration\Models\Integration;
use App\Shared\Integration\Models\IntegrationInstance;
use App\Shared\Integration\Models\AdminWebsiteTypeIntegration;
use App\Domains\Core\Tenant\Models\Tenant;
use Exception;
use Illuminate\Http\Client\PendingRequest;
use Illuminate\Support\Facades\Http;
@@ -86,6 +87,17 @@ abstract class BaseIntegrationService
return $this;
}
public function forEvent(Event $event): self
{
$event->loadMissing(['client', 'tenant.client']);
$this->tenant = $event->tenant;
$this->tenantCode = $event->tenant_code;
$this->clientContext = $event->effectiveClient();
$this->loadIntegration();
return $this;
}
/**
* Load the integration definition and its effective instance configuration.
*

View File

@@ -3,8 +3,9 @@
namespace App\Shared\Integration\Services;
use App\Domains\Core\Client\Models\Client;
use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Core\Tenant\Models\AdminWebsiteType;
use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Ticketing\Event\Models\Event;
use Exception;
use Illuminate\Contracts\Mail\Factory as MailFactory;
use Illuminate\Contracts\Mail\Mailer;
@@ -39,14 +40,7 @@ class MailService extends BaseIntegrationService
public function forTenant(string $tenantCode): self
{
parent::forTenant($tenantCode);
if ($this->integrationInstance) {
$this->mailer = $this->resolveMailer();
$this->usesInstanceMailer = true;
} else {
$this->mailer = $this->mailFactory->mailer();
$this->usesInstanceMailer = false;
}
$this->configureMailer();
return $this;
}
@@ -55,16 +49,30 @@ class MailService extends BaseIntegrationService
{
parent::forClient($client);
$this->tenant = $this->clientContext?->tenants()->first();
$this->configureMailer();
return $this;
}
public function forEvent(Event $event): self
{
parent::forEvent($event);
$this->configureMailer();
return $this;
}
private function configureMailer(): void
{
if ($this->integrationInstance) {
$this->mailer = $this->resolveMailer();
$this->usesInstanceMailer = true;
} else {
$this->mailer = $this->mailFactory->mailer();
$this->usesInstanceMailer = false;
return;
}
return $this;
$this->mailer = $this->mailFactory->mailer();
$this->usesInstanceMailer = false;
}
public function getHeaders(): array
@@ -83,7 +91,7 @@ class MailService extends BaseIntegrationService
array $attachments = [],
): void {
if (! $this->mailer || ! $this->tenant) {
throw new Exception('MailService no está configurado. Llamá a forTenant() o forClient() primero.');
throw new Exception('MailService no está configurado. Llamá a forTenant(), forClient() o forEvent() primero.');
}
$brand ??= $this->tenant;
@@ -160,7 +168,7 @@ class MailService extends BaseIntegrationService
public function onSetup(): void
{
if (! $this->mailer || ! $this->clientContext) {
throw new Exception('MailService no está configurado. Llamá a forTenant() o forClient() primero.');
throw new Exception('MailService no está configurado. Llamá a forTenant(), forClient() o forEvent() primero.');
}
$recipient = $this->getIntegrationSetting('MAIL_FROM_ADDRESS');

View File

@@ -46,7 +46,7 @@ class TelepagosIntegrationService extends BaseIntegrationService
public function getToken(): string
{
if (! $this->integrationInstance) {
throw new Exception('Client integration is not loaded. Call forTenant() or forClient() first.');
throw new Exception('Client integration is not loaded. Call forTenant(), forClient(), or forEvent() first.');
}
$cacheKey = $this->integrationInstance->tokenCacheKey();

View File

@@ -2,12 +2,12 @@
namespace App\Shared\Integration\Services;
use App\Domains\Core\Client\Models\Client;
use App\Domains\Commerce\Purchase\Models\Purchase;
use App\Domains\Commerce\Purchase\Models\TelepagosPayment;
use App\Domains\Commerce\Purchase\Models\TelepagosQr;
use App\Domains\Commerce\Purchase\Services\CheckoutService;
use App\Domains\Commerce\Purchase\Services\DniDistanceService;
use App\Domains\Core\Client\Models\Client;
use Exception;
use Illuminate\Database\Eloquent\Builder;
use Illuminate\Database\Eloquent\Collection;
@@ -75,9 +75,30 @@ class TelepagosWebhookService
$dni = substr($cuit, 2, -1);
$tenantCodes = $client->tenants()->pluck('codigo');
$eligiblePurchases = Purchase::query()
->whereIn('tenant_codigo', $tenantCodes)
->where(function (Builder $purchases) use ($client): void {
$purchases
->whereHas('event', function (Builder $events) use ($client): void {
$events
->where('client_id', $client->id)
->orWhere(function (Builder $fallback) use ($client): void {
$fallback
->whereNull('client_id')
->whereHas(
'tenant',
fn (Builder $tenants): Builder => $tenants->where('client_id', $client->id),
);
});
})
->orWhere(function (Builder $legacy) use ($client): void {
$legacy
->whereNull('event_id')
->whereHas(
'tenant',
fn (Builder $tenants): Builder => $tenants->where('client_id', $client->id),
);
});
})
->whereIn('status', [
Purchase::STATUS_CREATED,
Purchase::STATUS_PENDING_PAYMENT,
@@ -170,7 +191,7 @@ class TelepagosWebhookService
return;
}
if (! $client->tenants()->where('codigo', $compra->tenant_codigo)->exists()) {
if (! $this->purchaseBelongsToClient($compra, $client)) {
Log::channel('telepagos')->warning('Telepagos webhook: Purchase does not belong to client.', [
'client_code' => $client->code,
'cashin_id' => $cashinId,
@@ -244,6 +265,16 @@ class TelepagosWebhookService
return number_format((float) $amount, 2, '.', '');
}
private function purchaseBelongsToClient(Purchase $purchase, Client $client): bool
{
$purchase->loadMissing(['event.client', 'event.tenant.client', 'tenant.client']);
$effectiveClient = $purchase->event?->effectiveClient()
?? $purchase->tenant?->client;
return $effectiveClient?->is($client) ?? false;
}
/**
* @param Builder<Purchase> $eligiblePurchases
* @return Collection<int, Purchase>

View File

@@ -2,16 +2,16 @@
namespace App\Shared\Notification\Services;
use App\Domains\Commerce\Purchase\Models\Purchase;
use App\Domains\Core\Auth\Models\ResetPasswordAttempt;
use App\Domains\Core\Auth\Models\User;
use App\Shared\Integration\Services\MailService;
use App\Shared\Notification\Events\PasswordResetRequested;
use App\Domains\Commerce\Purchase\Models\Purchase;
use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Ticketing\Ticket\Models\Ticket;
use App\Domains\Ticketing\Ticket\Services\TicketPdfService;
use App\Domains\Ticketing\Ticket\Services\TicketPresentationResolver;
use App\Domains\Ticketing\Ticket\Services\TicketValidityResolver;
use App\Shared\Integration\Services\MailService;
use App\Shared\Notification\Events\PasswordResetRequested;
use Closure;
use Illuminate\Support\Collection;
use Illuminate\Support\Facades\Log;
@@ -158,7 +158,7 @@ class NotificationMailService
$context = ['purchase_id' => $purchaseId];
$purchase = Purchase::query()
->with(['tenant', 'user', 'items'])
->with(['event', 'tenant', 'user', 'items'])
->find($purchaseId);
if ($purchase === null) {
@@ -197,8 +197,7 @@ class NotificationMailService
'mime' => 'application/pdf',
]];
$this->mailService
->forTenant($purchase->tenant_codigo)
$this->mailForPurchase($purchase)
->send(
$recipient,
"Compra confirmada - Compra #{$purchase->getKey()}",
@@ -286,7 +285,6 @@ class NotificationMailService
$context,
$recipient,
function () use (
$tenantCode,
$purchase,
$recipient,
$previousDate,
@@ -295,8 +293,7 @@ class NotificationMailService
): array {
$brand = $purchase->tenant;
$this->mailService
->forTenant($tenantCode)
$this->mailForPurchase($purchase)
->send(
$recipient,
"Tu evento fue reprogramado - N° de Orden #{$purchase->getKey()}",
@@ -387,7 +384,6 @@ class NotificationMailService
$context,
$recipient,
function () use (
$tenantCode,
$purchase,
$recipient,
$date,
@@ -396,8 +392,7 @@ class NotificationMailService
): array {
$brand = $purchase->tenant;
$this->mailService
->forTenant($tenantCode)
$this->mailForPurchase($purchase)
->send(
$recipient,
"Una fecha de tu evento fue suspendida - N° de Orden #{$purchase->getKey()}",
@@ -421,10 +416,17 @@ class NotificationMailService
{
return Purchase::query()
->where('tenant_codigo', $tenantCode)
->with(['tenant', 'user'])
->with(['event', 'tenant', 'user'])
->find($purchaseId);
}
private function mailForPurchase(Purchase $purchase): MailService
{
return $purchase->event
? $this->mailService->forEvent($purchase->event)
: $this->mailService->forTenant($purchase->tenant_codigo);
}
private function recipientFor(Purchase $purchase): string
{
return (string) ($purchase->email ?: $purchase->user?->email);

View File

@@ -0,0 +1,43 @@
<?php
use Illuminate\Database\Migrations\Migration;
use Illuminate\Support\Facades\DB;
return new class extends Migration
{
private const MENU_CODE = 'adminapp.tickets';
private const TENANT_CODE = 'desfile_pura_tendencia';
public function up(): void
{
if (
! DB::table('menues')->where('code', self::MENU_CODE)->exists()
|| ! DB::table('tenants')->where('codigo', self::TENANT_CODE)->exists()
) {
return;
}
$now = now();
DB::table('tenants_menues')->updateOrInsert(
[
'tenant_code' => self::TENANT_CODE,
'menu_code' => self::MENU_CODE,
],
[
'static_content' => null,
'created_at' => $now,
'updated_at' => $now,
],
);
}
public function down(): void
{
DB::table('tenants_menues')
->where('tenant_code', self::TENANT_CODE)
->where('menu_code', self::MENU_CODE)
->delete();
}
};

View File

@@ -0,0 +1,26 @@
<?php
use Illuminate\Database\Migrations\Migration;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\Schema;
return new class extends Migration
{
public function up(): void
{
Schema::table('events', function (Blueprint $table): void {
$table->foreignId('client_id')
->nullable()
->after('id')
->constrained('clients')
->restrictOnDelete();
});
}
public function down(): void
{
Schema::table('events', function (Blueprint $table): void {
$table->dropConstrainedForeignId('client_id');
});
}
};

View File

@@ -0,0 +1,44 @@
<?php
use Illuminate\Database\Migrations\Migration;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Schema;
return new class extends Migration
{
public function up(): void
{
Schema::table('compras', function (Blueprint $table): void {
$table->foreignId('event_id')
->nullable()
->after('tenant_codigo')
->constrained('events')
->nullOnDelete();
});
DB::table('compras')
->orderBy('id')
->each(function (object $purchase): void {
$eventIds = DB::table('compra_items')
->join('catalog_items', 'catalog_items.id', '=', 'compra_items.source_catalog_item_id')
->where('compra_items.compra_id', $purchase->id)
->whereNotNull('catalog_items.event_id')
->distinct()
->pluck('catalog_items.event_id');
if ($eventIds->count() === 1) {
DB::table('compras')
->where('id', $purchase->id)
->update(['event_id' => $eventIds->first()]);
}
});
}
public function down(): void
{
Schema::table('compras', function (Blueprint $table): void {
$table->dropConstrainedForeignId('event_id');
});
}
};

View File

@@ -0,0 +1,42 @@
<?php
use Illuminate\Database\Migrations\Migration;
use Illuminate\Support\Facades\DB;
return new class extends Migration
{
private const EVENT_TITLE = '26.º Fiesta de la Tradición y 4.º Encuentro de Agrupaciones Gauchas';
public function up(): void
{
$clientId = DB::table('clients')
->where('code', 'pyme_rural')
->value('id');
if ($clientId === null) {
return;
}
DB::table('events')
->where('tenant_code', 'onticket')
->where('title', self::EVENT_TITLE)
->update(['client_id' => $clientId]);
}
public function down(): void
{
$clientId = DB::table('clients')
->where('code', 'pyme_rural')
->value('id');
if ($clientId === null) {
return;
}
DB::table('events')
->where('tenant_code', 'onticket')
->where('title', self::EVENT_TITLE)
->where('client_id', $clientId)
->update(['client_id' => null]);
}
};

View File

@@ -0,0 +1,25 @@
<?php
use Illuminate\Database\Migrations\Migration;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\Schema;
return new class extends Migration
{
public function up(): void
{
Schema::table('users', function (Blueprint $table): void {
// Existing administrators keep their tenant-wide access.
$table->string('admin_scope', 20)->default('tenant');
$table->foreignId('event_id')->nullable()->constrained('events')->nullOnDelete();
});
}
public function down(): void
{
Schema::table('users', function (Blueprint $table): void {
$table->dropConstrainedForeignId('event_id');
$table->dropColumn('admin_scope');
});
}
};

View File

@@ -0,0 +1,44 @@
<?php
use Illuminate\Database\Migrations\Migration;
use Illuminate\Support\Facades\DB;
return new class extends Migration
{
public function up(): void
{
DB::transaction(function (): void {
DB::table('tenants')
->join('events', 'events.id', '=', 'tenants.active_event_id')
->whereColumn('events.tenant_code', 'tenants.codigo')
->select('tenants.codigo', 'tenants.active_event_id')
->get()
->each(function (object $tenant): void {
DB::table('users')
->whereIn('rol_codigo', ['adminapp', 'scanner'])
->where('tenant_codigo', $tenant->codigo)
->where('admin_scope', 'tenant')
->whereNull('event_id')
->whereNull('deleted_at')
->update([
'admin_scope' => 'event',
'event_id' => $tenant->active_event_id,
'updated_at' => now(),
]);
});
// Missing or mismatched active events must not leave legacy staff with tenant-wide access.
DB::table('users')
->whereIn('rol_codigo', ['adminapp', 'scanner'])
->where('admin_scope', 'tenant')
->whereNull('event_id')
->whereNull('deleted_at')
->update(['admin_scope' => 'event', 'updated_at' => now()]);
});
}
public function down(): void
{
// Do not broaden permissions or overwrite subsequent assignments on rollback.
}
};

View File

@@ -0,0 +1,38 @@
<?php
use Illuminate\Database\Migrations\Migration;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Schema;
return new class extends Migration
{
public function up(): void
{
Schema::table('events', function (Blueprint $table): void {
$table->boolean('allow_ticket_refund')->default(false);
$table->boolean('allow_ticket_total_refund')->default(false);
$table->boolean('allow_ticket_partial_refund')->default(false);
$table->decimal('ticket_partial_refund_percentage', 5, 2)->default(0);
});
DB::table('tenants')->select([
'codigo', 'allow_ticket_refund', 'allow_ticket_total_refund',
'allow_ticket_partial_refund', 'ticket_partial_refund_percentage',
])->get()->each(function (object $tenant): void {
DB::table('events')->where('tenant_code', $tenant->codigo)->update([
'allow_ticket_refund' => $tenant->allow_ticket_refund,
'allow_ticket_total_refund' => $tenant->allow_ticket_total_refund,
'allow_ticket_partial_refund' => $tenant->allow_ticket_partial_refund,
'ticket_partial_refund_percentage' => $tenant->ticket_partial_refund_percentage ?? 0,
]);
});
}
public function down(): void
{
Schema::table('events', fn (Blueprint $table) => $table->dropColumn([
'allow_ticket_refund', 'allow_ticket_total_refund',
'allow_ticket_partial_refund', 'ticket_partial_refund_percentage',
]));
}
};

View File

@@ -0,0 +1,22 @@
<?php
use Illuminate\Database\Migrations\Migration;
use Illuminate\Support\Facades\DB;
return new class extends Migration
{
public function up(): void
{
DB::transaction(function (): void {
$codes = ['adminapp.combos', 'adminapp.categories'];
DB::table('roles_menues')->whereIn('menu_codigo', $codes)->delete();
DB::table('tenants_menues')->whereIn('menu_code', $codes)->delete();
DB::table('menues')->whereIn('code', $codes)->delete();
});
}
public function down(): void
{
// Deprecated menus must not be restored by rollback.
}
};

View File

@@ -0,0 +1,28 @@
<?php
use Illuminate\Database\Migrations\Migration;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Schema;
return new class extends Migration
{
public function up(): void
{
Schema::table('scan_attempts', function (Blueprint $table): void {
$table->foreignId('event_id')->nullable()->constrained('events')->nullOnDelete();
$table->index(['scanner_user_id', 'event_id']);
});
DB::table('scan_attempts')->update([
'event_id' => DB::raw('(SELECT tickets.event_id FROM tickets WHERE tickets.id = scan_attempts.ticket_id)'),
]);
}
public function down(): void
{
Schema::table('scan_attempts', function (Blueprint $table): void {
$table->dropIndex(['scanner_user_id', 'event_id']);
$table->dropConstrainedForeignId('event_id');
});
}
};

View File

@@ -6,6 +6,7 @@ use App\Domains\Commerce\Catalog\Enums\InventoryPolicy;
use App\Domains\Commerce\Catalog\Models\Attribute;
use App\Domains\Commerce\Catalog\Models\CatalogItem;
use App\Domains\Commerce\Catalog\Services\CatalogService;
use App\Domains\Core\Client\Models\Client;
use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Ticketing\Event\Models\Event;
use App\Shared\Attachable\Services\AttachmentService;
@@ -35,6 +36,12 @@ class FiestaTradicionArrufoSeeder extends Seeder
throw new RuntimeException("Tenant 'onticket' no encontrado.");
}
$client = Client::query()->where('code', 'pyme_rural')->first();
if ($client === null) {
throw new RuntimeException("Client 'pyme_rural' no encontrado.");
}
Attribute::query()->firstOrCreate(
['tenant_codigo' => $tenant->codigo, 'codigo' => 'event_date'],
['nombre' => 'Fecha', 'type' => FieldType::EventDate, 'is_required' => true],
@@ -45,6 +52,7 @@ class FiestaTradicionArrufoSeeder extends Seeder
['published_at' => now()],
);
$event->update([
'client_id' => $client->id,
'subtitle' => 'Una noche para celebrar nuestras raíces y mantener viva la tradición gaucha.',
'description' => 'La 26.º Fiesta de la Tradición y 4.º Encuentro de Agrupaciones Gauchas reunirá a agrupaciones, artesanos, pilcheros y público en general para compartir una jornada dedicada a nuestras costumbres y cultura.'
."\n\n".'Un encuentro para disfrutar de la tradición, la identidad gaucha y el espíritu de camaradería, en el Predio de Doma del Club Unión Deportiva Arrufó.'

View File

@@ -70,18 +70,6 @@ class MenuSeeder extends Seeder
'parent_menu_code' => 'main.adminapp',
'route' => '/admin/catalog',
],
[
'code' => 'adminapp.combos',
'label' => 'Combos',
'parent_menu_code' => 'main.adminapp',
'route' => '/admin/combos',
],
[
'code' => 'adminapp.categories',
'label' => 'Categorías',
'parent_menu_code' => 'main.adminapp',
'route' => '/admin/categories',
],
[
'code' => 'adminapp.ventas',
'label' => 'Ventas',
@@ -242,6 +230,8 @@ class MenuSeeder extends Seeder
->whereIn('code', [
'admin.event',
'admin.catalog',
'adminapp.combos',
'adminapp.categories',
'admin.combos',
'admin.categories',
'admin.ventas',
@@ -298,8 +288,10 @@ class MenuSeeder extends Seeder
'fiesta_futbol_infantil',
'mutual_smep',
];
$fiestaCategoryMenuCodes = [
$ticketAdminMenuCodes = [
'adminapp.tickets',
];
$fiestaCategoryMenuCodes = [
'adminapp.fiesta-futbol-infantil.entradas',
'adminapp.fiesta-futbol-infantil.alojamientos',
'adminapp.fiesta-futbol-infantil.merchandising',
@@ -416,6 +408,10 @@ class MenuSeeder extends Seeder
$menuCodes = array_diff($menuCodes, $helpMenuCodes);
}
if (! in_array($tenant->codigo, ['fiesta_futbol_infantil', 'desfile_pura_tendencia'], true)) {
$menuCodes = array_diff($menuCodes, $ticketAdminMenuCodes);
}
if ($tenant->codigo !== 'fiesta_futbol_infantil') {
$menuCodes = array_diff($menuCodes, $fiestaCategoryMenuCodes);
} else {

View File

@@ -0,0 +1,236 @@
<?php
namespace Tests\Feature\Auth;
use App\Domains\Core\Auth\Models\User;
use Illuminate\Database\Migrations\Migration;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Hash;
use Illuminate\Support\Facades\Schema;
use Illuminate\Testing\TestResponse;
use Tests\TestCase;
class AdminAppEventScopeTest extends TestCase
{
private User $user;
protected function setUp(): void
{
parent::setUp();
// Focused pre-migration schema: do not replay unrelated provisioning migrations.
// Tests\TestCase and tests/bootstrap.php enforce SQLite :memory:.
Schema::create('tenants', function (Blueprint $table): void {
$table->id();
$table->string('codigo')->unique();
$table->string('nombre');
$table->string('dominio');
$table->string('search_product_layout')->default('column_with_image');
$table->string('search_group_layout')->default('paginated');
});
Schema::create('events', function (Blueprint $table): void {
$table->id();
$table->string('tenant_code');
$table->string('title');
$table->timestamps();
});
Schema::create('users', function (Blueprint $table): void {
$table->id();
$table->string('nombre_apellido');
$table->string('email');
$table->string('active_email')->virtualAs('CASE WHEN deleted_at IS NULL THEN lower(email) ELSE NULL END');
$table->string('password');
$table->string('rol_codigo')->default('user');
$table->string('tenant_codigo')->nullable();
$table->softDeletes();
$table->timestamps();
$table->unique(['active_email', 'rol_codigo']);
});
Schema::create('menues', function (Blueprint $table): void {
$table->id();
$table->string('code')->unique();
$table->string('label');
$table->string('route');
$table->string('parent_menu_code')->nullable();
$table->string('content_type')->default('dynamic');
});
Schema::create('roles_menues', function (Blueprint $table): void {
$table->string('rol_codigo');
$table->string('menu_codigo');
});
Schema::create('tenants_menues', function (Blueprint $table): void {
$table->string('tenant_code');
$table->string('menu_code');
$table->json('static_content')->nullable();
$table->timestamps();
});
foreach ([
'2026_06_18_130006_create_personal_access_tokens_table.php',
'2026_07_28_000000_create_roles_and_permissions_tables.php',
'2026_07_29_000000_add_login_security_fields_to_users_table.php',
'2026_07_29_000100_create_login_attempts_table.php',
] as $file) {
(require database_path('migrations/'.$file))->up();
}
DB::table('roles')->insert(['codigo' => 'adminapp', 'nombre' => 'AdminApp']);
DB::table('tenants')->insert([
['codigo' => 'onticket', 'nombre' => 'OnTicket', 'dominio' => 'onticket.test'],
['codigo' => 'other', 'nombre' => 'Other', 'dominio' => 'other.test'],
]);
DB::table('events')->insert([
['id' => 1, 'tenant_code' => 'onticket', 'title' => 'Evento A'],
['id' => 2, 'tenant_code' => 'onticket', 'title' => 'Evento B'],
['id' => 3, 'tenant_code' => 'other', 'title' => 'Evento ajeno'],
]);
// An existing administrator must remain general after applying the new migration.
DB::table('users')->insert([
'id' => 1, 'nombre_apellido' => 'Admin', 'email' => 'admin@example.test',
'password' => Hash::make('secret123'), 'rol_codigo' => 'adminapp', 'tenant_codigo' => 'onticket',
]);
$this->scopeMigration()->up();
$this->user = User::query()->findOrFail(1);
DB::table('menues')->insert([
['code' => 'main.adminapp', 'label' => 'Administración', 'route' => '/', 'parent_menu_code' => null],
['code' => 'adminapp.ventas', 'label' => 'Ventas', 'route' => '/admin/ventas', 'parent_menu_code' => 'main.adminapp'],
]);
foreach (['main.adminapp', 'adminapp.ventas'] as $code) {
DB::table('roles_menues')->insert(['rol_codigo' => 'adminapp', 'menu_codigo' => $code]);
DB::table('tenants_menues')->insert(['tenant_code' => 'onticket', 'menu_code' => $code]);
}
}
private function scopeMigration(): Migration
{
return require database_path('migrations/2026_09_30_000000_add_admin_scope_to_users.php');
}
private function login(array $extra = []): TestResponse
{
return $this->postJson('/api/v1/adminapp/login', [
'email' => ' ADMIN@EXAMPLE.TEST ', 'password' => 'secret123', ...$extra,
]);
}
public function test_existing_admin_keeps_general_access_after_migration(): void
{
$this->assertTrue($this->user->isTenantAdministrator());
$token = $this->login()->assertOk()->assertJsonPath('user.admin_scope', 'tenant')
->assertJsonPath('user.event_id', null)->json('token');
$this->withToken($token)->getJson('/api/v1/adminapp/me')->assertOk()
->assertJsonPath('data.event', null)->assertJsonCount(1, 'data.tenant.menues.0.submenues');
}
public function test_event_admin_logs_in_and_restores_only_its_assigned_context(): void
{
$this->user->update(['admin_scope' => 'event', 'event_id' => 1]);
$this->assertSame(1, $this->user->event->id);
// Scope cannot be chosen by the caller during login.
$token = $this->login(['admin_scope' => 'tenant', 'event_id' => 2])->assertOk()
->assertJsonPath('user.admin_scope', 'event')->assertJsonPath('user.event_id', 1)->json('token');
$this->withToken($token)->getJson('/api/v1/adminapp/me')->assertOk()
->assertJsonPath('data.event.id', 1)->assertJsonPath('data.event.title', 'Evento A')
->assertJsonPath('data.tenant.codigo', 'onticket')
->assertJsonCount(1, 'data.tenant.menues.0.submenues');
$this->assertSame(['adminapp'], $this->user->tokens()->sole()->abilities);
}
public function test_event_admins_of_the_same_tenant_receive_the_same_assigned_menus(): void
{
DB::table('menues')->insert([
'code' => 'onticket.adminapp.event',
'label' => 'Eventos',
'route' => '/admin/event',
'parent_menu_code' => 'main.adminapp',
]);
DB::table('roles_menues')->insert([
'rol_codigo' => 'adminapp',
'menu_codigo' => 'onticket.adminapp.event',
]);
DB::table('tenants_menues')->insert([
'tenant_code' => 'onticket',
'menu_code' => 'onticket.adminapp.event',
]);
$this->user->update(['admin_scope' => 'event', 'event_id' => 1]);
$token = $this->login()->assertOk()->json('token');
$firstMenus = $this->withToken($token)->getJson('/api/v1/adminapp/me')
->assertOk()->json('data.tenant.menues');
$this->user->update(['event_id' => 2]);
$secondMenus = $this->withToken($token)->getJson('/api/v1/adminapp/me')
->assertOk()->json('data.tenant.menues');
$this->assertSame($firstMenus, $secondMenus);
$this->assertSame(
['adminapp.ventas', 'onticket.adminapp.event'],
collect($firstMenus[0]['submenues'])->pluck('code')->sort()->values()->all(),
);
}
public function test_invalid_scopes_never_issue_tokens_or_increment_password_failure_counts(): void
{
foreach ([
['admin_scope' => 'event', 'event_id' => null],
['admin_scope' => 'event', 'event_id' => 3],
['admin_scope' => 'tenant', 'event_id' => 1],
['admin_scope' => 'unknown', 'event_id' => null],
['admin_scope' => 'event', 'event_id' => 1, 'tenant_codigo' => null],
] as $attributes) {
$this->user->update($attributes);
$this->login()->assertUnprocessable()->assertJsonValidationErrors('email');
}
$this->assertDatabaseCount('personal_access_tokens', 0);
$this->assertSame(0, $this->user->refresh()->failed_login_attempts);
}
public function test_event_admin_cannot_access_tenant_operations_but_can_logout(): void
{
$this->user->update(['admin_scope' => 'event', 'event_id' => 1]);
$token = $this->login()->assertOk()->json('token');
foreach (['tenant/tickets', 'tenant/administrators', 'tenant/website-extras', 'forms/tickets-filter'] as $path) {
$this->withToken($token)->getJson('/api/v1/adminapp/'.$path)->assertForbidden();
}
$this->withToken($token)->postJson('/api/v1/adminapp/tenant/administrators', [])->assertForbidden();
$this->withToken($token)->postJson('/api/logout')->assertOk();
$this->assertDatabaseCount('personal_access_tokens', 0);
}
public function test_deleting_the_event_invalidates_an_existing_token_without_promoting_the_user(): void
{
$this->user->update(['admin_scope' => 'event', 'event_id' => 1]);
$token = $this->login()->assertOk()->json('token');
DB::table('events')->where('id', 1)->delete();
$this->assertNull($this->user->refresh()->event_id);
$this->assertSame('event', $this->user->admin_scope);
$this->withToken($token)->getJson('/api/v1/adminapp/me')->assertForbidden();
$this->withToken($token)->getJson('/api/v1/adminapp/tenant/administrators')->assertForbidden();
}
public function test_event_reassignment_and_tenant_changes_apply_to_existing_tokens(): void
{
$this->user->update(['admin_scope' => 'event', 'event_id' => 1]);
$token = $this->login()->assertOk()->json('token');
$this->user->update(['event_id' => 2]);
$this->withToken($token)->getJson('/api/v1/adminapp/me')->assertOk()->assertJsonPath('data.event.id', 2);
DB::table('events')->where('id', 2)->update(['tenant_code' => 'other']);
$this->withToken($token)->getJson('/api/v1/adminapp/me')->assertForbidden();
}
public function test_wrong_password_still_counts_as_a_failed_attempt(): void
{
$this->user->update(['admin_scope' => 'event', 'event_id' => 1]);
$this->login(['password' => 'wrong'])->assertUnprocessable()->assertJsonValidationErrors('email');
$this->assertSame(1, $this->user->refresh()->failed_login_attempts);
$this->assertDatabaseCount('personal_access_tokens', 0);
}
public function test_scope_migration_can_be_rolled_back_without_removing_users(): void
{
$this->scopeMigration()->down();
$this->assertFalse(Schema::hasColumn('users', 'admin_scope'));
$this->assertFalse(Schema::hasColumn('users', 'event_id'));
$this->assertDatabaseHas('users', ['id' => 1, 'email' => 'admin@example.test']);
}
}

View File

@@ -0,0 +1,485 @@
<?php
namespace Tests\Feature\Auth;
use App\Domains\Commerce\Purchase\Models\Purchase;
use App\Domains\Commerce\Sale\Services\AdminAppSaleService;
use App\Domains\Core\Auth\Models\User;
use App\Domains\Core\Auth\Services\ResetPasswordAttemptService;
use App\Domains\Ticketing\Ticket\Models\Ticket;
use App\Domains\Ticketing\Ticket\Services\AdminAppTicketService;
use Illuminate\Database\Migrations\Migration;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Hash;
use Illuminate\Support\Facades\Schema;
use Illuminate\Testing\TestResponse;
use Laravel\Sanctum\Sanctum;
use Tests\TestCase;
class EventScopedOperationsTest extends TestCase
{
private User $user;
protected function setUp(): void
{
parent::setUp();
// Focused pre-migration schema: do not replay unrelated provisioning migrations.
// Tests\TestCase and tests/bootstrap.php enforce SQLite :memory:.
Schema::create('tenants', function (Blueprint $table): void {
$table->id();
$table->string('codigo')->unique();
$table->string('nombre');
$table->string('dominio');
$table->string('search_product_layout')->default('column_with_image');
$table->string('search_group_layout')->default('paginated');
});
Schema::create('events', function (Blueprint $table): void {
$table->id();
$table->string('tenant_code');
$table->string('title');
$table->timestamps();
});
Schema::create('users', function (Blueprint $table): void {
$table->id();
$table->string('nombre_apellido');
$table->string('email');
$table->string('active_email')->virtualAs('CASE WHEN deleted_at IS NULL THEN lower(email) ELSE NULL END');
$table->string('password');
$table->string('rol_codigo')->default('user');
$table->string('tenant_codigo')->nullable();
$table->softDeletes();
$table->timestamps();
$table->unique(['active_email', 'rol_codigo']);
});
Schema::create('menues', function (Blueprint $table): void {
$table->id();
$table->string('code')->unique();
$table->string('label');
$table->string('route');
$table->string('parent_menu_code')->nullable();
$table->string('content_type')->default('dynamic');
});
Schema::create('roles_menues', function (Blueprint $table): void {
$table->string('rol_codigo');
$table->string('menu_codigo');
});
Schema::create('tenants_menues', function (Blueprint $table): void {
$table->string('tenant_code');
$table->string('menu_code');
$table->json('static_content')->nullable();
$table->timestamps();
});
foreach ([
'2026_06_18_130006_create_personal_access_tokens_table.php',
'2026_07_28_000000_create_roles_and_permissions_tables.php',
'2026_07_29_000000_add_login_security_fields_to_users_table.php',
'2026_07_29_000100_create_login_attempts_table.php',
] as $file) {
(require database_path('migrations/'.$file))->up();
}
DB::table('roles')->insert(['codigo' => 'adminapp', 'nombre' => 'AdminApp']);
DB::table('tenants')->insert([
['codigo' => 'onticket', 'nombre' => 'OnTicket', 'dominio' => 'onticket.test'],
['codigo' => 'other', 'nombre' => 'Other', 'dominio' => 'other.test'],
]);
DB::table('events')->insert([
['id' => 1, 'tenant_code' => 'onticket', 'title' => 'Evento A'],
['id' => 2, 'tenant_code' => 'onticket', 'title' => 'Evento B'],
['id' => 3, 'tenant_code' => 'other', 'title' => 'Evento ajeno'],
]);
// An existing administrator must remain general after applying the new migration.
DB::table('users')->insert([
'id' => 1, 'nombre_apellido' => 'Admin', 'email' => 'admin@example.test',
'password' => Hash::make('secret123'), 'rol_codigo' => 'adminapp', 'tenant_codigo' => 'onticket',
]);
$this->scopeMigration()->up();
$this->user = User::query()->findOrFail(1);
$this->createOperationsSchema();
DB::table('menues')->insert([
['code' => 'main.adminapp', 'label' => 'Administración', 'route' => '/', 'parent_menu_code' => null],
['code' => 'adminapp.ventas', 'label' => 'Ventas', 'route' => '/admin/ventas', 'parent_menu_code' => 'main.adminapp'],
]);
foreach (['main.adminapp', 'adminapp.ventas'] as $code) {
DB::table('roles_menues')->insert(['rol_codigo' => 'adminapp', 'menu_codigo' => $code]);
DB::table('tenants_menues')->insert(['tenant_code' => 'onticket', 'menu_code' => $code]);
}
}
private function scopeMigration(): Migration
{
return require database_path('migrations/2026_09_30_000000_add_admin_scope_to_users.php');
}
private function login(array $extra = []): TestResponse
{
return $this->postJson('/api/v1/adminapp/login', [
'email' => ' ADMIN@EXAMPLE.TEST ', 'password' => 'secret123', ...$extra,
]);
}
private function createOperationsSchema(): void
{
Schema::table('tenants', function (Blueprint $table): void {
$table->unsignedBigInteger('active_event_id')->nullable();
$table->boolean('scanner_category_validation_enabled')->default(false);
$table->boolean('allow_ticket_refund')->default(true);
$table->boolean('allow_ticket_total_refund')->default(true);
$table->boolean('allow_ticket_partial_refund')->default(true);
$table->decimal('ticket_partial_refund_percentage')->default(25);
});
Schema::table('users', fn (Blueprint $table) => $table->string('dni')->nullable());
Schema::table('events', function (Blueprint $table): void {
$table->string('location')->nullable();
$table->string('date_text')->nullable();
});
(require database_path('migrations/2026_09_30_000200_add_refund_configuration_to_events.php'))->up();
DB::table('tenants')->where('codigo', 'onticket')->update(['active_event_id' => 2]);
Schema::create('social_media', function (Blueprint $table): void {
$table->id();
$table->string('code')->unique();
$table->string('nombre');
});
Schema::create('event_social_media', function (Blueprint $table): void {
$table->unsignedBigInteger('event_id');
$table->string('social_media_code');
$table->string('url');
$table->integer('orden');
$table->timestamps();
});
Schema::create('event_dates', function (Blueprint $table): void {
$table->id();
$table->string('tenant_code');
$table->unsignedBigInteger('event_id');
$table->date('date');
$table->time('time_start');
$table->time('time_end');
$table->unsignedBigInteger('validity_time_id')->nullable();
$table->unsignedBigInteger('rescheduled_to_event_date_id')->nullable();
$table->timestamp('suspended_at')->nullable();
});
Schema::create('validity_times', function (Blueprint $table): void {
$table->id();
$table->string('type');
$table->time('start_time')->nullable();
$table->time('end_time')->nullable();
$table->timestamp('fixed_starts_at')->nullable();
$table->timestamp('fixed_expires_at')->nullable();
$table->timestamps();
});
Schema::create('categorias', function (Blueprint $table): void {
$table->id();
$table->string('tenant_code')->nullable();
$table->unsignedBigInteger('categoria_id')->nullable();
$table->string('nombre');
});
Schema::create('category_scanners', function (Blueprint $table): void {
$table->unsignedBigInteger('user_id');
$table->unsignedBigInteger('categoria_id');
$table->timestamps();
});
Schema::create('catalog_items', function (Blueprint $table): void {
$table->id();
$table->string('tenant_code');
$table->unsignedBigInteger('event_id');
$table->unsignedBigInteger('category_id')->nullable();
$table->string('nombre');
$table->string('slug');
$table->text('descripcion')->nullable();
$table->decimal('precio')->default(0);
$table->string('type')->default('standard');
$table->string('inventory_policy')->default('tracked');
$table->string('inventory_subject')->default('product');
$table->integer('group_order')->default(0);
$table->boolean('has_tickets')->default(false);
$table->softDeletes();
});
Schema::create('compras', function (Blueprint $table): void {
$table->id();
$table->string('tenant_codigo');
$table->unsignedBigInteger('event_id');
$table->string('status');
$table->decimal('total');
$table->string('nombre_apellido');
$table->timestamps();
});
Schema::create('compra_items', function (Blueprint $table): void {
$table->id();
$table->unsignedBigInteger('compra_id');
$table->integer('cantidad');
$table->string('item_nombre')->nullable();
$table->decimal('precio_unitario')->default(10);
$table->decimal('total')->default(10);
});
Schema::create('tickets', function (Blueprint $table): void {
$table->id();
$table->string('tenant_code');
$table->unsignedBigInteger('event_id')->nullable();
$table->uuid('ticket');
foreach (['source_purchase_item_id', 'source_catalog_item_id', 'source_variant_id', 'scanner_user_id', 'user_id'] as $column) {
$table->unsignedBigInteger($column)->nullable();
}
foreach (['used_at', 'disabled_at', 'cancelled_at', 'refunded_at'] as $column) {
$table->timestamp($column)->nullable();
}
});
Schema::create('ticket_refunds', function (Blueprint $table): void {
$table->id();
$table->unsignedBigInteger('purchase_item_id');
$table->decimal('amount');
});
Schema::create('scan_attempts', function (Blueprint $table): void {
$table->id();
$table->string('tenant_code');
$table->unsignedBigInteger('scanner_user_id');
$table->unsignedBigInteger('ticket_id')->nullable();
$table->text('data')->nullable();
$table->string('result');
$table->timestamp('created_at')->nullable();
$table->timestamp('resolved_at')->nullable();
});
(require database_path('migrations/2026_09_30_000400_add_event_id_to_scan_attempts.php'))->up();
Schema::create('value_changes', function (Blueprint $table): void {
$table->id();
$table->string('tenant_code');
$table->string('trackable_type');
$table->unsignedBigInteger('trackable_id');
$table->string('attribute');
$table->string('old_value')->nullable();
$table->string('new_value')->nullable();
$table->string('actor_type')->default('user');
$table->unsignedBigInteger('user_id')->nullable();
$table->timestamp('changed_at')->nullable();
});
DB::table('roles')->insert(['codigo' => 'scanner', 'nombre' => 'Scanner']);
DB::table('permisos')->insert(['codigo' => 'tickets.escanear', 'nombre' => 'Escanear']);
DB::table('roles_permisos')->insert(['rol_codigo' => 'scanner', 'codigo_permiso' => 'tickets.escanear']);
foreach (['adminapp.catalog', 'adminapp.event', 'adminapp.staff', 'adminapp.inicio'] as $code) {
DB::table('menues')->insert(['code' => $code, 'label' => $code, 'route' => '/admin/test', 'parent_menu_code' => 'main.adminapp']);
DB::table('roles_menues')->insert(['rol_codigo' => 'adminapp', 'menu_codigo' => $code]);
DB::table('tenants_menues')->insert(['tenant_code' => 'onticket', 'menu_code' => $code]);
}
}
private function actingEventAdmin(): void
{
$this->user->update(['admin_scope' => 'event', 'event_id' => 1]);
Sanctum::actingAs($this->user);
}
public function test_event_and_refund_settings_use_user_event_even_when_tenant_active_event_changes(): void
{
$this->actingEventAdmin();
$this->getJson('/api/v1/adminapp/tenant/event')->assertOk()->assertJsonPath('data.id', 1)
->assertJsonPath('data.allow_ticket_refund', true);
$this->putJson('/api/v1/adminapp/tenant/event', [
'title' => 'Solo A', 'location' => 'Predio A', 'social_media' => [], 'allow_ticket_refund' => false,
'allow_ticket_total_refund' => true, 'allow_ticket_partial_refund' => true,
'ticket_partial_refund_percentage' => 30,
])->assertOk()->assertJsonPath('data.id', 1)->assertJsonPath('data.allow_ticket_refund', false);
$this->assertDatabaseHas('events', ['id' => 1, 'title' => 'Solo A', 'allow_ticket_refund' => false]);
$this->assertDatabaseHas('events', ['id' => 2, 'title' => 'Evento B', 'allow_ticket_refund' => true]);
$this->assertDatabaseHas('tenants', ['codigo' => 'onticket', 'allow_ticket_refund' => true]);
$this->getJson('/api/v1/adminapp/forms/event')->assertOk();
$this->getJson('/api/v1/adminapp/tenant/website-extras')->assertForbidden();
}
public function test_dates_are_created_on_user_event_and_other_event_dates_cannot_be_changed(): void
{
$this->actingEventAdmin();
$this->postJson('/api/v1/adminapp/tenant/event-dates', [
'date' => '2027-01-20', 'start_time' => '10:00', 'end_time' => '12:00',
])->assertSuccessful();
$this->assertDatabaseHas('event_dates', ['event_id' => 1, 'date' => '2027-01-20']);
DB::table('event_dates')->insert(['id' => 20, 'event_id' => 2, 'tenant_code' => 'onticket',
'date' => '2027-01-20', 'time_start' => '10:00', 'time_end' => '12:00']);
$this->postJson('/api/v1/adminapp/tenant/event-dates/20/suspend')->assertNotFound();
$this->postJson('/api/v1/adminapp/tenant/event-dates/20/reschedule', ['date' => '2027-01-21'])->assertNotFound();
$this->assertDatabaseHas('event_dates', ['id' => 20, 'suspended_at' => null]);
}
public function test_sales_totals_details_exports_and_history_are_scoped_to_user_event(): void
{
$this->actingEventAdmin();
foreach ([1, 2] as $id) {
DB::table('compras')->insert(['id' => $id, 'tenant_codigo' => 'onticket', 'event_id' => $id,
'status' => 'paid', 'total' => $id * 100, 'nombre_apellido' => 'Cliente', 'created_at' => now()]);
DB::table('compra_items')->insert(['id' => $id, 'compra_id' => $id, 'cantidad' => 1]);
DB::table('ticket_refunds')->insert(['purchase_item_id' => $id, 'amount' => $id * 10]);
DB::table('value_changes')->insert(['tenant_code' => 'onticket',
'trackable_type' => (new Purchase)->getMorphClass(),
'trackable_id' => $id, 'attribute' => 'status', 'new_value' => 'paid', 'changed_at' => now()]);
}
$this->getJson('/api/v1/adminapp/tenant/sales')->assertOk()->assertJsonCount(1, 'data')
->assertJsonPath('confirmed_sales_total', '100.00')->assertJsonPath('refunded_total', '10.00');
$this->getJson('/api/v1/adminapp/tenant/sales/1')->assertOk();
foreach (['', '/tickets'] as $suffix) {
$this->getJson('/api/v1/adminapp/tenant/sales/2'.$suffix)->assertNotFound();
}
foreach (['confirm', 'cancel'] as $action) {
$this->postJson('/api/v1/adminapp/tenant/sales/2/'.$action)->assertNotFound();
}
$this->getJson('/api/v1/adminapp/tenant/sales/modifications')->assertOk()->assertJsonCount(1, 'data');
$service = app(AdminAppSaleService::class);
$tenant = $this->user->tenant;
$this->assertSame([1], $service->salesForExport($tenant, [], 1)->pluck('id')->all());
$this->assertSame([1], $service->modificationsForExport($tenant, [], 1)->pluck('trackable_id')->all());
}
private function scanner(int $eventId, int $id = 10): User
{
return User::query()->create(['id' => $id, 'nombre_apellido' => 'Scanner',
'email' => "scanner{$id}@example.test", 'password' => 'password', 'dni' => '123',
'tenant_codigo' => 'onticket', 'rol_codigo' => 'scanner', 'admin_scope' => 'event', 'event_id' => $eventId]);
}
public function test_staff_is_created_on_admin_event_and_other_staff_cannot_be_managed(): void
{
$this->actingEventAdmin();
$scanner = $this->scanner(2);
$this->getJson('/api/v1/adminapp/tenant/staff')->assertOk()->assertJsonCount(0, 'data');
$payload = ['nombre_apellido' => 'Nuevo', 'email' => 'nuevo@example.test', 'dni' => '123'];
$this->putJson('/api/v1/adminapp/tenant/staff/'.$scanner->id, $payload)->assertNotFound();
$this->deleteJson('/api/v1/adminapp/tenant/staff/'.$scanner->id)->assertNotFound();
$this->getJson('/api/v1/adminapp/tenant/staff/'.$scanner->id.'/scan-attempts')->assertNotFound();
$this->mock(ResetPasswordAttemptService::class,
fn ($mock) => $mock->shouldReceive('createForScannerEmail')->once());
$this->postJson('/api/v1/adminapp/tenant/staff', [...$payload, 'event_id' => 2])
->assertSuccessful()->assertJsonPath('data.event_id', 1);
$this->assertDatabaseHas('users', ['email' => 'nuevo@example.test', 'event_id' => 1, 'admin_scope' => 'event']);
}
public function test_scanner_rejects_foreign_event_qr_without_consuming_or_disclosing_ticket(): void
{
$scanner = $this->scanner(1);
Sanctum::actingAs($scanner);
$uuid = '11111111-1111-4111-8111-111111111111';
DB::table('tickets')->insert(['id' => 20, 'tenant_code' => 'onticket', 'event_id' => 2, 'ticket' => $uuid]);
$this->getJson('/api/v1/scanner/tickets/'.$uuid)->assertNotFound();
$this->postJson('/api/v1/scanner/tickets/scan', ['data' => $uuid])->assertOk()
->assertJsonPath('data.scan_attempt.result', 'ticket_not_found')->assertJsonPath('data.ticket', null);
$this->assertDatabaseHas('tickets', ['id' => 20, 'used_at' => null, 'scanner_user_id' => null]);
$this->assertDatabaseHas('scan_attempts', ['scanner_user_id' => $scanner->id, 'event_id' => 1, 'ticket_id' => null]);
}
public function test_scanner_history_and_detail_follow_assignment_changes_and_invalid_event_is_denied(): void
{
$scanner = $this->scanner(1);
Sanctum::actingAs($scanner);
$response = $this->postJson('/api/v1/scanner/tickets/scan', ['data' => 'invalid'])->assertOk();
$id = $response->json('data.scan_attempt.id');
$this->getJson('/api/v1/scanner/attempts')->assertOk()->assertJsonCount(1, 'data');
$scanner->update(['event_id' => 2]);
$this->getJson('/api/v1/scanner/attempts')->assertOk()->assertJsonCount(0, 'data');
$this->getJson('/api/v1/scanner/attempts/'.$id)->assertNotFound();
$scanner->update(['event_id' => null]);
$this->getJson('/api/v1/scanner/attempts')->assertForbidden();
}
public function test_initial_assignment_migration_preserves_existing_scopes_and_ignores_missing_events(): void
{
$this->user->update(['admin_scope' => 'event', 'event_id' => 1]);
$scanner = $this->scanner(1);
$scanner->update(['event_id' => null, 'admin_scope' => 'tenant']);
$migration = require database_path('migrations/2026_09_30_000100_assign_active_event_to_staff_users.php');
$migration->up();
$migration->up();
$this->assertDatabaseHas('users', ['id' => 1, 'event_id' => 1]);
$this->assertDatabaseHas('users', ['id' => $scanner->id, 'event_id' => 2, 'admin_scope' => 'event']);
DB::table('tenants')->where('codigo', 'onticket')->update(['active_event_id' => 3]);
$scanner->refresh()->update(['event_id' => null, 'admin_scope' => 'tenant']);
$migration->up();
$this->assertDatabaseHas('users', ['id' => $scanner->id, 'event_id' => null, 'admin_scope' => 'event']);
}
public function test_deprecated_menus_are_removed_with_their_role_and_tenant_assignments(): void
{
foreach (['adminapp.categories', 'adminapp.combos'] as $code) {
DB::table('menues')->insert(['code' => $code, 'label' => $code, 'route' => '/admin/old']);
DB::table('roles_menues')->insert(['rol_codigo' => 'adminapp', 'menu_codigo' => $code]);
DB::table('tenants_menues')->insert(['tenant_code' => 'onticket', 'menu_code' => $code]);
}
(require database_path('migrations/2026_09_30_000300_remove_deprecated_admin_menus.php'))->up();
foreach (['adminapp.categories', 'adminapp.combos'] as $code) {
$this->assertDatabaseMissing('menues', ['code' => $code]);
$this->assertDatabaseMissing('roles_menues', ['menu_codigo' => $code]);
$this->assertDatabaseMissing('tenants_menues', ['menu_code' => $code]);
}
}
public function test_scanner_accepts_ticket_from_its_event_and_cannot_consume_it_twice(): void
{
$scanner = $this->scanner(1);
Sanctum::actingAs($scanner);
$uuid = '11111111-1111-4111-8111-111111111111';
DB::table('tickets')->insert(['id' => 20, 'tenant_code' => 'onticket', 'event_id' => 1, 'ticket' => $uuid]);
$this->postJson('/api/v1/scanner/tickets/scan', ['data' => $uuid])->assertOk()
->assertJsonPath('data.scan_attempt.result', 'accepted')->assertJsonPath('data.ticket.id', 20);
$this->assertNotNull(DB::table('tickets')->where('id', 20)->value('used_at'));
$this->postJson('/api/v1/scanner/tickets/scan', ['data' => $uuid])->assertOk()
->assertJsonPath('data.scan_attempt.result', 'already_scanned');
$this->getJson('/api/v1/scanner/tickets/'.$uuid)->assertOk();
}
public function test_refund_calculation_uses_ticket_event_configuration_instead_of_tenant_defaults(): void
{
Schema::create('desfile_entry_reservations', function (Blueprint $table): void {
$table->id();
$table->unsignedBigInteger('ticket_id');
$table->softDeletes();
});
DB::table('ticket_refunds')->delete();
DB::table('compra_items')->insert(['id' => 1, 'compra_id' => 1, 'cantidad' => 1,
'precio_unitario' => 100, 'total' => 100]);
DB::table('tickets')->insert(['id' => 20, 'tenant_code' => 'onticket', 'event_id' => 1,
'ticket' => '11111111-1111-4111-8111-111111111111', 'source_purchase_item_id' => 1]);
DB::table('events')->where('id', 1)->update(['ticket_partial_refund_percentage' => 75]);
$calculation = app(AdminAppTicketService::class)
->calculateRefund($this->user->tenant, 20);
$this->assertSame(['total' => '100.00', 'partial' => '75.00'], $calculation);
DB::table('events')->where('id', 1)->update(['allow_ticket_refund' => false]);
$this->assertFalse(Ticket::query()->findOrFail(20)->allow_refund());
}
public function test_staff_category_options_and_assignments_exclude_other_event_products(): void
{
$this->actingEventAdmin();
DB::table('tenants')->where('codigo', 'onticket')->update(['scanner_category_validation_enabled' => true]);
foreach ([1, 2] as $id) {
DB::table('categorias')->insert(['id' => $id, 'nombre' => "Categoria {$id}", 'tenant_code' => 'onticket']);
DB::table('catalog_items')->insert(['id' => $id, 'tenant_code' => 'onticket', 'event_id' => $id,
'nombre' => "Producto {$id}", 'slug' => "producto-{$id}", 'category_id' => $id]);
}
$this->getJson('/api/v1/adminapp/forms/staff')->assertOk()->assertJsonCount(1, 'data.categories')
->assertJsonPath('data.categories.0.id', 1);
$this->postJson('/api/v1/adminapp/tenant/staff', ['nombre_apellido' => 'Nuevo', 'dni' => '123',
'email' => 'nuevo@example.test', 'category_ids' => [2]])->assertUnprocessable()->assertJsonValidationErrors('category_ids');
$this->assertDatabaseMissing('users', ['email' => 'nuevo@example.test']);
}
public function test_initial_migration_assigns_existing_tenant_admin_and_blocks_staff_without_active_event(): void
{
$unassigned = $this->scanner(1);
$unassigned->update(['tenant_codigo' => 'other', 'admin_scope' => 'tenant', 'event_id' => null]);
(require database_path('migrations/2026_09_30_000100_assign_active_event_to_staff_users.php'))->up();
$this->assertDatabaseHas('users', ['id' => 1, 'admin_scope' => 'event', 'event_id' => 2]);
$this->assertDatabaseHas('users', ['id' => $unassigned->id, 'admin_scope' => 'event', 'event_id' => null]);
$this->user->refresh();
$this->assertFalse($this->user->isTenantAdministrator());
$this->login()->assertOk()->assertJsonPath('user.event_id', 2);
}
public function test_scanner_login_validates_event_before_issuing_a_token(): void
{
$scanner = $this->scanner(1);
$this->postJson('/api/v1/scanner/login', ['email' => $scanner->email, 'password' => 'password'])
->assertOk()->assertJsonPath('user.event_id', 1);
$scanner->update(['event_id' => null]);
$this->postJson('/api/v1/scanner/login', ['email' => $scanner->email, 'password' => 'password'])
->assertUnprocessable()->assertJsonValidationErrors('email');
$this->assertDatabaseCount('personal_access_tokens', 1);
$this->assertSame(0, $scanner->refresh()->failed_login_attempts);
}
}

View File

@@ -2,20 +2,22 @@
namespace Tests\Feature\Integration;
use App\Shared\Attachable\Enums\AttachmentType;
use App\Shared\Attachable\Models\Attachment;
use App\Domains\Core\Auth\Models\User;
use App\Domains\Commerce\Cart\Models\Cart;
use App\Domains\Commerce\Catalog\Enums\InventoryPolicy;
use App\Domains\Commerce\Catalog\Models\CatalogItem;
use App\Domains\Commerce\Catalog\Models\Category;
use App\Domains\Commerce\Catalog\Models\Inventory;
use App\Domains\Commerce\Catalog\Models\Variant;
use App\Shared\Integration\Models\Integration;
use App\Domains\Commerce\Purchase\Models\Purchase;
use App\Domains\Commerce\Purchase\Models\TelepagosPayment;
use App\Domains\Commerce\Purchase\Services\CheckoutService;
use App\Domains\Core\Auth\Models\User;
use App\Domains\Core\Client\Models\Client;
use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Ticketing\Event\Models\Event;
use App\Shared\Attachable\Enums\AttachmentType;
use App\Shared\Attachable\Models\Attachment;
use App\Shared\Integration\Models\Integration;
use Illuminate\Foundation\Testing\RefreshDatabase;
use Illuminate\Support\Facades\Cache;
use Illuminate\Support\Facades\Http;
@@ -227,6 +229,77 @@ class TelepagosWebhookTest extends TestCase
]);
}
public function test_transfer_webhook_matches_the_client_configured_on_the_event(): void
{
$tenant = $this->createTenant('multi-event', 'Multi Event', 'multi-event.com.ar');
$eventClient = Client::query()->create([
'code' => 'event-client',
'name' => 'Event Client',
]);
Integration::query()->create([
'integration_code' => 'telepagos_homo',
'name' => 'Telepagos',
'url' => 'https://api.telepagos.com.ar',
'integration_data_schema' => [
'username' => 'required|string',
'password' => 'required|string',
],
]);
$this->createClientIntegration([
'client_id' => $eventClient->id,
'integration_code' => 'telepagos_homo',
'integration_data' => ['username' => 'event-user', 'password' => 'event-password'],
]);
$event = Event::query()->create([
'client_id' => $eventClient->id,
'tenant_code' => $tenant->codigo,
'title' => 'Event with its own client',
]);
$tenant->update(['active_event_id' => $event->id]);
$user = User::factory()->create();
$variant = $this->createVariantForTenant($tenant->codigo, 10, '50.00');
$purchase = $this->createPendingTransferPurchase(
$tenant,
$user->id,
$variant->id,
1,
'12345678',
);
Http::fake([
'https://api.telepagos.com.ar/v2/auth/token' => Http::response([
'status' => 'ok',
'token' => 'event-client-token',
'expires_at' => now()->addHour()->toIso8601String(),
]),
'https://api.telepagos.com.ar/v2/payment/cashin/event-client-payment' => Http::response([
'status' => 'ok',
'data' => [
'amount' => 50,
'operation_id' => 1,
'transaction_id' => 'tx-event-client',
'buyer' => ['cuit' => '20123456789'],
],
]),
]);
$this->postJson('/api/webhooks/telepagos/event-client', [
'id' => 'event-client-payment',
])->assertOk()->assertJsonPath('status', 'success');
$this->assertSame($event->id, $purchase->event_id);
$this->assertDatabaseHas('compras', [
'id' => $purchase->id,
'event_id' => $event->id,
'status' => Purchase::STATUS_PAID,
]);
$this->assertDatabaseHas('telepagos_payments', [
'compra_id' => $purchase->id,
'transaction_id' => 'tx-event-client',
]);
}
public function test_transfer_webhook_buys_unlimited_inventory_without_reducing_real_stock(): void
{
$tenant = $this->createTenant('unlimited', 'Unlimited', 'unlimited.com.ar');

View File

@@ -0,0 +1,57 @@
<?php
namespace Tests\Feature\Migrations;
use App\Domains\Core\Client\Models\Client;
use App\Domains\Ticketing\Event\Models\Event;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Schema;
use Tests\TestCase;
class AddClientIdToEventsTest extends TestCase
{
public function test_event_client_overrides_the_tenant_client_when_configured(): void
{
Schema::create('clients', function (Blueprint $table): void {
$table->id();
$table->string('code');
$table->string('name');
});
Schema::create('tenants', function (Blueprint $table): void {
$table->id();
$table->foreignId('client_id');
$table->string('codigo');
});
Schema::create('events', function (Blueprint $table): void {
$table->id();
$table->string('tenant_code');
$table->string('title');
$table->timestamps();
});
DB::table('clients')->insert([
['id' => 10, 'code' => 'tenant-client', 'name' => 'Tenant Client'],
['id' => 11, 'code' => 'event-client', 'name' => 'Event Client'],
]);
DB::table('tenants')->insert(['id' => 20, 'client_id' => 10, 'codigo' => 'tenant']);
DB::table('events')->insert([
'id' => 30,
'tenant_code' => 'tenant',
'title' => 'Event',
'created_at' => now(),
'updated_at' => now(),
]);
$migration = require database_path('migrations/2026_09_28_000000_add_client_id_to_events.php');
$migration->up();
$event = Event::query()->findOrFail(30);
$this->assertSame(10, $event->effectiveClient()->id);
$event->update(['client_id' => 11]);
$this->assertSame(11, $event->fresh()->effectiveClient()->id);
$this->assertTrue(Client::query()->findOrFail(11)->events()->whereKey(30)->exists());
}
}

View File

@@ -0,0 +1,44 @@
<?php
namespace Tests\Feature\Migrations;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Schema;
use Tests\TestCase;
class AddEventIdToPurchasesTest extends TestCase
{
public function test_it_backfills_the_event_from_purchase_items(): void
{
Schema::create('events', fn (Blueprint $table) => $table->id());
Schema::create('compras', fn (Blueprint $table) => $table->id());
Schema::create('catalog_items', function (Blueprint $table): void {
$table->id();
$table->foreignId('event_id')->nullable();
});
Schema::create('compra_items', function (Blueprint $table): void {
$table->id();
$table->foreignId('compra_id');
$table->foreignId('source_catalog_item_id');
});
DB::table('events')->insert([['id' => 10], ['id' => 11]]);
DB::table('compras')->insert([['id' => 20], ['id' => 21]]);
DB::table('catalog_items')->insert([
['id' => 30, 'event_id' => 10],
['id' => 31, 'event_id' => 11],
]);
DB::table('compra_items')->insert([
['compra_id' => 20, 'source_catalog_item_id' => 30],
['compra_id' => 21, 'source_catalog_item_id' => 30],
['compra_id' => 21, 'source_catalog_item_id' => 31],
]);
$migration = require database_path('migrations/2026_09_28_000100_add_event_id_to_compras.php');
$migration->up();
$this->assertDatabaseHas('compras', ['id' => 20, 'event_id' => 10]);
$this->assertDatabaseHas('compras', ['id' => 21, 'event_id' => null]);
}
}

View File

@@ -0,0 +1,50 @@
<?php
namespace Tests\Feature\Migrations;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Schema;
use Tests\TestCase;
class AssignArrufoEventToPymeRuralClientTest extends TestCase
{
public function test_it_assigns_only_the_arrufo_event_to_pyme_rural(): void
{
Schema::create('clients', function (Blueprint $table): void {
$table->id();
$table->string('code');
});
Schema::create('events', function (Blueprint $table): void {
$table->id();
$table->foreignId('client_id')->nullable();
$table->string('tenant_code');
$table->string('title');
});
DB::table('clients')->insert([
['id' => 10, 'code' => 'pyme_rural'],
['id' => 11, 'code' => 'onticket'],
]);
DB::table('events')->insert([
[
'id' => 20,
'client_id' => null,
'tenant_code' => 'onticket',
'title' => '26.º Fiesta de la Tradición y 4.º Encuentro de Agrupaciones Gauchas',
],
[
'id' => 21,
'client_id' => 11,
'tenant_code' => 'onticket',
'title' => 'Otro evento',
],
]);
$migration = require database_path('migrations/2026_09_28_000200_assign_arrufo_event_to_pyme_rural_client.php');
$migration->up();
$this->assertDatabaseHas('events', ['id' => 20, 'client_id' => 10]);
$this->assertDatabaseHas('events', ['id' => 21, 'client_id' => 11]);
}
}

View File

@@ -0,0 +1,81 @@
<?php
namespace Tests\Feature\Migrations;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Schema;
use Tests\TestCase;
class AssociateAdminAppTicketsMenuWithDesfileTest extends TestCase
{
protected function setUp(): void
{
parent::setUp();
Schema::create('menues', function (Blueprint $table): void {
$table->string('code')->primary();
});
Schema::create('tenants', function (Blueprint $table): void {
$table->string('codigo')->primary();
});
Schema::create('tenants_menues', function (Blueprint $table): void {
$table->id();
$table->string('tenant_code');
$table->string('menu_code');
$table->json('static_content')->nullable();
$table->timestamps();
$table->unique(['tenant_code', 'menu_code']);
});
DB::table('menues')->insert(['code' => 'adminapp.tickets']);
DB::table('tenants')->insert([
['codigo' => 'desfile_pura_tendencia'],
['codigo' => 'fiesta_futbol_infantil'],
]);
DB::table('tenants_menues')->insert([
'tenant_code' => 'fiesta_futbol_infantil',
'menu_code' => 'adminapp.tickets',
]);
}
protected function tearDown(): void
{
Schema::dropIfExists('tenants_menues');
Schema::dropIfExists('tenants');
Schema::dropIfExists('menues');
parent::tearDown();
}
public function test_it_associates_the_tickets_menu_only_with_desfile_and_rolls_back_that_association(): void
{
$migration = require database_path(
'migrations/2026_09_25_000000_associate_adminapp_tickets_menu_with_desfile.php'
);
$migration->down();
$migration->up();
$migration->up();
$this->assertSame(1, DB::table('tenants_menues')
->where('tenant_code', 'desfile_pura_tendencia')
->where('menu_code', 'adminapp.tickets')
->count());
$this->assertDatabaseHas('tenants_menues', [
'tenant_code' => 'fiesta_futbol_infantil',
'menu_code' => 'adminapp.tickets',
]);
$migration->down();
$this->assertDatabaseMissing('tenants_menues', [
'tenant_code' => 'desfile_pura_tendencia',
'menu_code' => 'adminapp.tickets',
]);
$this->assertDatabaseHas('tenants_menues', [
'tenant_code' => 'fiesta_futbol_infantil',
'menu_code' => 'adminapp.tickets',
]);
}
}

View File

@@ -27,8 +27,6 @@ class MenuSeederTest extends TestCase
$expectedMenus = [
'adminapp.inicio' => ['Inicio', '/admin/inicio'],
'adminapp.catalog' => ['Catálogo', '/admin/catalog'],
'adminapp.categories' => ['Categorías', '/admin/categories'],
'adminapp.combos' => ['Combos', '/admin/combos'],
'adminapp.event' => ['Eventos', '/admin/event'],
'adminapp.staff' => ['Staff', '/admin/staff'],
'adminapp.ventas' => ['Ventas', '/admin/ventas'],
@@ -100,6 +98,8 @@ class MenuSeederTest extends TestCase
$this->assertFalse(
Menu::query()->whereIn('code', [
'adminapp.categories',
'adminapp.combos',
'admin.event',
'admin.catalog',
'admin.combos',

View File

@@ -2,22 +2,24 @@
namespace Tests\Feature\Ticket;
use App\Shared\Attachable\Enums\AttachmentType;
use App\Shared\Attachable\Models\Attachment;
use App\Domains\Core\Auth\Models\User;
use App\Domains\Core\Authorization\Enums\RoleCode;
use App\Domains\Commerce\Catalog\Models\Attribute;
use App\Domains\Commerce\Catalog\Models\CatalogItem;
use App\Domains\Commerce\Catalog\Models\Inventory;
use App\Domains\Commerce\Catalog\Models\Variant;
use App\Domains\Core\Menu\Models\Menu;
use App\Domains\Commerce\Purchase\Models\Purchase;
use App\Domains\Commerce\Purchase\Models\PurchaseItem;
use App\Shared\Enums\FieldType;
use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Core\Auth\Models\User;
use App\Domains\Core\Authorization\Enums\RoleCode;
use App\Domains\Core\Menu\Models\Menu;
use App\Domains\Core\Tenant\Models\AdminWebsiteType;
use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Ticketing\Desfile\Enums\EntryReservationPaymentType;
use App\Domains\Ticketing\Desfile\Models\EntryReservation;
use App\Domains\Ticketing\Ticket\Models\Ticket;
use App\Domains\Ticketing\Ticket\Models\TicketRefund;
use App\Shared\Attachable\Enums\AttachmentType;
use App\Shared\Attachable\Models\Attachment;
use App\Shared\Enums\FieldType;
use Barryvdh\DomPDF\ServiceProvider as DomPdfServiceProvider;
use Database\Seeders\AttributeSeeder;
use Database\Seeders\AuthorizationSeeder;
@@ -222,6 +224,56 @@ class AdminAppTicketControllerTest extends TestCase
$this->assertSame(1, $purchaseItem->ticketRefunds()->count());
}
public function test_it_does_not_refund_a_reserved_desfile_entry(): void
{
$tenant = $this->createTenant('desfile_pura_tendencia');
$tenant->update([
'allow_ticket_refund' => true,
'allow_ticket_total_refund' => true,
]);
$admin = $this->createAdminAppUser($tenant);
$this->grantTicketsMenu($tenant);
Sanctum::actingAs($admin);
[$ticket, $purchaseItem] = $this->createRefundableTicket($tenant, $admin, '100.00');
$inventory = $ticket->sourceCatalogItem->inventory;
$variant = Variant::query()->create([
'catalog_item_id' => $ticket->source_catalog_item_id,
'inventory_id' => $inventory->id,
'precio' => '100.00',
]);
$ticket->update(['source_variant_id' => $variant->id]);
EntryReservation::query()->create([
'variant_id' => $variant->id,
'ticket_id' => $ticket->id,
'inventory_id' => $inventory->id,
'fecha_reserva' => now(),
'importe' => '100.00',
'tipo_pago' => EntryReservationPaymentType::Other,
]);
$this->getJson('/api/v1/adminapp/tenant/tickets')
->assertOk()
->assertJsonPath('data.0.id', $ticket->id)
->assertJsonPath('data.0.amount', '100.00')
->assertJsonPath('data.0.values.amount', 100)
->assertJsonPath('data.0.allow_refund', true)
->assertJsonPath('data.0.can_refund', false);
$this->getJson("/api/v1/adminapp/tenant/tickets/{$ticket->id}/refund")
->assertUnprocessable()
->assertJsonValidationErrors('refund');
$this->postJson("/api/v1/adminapp/tenant/tickets/{$ticket->id}/refund", [
'refund_type' => TicketRefund::TYPE_TOTAL,
])
->assertUnprocessable()
->assertJsonValidationErrors('refund');
$this->assertNull($ticket->fresh()->refunded_at);
$this->assertSame(0, $purchaseItem->ticketRefunds()->count());
$this->assertSame(0, $inventory->fresh()->refunded_units);
}
public function test_it_partially_refunds_a_ticket_using_the_tenant_percentage(): void
{
$tenant = $this->createTenant('ticket-partial-refund');
@@ -840,6 +892,105 @@ class AdminAppTicketControllerTest extends TestCase
->assertJsonPath('data.0.variant_properties.0.values.0.label', 'XL');
}
public function test_desfile_exposes_and_applies_filters_and_columns_from_ticket_product_attributes(): void
{
$tenant = $this->createTenant('desfile_pura_tendencia');
$admin = $this->createAdminAppUser($tenant);
$this->grantTicketsMenu($tenant);
Sanctum::actingAs($admin);
$item = CatalogItem::query()->create([
'tenant_code' => $tenant->codigo,
'slug' => 'entrada',
'nombre' => 'Entrada',
'precio' => '1000.00',
'has_tickets' => true,
]);
$type = Attribute::query()->create([
'tenant_codigo' => $tenant->codigo,
'codigo' => 'tipo',
'nombre' => 'Tipo',
'type' => FieldType::Select,
]);
$type->options()->create(['value' => 'vip', 'label' => 'VIP']);
$sector = Attribute::query()->create([
'tenant_codigo' => $tenant->codigo,
'codigo' => 'sector',
'nombre' => 'Sector',
'type' => FieldType::Select,
]);
$sector->options()->createMany([
['value' => 'a', 'label' => 'A'],
['value' => 'b', 'label' => 'B'],
]);
$typeItemAttribute = $item->itemAttributes()->create([
'attribute_id' => $type->id,
'sort_order' => 1,
]);
$sectorItemAttribute = $item->itemAttributes()->create([
'attribute_id' => $sector->id,
'sort_order' => 2,
'ticket_label' => 'Lado',
]);
$variants = collect(['a', 'b'])->map(function (string $sectorValue) use (
$item,
$typeItemAttribute,
$sectorItemAttribute,
): Variant {
$variant = Variant::query()->create([
'catalog_item_id' => $item->id,
'inventory_id' => Inventory::query()->create()->id,
]);
$variant->definitions()->createMany([
['item_attribute_id' => $typeItemAttribute->id, 'value' => 'vip'],
['item_attribute_id' => $sectorItemAttribute->id, 'value' => $sectorValue],
]);
return $variant;
});
$purchase = $this->createPurchase($tenant, $admin, '2026-09-25 10:00:00');
$matchingItem = $this->createPurchaseItem($purchase, $item, $variants[0]);
$otherItem = $this->createPurchaseItem($purchase, $item, $variants[1]);
$matching = $this->createTicket($tenant, $admin, [
'source_purchase_item_id' => $matchingItem->id,
'source_catalog_item_id' => $item->id,
'source_variant_id' => $variants[0]->id,
]);
$this->createTicket($tenant, $admin, [
'source_purchase_item_id' => $otherItem->id,
'source_catalog_item_id' => $item->id,
'source_variant_id' => $variants[1]->id,
]);
$this->getJson('/api/v1/adminapp/forms/tickets-filter')
->assertOk()
->assertJsonPath('data.fields.0.name', 'tipo')
->assertJsonPath('data.fields.0.label', 'Tipo')
->assertJsonPath('data.fields.0.options.0', ['value' => 'vip', 'label' => 'VIP'])
->assertJsonPath('data.fields.1.name', 'sector')
->assertJsonPath('data.fields.1.label', 'Lado')
->assertJsonPath('data.columns.1.key', 'product')
->assertJsonPath('data.columns.2.key', 'tipo')
->assertJsonPath('data.columns.2.sortable', false)
->assertJsonPath('data.columns.3.key', 'sector')
->assertJsonPath('data.columns.3.label', 'Lado');
$this->getJson('/api/v1/adminapp/tenant/tickets?tipo=vip&sector=a')
->assertOk()
->assertJsonCount(1, 'data')
->assertJsonPath('data.0.id', $matching->id)
->assertJsonPath('data.0.product', 'Entrada (Sector A)')
->assertJsonPath('data.0.values.product', 'Entrada (Sector A)')
->assertJsonPath('data.0.values.tipo', 'VIP')
->assertJsonPath('data.0.values.sector', 'A');
$this->getJson('/api/v1/adminapp/tenant/tickets?sector=invalid')
->assertUnprocessable()
->assertJsonValidationErrors('sector');
}
public function test_it_applies_the_ticket_filter_form_values(): void
{
$tenant = $this->createTenant('fiesta_futbol_infantil');

View File

@@ -3,6 +3,7 @@
namespace Tests\Unit\Ticket;
use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Ticketing\Ticket\Services\AdminAppTicketAttributeService;
use App\Domains\Ticketing\Ticket\Services\AdminAppTicketColumnService;
use App\Domains\Ticketing\Ticket\Services\AdminAppTicketExcelService;
use App\Domains\Ticketing\Ticket\Services\AdminAppTicketPdfService;
@@ -149,7 +150,7 @@ class AdminAppTicketExportServiceTest extends TestCase
private function columnService(): AdminAppTicketColumnService
{
return new AdminAppTicketColumnService;
return new AdminAppTicketColumnService(new AdminAppTicketAttributeService);
}
private function spreadsheetPath(StreamedResponse $response): string

View File

@@ -2,10 +2,11 @@
namespace Tests\Unit\Ticket;
use App\Domains\Core\Auth\Models\User;
use App\Domains\Commerce\Catalog\Models\CatalogItem;
use App\Domains\Commerce\Catalog\Models\Variant;
use App\Domains\Core\Auth\Models\User;
use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Ticketing\Desfile\Models\EntryReservation;
use App\Domains\Ticketing\Ticket\Enums\ValidityTimeType;
use App\Domains\Ticketing\Ticket\Models\Ticket;
use App\Domains\Ticketing\Ticket\Models\ValidityTime;
@@ -54,6 +55,7 @@ class TicketTest extends TestCase
$this->assertInstanceOf(User::class, $ticket->scannerUser()->getRelated());
$this->assertInstanceOf(CatalogItem::class, $ticket->sourceCatalogItem()->getRelated());
$this->assertInstanceOf(Variant::class, $ticket->sourceVariant()->getRelated());
$this->assertInstanceOf(EntryReservation::class, $ticket->entryReservation()->getRelated());
}
public function test_unused_ticket_without_validity_time_is_valid(): void
@@ -83,6 +85,21 @@ class TicketTest extends TestCase
$this->assertFalse($active->can_refund());
}
public function test_a_ticket_with_an_entry_reservation_cannot_be_refunded(): void
{
$tenant = new Tenant([
'allow_ticket_refund' => true,
'allow_ticket_total_refund' => true,
]);
$ticket = (new Ticket)
->setRelation('tenant', $tenant)
->setRelation('entryReservation', new EntryReservation);
$this->assertTrue($ticket->is_active());
$this->assertTrue($ticket->allow_refund());
$this->assertFalse($ticket->can_refund());
}
public function test_fixed_window_controls_ticket_validity(): void
{
Carbon::setTestNow('2026-07-21 10:00:00');