Compare commits

..

10 Commits

107 changed files with 1723 additions and 1516 deletions

View File

@@ -0,0 +1,18 @@
<?php
namespace App\Domains\Commerce\Catalog\Enums;
enum InventoryMovementOperation: string
{
case StockInitialized = 'stock_initialized';
case StockIncreased = 'stock_increased';
case StockDecreased = 'stock_decreased';
case StockReserved = 'stock_reserved';
case StockReleased = 'stock_released';
case PurchaseCommitted = 'purchase_committed';
case StockRefunded = 'stock_refunded';
case EntryStockReserved = 'entry_stock_reserved';
case EntryStockReleased = 'entry_stock_released';
case InventoryReset = 'inventory_reset';
case InventoryTransferred = 'inventory_transferred';
}

View File

@@ -19,6 +19,7 @@ use Illuminate\Database\Eloquent\Relations\BelongsToMany;
use Illuminate\Database\Eloquent\Relations\HasMany;
use Illuminate\Database\Eloquent\SoftDeletes;
use Illuminate\Support\Collection;
use Illuminate\Support\Facades\Schema;
#[Fillable([
'tenant_code',
@@ -213,10 +214,14 @@ class CatalogItem extends Model
/** @param Builder<CatalogItem> $query */
public function scopeWhereAvailable(Builder $query): Builder
{
$availableInventory = static fn (Builder $inventoryQuery): Builder => Schema::hasColumn('inventories', 'available_stock')
? $inventoryQuery->where('inventories.available_stock', '>', 0)
: $inventoryQuery->whereRaw('inventories.real_stock > inventories.reserved_stock + inventories.entry_reserved_stock');
return $query->where(function (Builder $query): void {
$query->whereNull('catalog_items.sales_end_at')
->orWhere('catalog_items.sales_end_at', '>', now());
})->where(function (Builder $query): void {
})->where(function (Builder $query) use ($availableInventory): void {
$query
->where(function (Builder $unlimitedQuery): void {
$unlimitedQuery
@@ -236,20 +241,18 @@ class CatalogItem extends Model
->whereNull('replaced_by_variant_id')
->whereHas(
'inventory',
fn (Builder $inventoryQuery): Builder => $inventoryQuery
->whereRaw('inventories.real_stock > inventories.reserved_stock + inventories.entry_reserved_stock')
$availableInventory
)
)
->orWhere(function (Builder $directItemQuery): void {
->orWhere(function (Builder $directItemQuery) use ($availableInventory): void {
$directItemQuery
->whereDoesntHave('variants')
->where(function (Builder $inventoryQuery): void {
->where(function (Builder $inventoryQuery) use ($availableInventory): void {
$inventoryQuery
->whereNull('catalog_items.inventory_id')
->orWhereHas(
'inventory',
fn (Builder $availableInventoryQuery): Builder => $availableInventoryQuery
->whereRaw('inventories.real_stock > inventories.reserved_stock + inventories.entry_reserved_stock')
$availableInventory
);
});
});

View File

@@ -2,11 +2,17 @@
namespace App\Domains\Commerce\Catalog\Models;
use App\Domains\Commerce\Catalog\Enums\InventoryMovementOperation;
use App\Domains\Core\Auth\Models\User;
use Illuminate\Database\Eloquent\Attributes\Fillable;
use Illuminate\Database\Eloquent\Factories\HasFactory;
use Illuminate\Database\Eloquent\Model;
use Illuminate\Database\Eloquent\Relations\HasMany;
use Illuminate\Database\Eloquent\Relations\HasOne;
use Illuminate\Support\Facades\Auth;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Schema;
use Illuminate\Validation\ValidationException;
#[Fillable([
'sold_units',
@@ -38,6 +44,7 @@ class Inventory extends Model
'reserved_stock' => 'integer',
'entry_reserved_stock' => 'integer',
'real_stock' => 'integer',
'available_stock' => 'integer',
];
}
@@ -59,70 +66,295 @@ class Inventory extends Model
return $this->hasMany(StockReservationLine::class);
}
/** @return HasMany<InventoryMovement, $this> */
public function movements(): HasMany
{
return $this->hasMany(InventoryMovement::class);
}
public function availableStock(): int
{
return max(0, $this->real_stock - $this->reserved_stock - $this->entry_reserved_stock);
if (! array_key_exists('available_stock', $this->attributes)) {
return max(0, $this->real_stock - $this->reserved_stock - ($this->entry_reserved_stock ?? 0));
}
return (int) $this->getAttribute('available_stock');
}
public function reserveEntry(int $amount, bool $tracksInventory): void
{
if ($amount < 1 || ($tracksInventory && $this->availableStock() < $amount)) {
$this->mutate(
InventoryMovementOperation::EntryStockReserved,
['entry_reserved_stock' => $amount],
function (self $inventory) use ($amount, $tracksInventory): void {
if ($amount < 1 || ($tracksInventory && $inventory->availableStock() < $amount)) {
throw new \InvalidArgumentException('No hay stock disponible para la reserva de entradas.');
}
$this->entry_reserved_stock += $amount;
$this->save();
},
);
}
public function releaseEntry(int $amount): void
{
if ($amount < 1 || $this->entry_reserved_stock < $amount) {
$this->mutate(
InventoryMovementOperation::EntryStockReleased,
['entry_reserved_stock' => -$amount],
function (self $inventory) use ($amount): void {
if ($amount < 1 || $inventory->entry_reserved_stock < $amount) {
throw new \InvalidArgumentException('La cantidad de entradas reservadas no es válida.');
}
$this->entry_reserved_stock -= $amount;
$this->save();
},
);
}
public function reserve(int $amount, bool $tracksInventory): void
{
$this->mutate(
InventoryMovementOperation::StockReserved,
['reserved_stock' => $amount],
function (self $inventory) use ($amount, $tracksInventory): void {
if ($amount < 0) {
throw new \InvalidArgumentException('La cantidad a reservar debe ser positiva.');
}
if ($tracksInventory && $this->availableStock() < $amount) {
if ($tracksInventory && $inventory->availableStock() < $amount) {
throw new \InvalidArgumentException('No hay suficiente stock disponible para reservar.');
}
$this->reserved_stock += $amount;
$this->save();
},
);
}
public function release(int $amount): void
{
if ($amount < 0 || $this->reserved_stock < $amount) {
$this->mutate(
InventoryMovementOperation::StockReleased,
['reserved_stock' => -$amount],
function (self $inventory) use ($amount): void {
if ($amount < 0 || $inventory->reserved_stock < $amount) {
throw new \InvalidArgumentException('La cantidad reservada no es válida.');
}
$this->reserved_stock -= $amount;
$this->save();
},
);
}
public function buy(int $amount, bool $tracksInventory): void
{
if ($amount < 0 || $this->reserved_stock < $amount) {
$counterDeltas = ['reserved_stock' => -$amount, 'sold_units' => $amount];
if (! array_key_exists('available_stock', $this->attributes) && $tracksInventory) {
$counterDeltas['real_stock'] = -$amount;
}
$this->mutate(
InventoryMovementOperation::PurchaseCommitted,
$counterDeltas,
function (self $inventory) use ($amount, $tracksInventory): void {
if ($amount < 0 || $inventory->reserved_stock < $amount) {
throw new \InvalidArgumentException('La cantidad reservada no alcanza para confirmar la compra.');
}
if ($tracksInventory && $this->real_stock - $this->entry_reserved_stock < $amount) {
if ($tracksInventory && $inventory->availableStock() < 0) {
throw new \InvalidArgumentException('No hay suficiente stock real para confirmar la compra.');
}
if ($tracksInventory) {
$this->real_stock -= $amount;
},
);
}
$this->reserved_stock -= $amount;
$this->sold_units += $amount;
public function adjustAvailableStock(
int $delta,
?User $responsibleUser = null,
?string $idempotencyKey = null,
): void {
if ($delta === 0) {
return;
}
$operation = $delta > 0
? InventoryMovementOperation::StockIncreased
: InventoryMovementOperation::StockDecreased;
$this->mutate(
$operation,
['real_stock' => $delta],
function (self $inventory) use ($delta): void {
if ($inventory->real_stock + $delta < 0 || $inventory->availableStock() + $delta < 0) {
throw ValidationException::withMessages([
'stock_difference' => ['El ajuste dejaría el stock en un valor inválido.'],
]);
}
},
$responsibleUser,
$idempotencyKey,
);
}
public function refundStock(int $amount, ?User $responsibleUser = null): void
{
$counterDeltas = ['refunded_units' => $amount];
if (! array_key_exists('available_stock', $this->attributes)) {
$counterDeltas['real_stock'] = $amount;
}
$this->mutate(
InventoryMovementOperation::StockRefunded,
$counterDeltas,
function () use ($amount): void {
if ($amount < 1) {
throw new \InvalidArgumentException('La cantidad devuelta debe ser positiva.');
}
},
$responsibleUser,
);
}
public function commitDirectSale(int $amount, bool $tracksInventory = true): void
{
$this->mutate(
InventoryMovementOperation::PurchaseCommitted,
['sold_units' => $amount],
function (self $inventory) use ($amount, $tracksInventory): void {
if ($amount < 1 || ($tracksInventory && $inventory->availableStock() < $amount)) {
throw new \InvalidArgumentException('No hay suficiente stock para confirmar la compra.');
}
},
);
}
public function recordInitialization(?User $responsibleUser = null): void
{
$this->recordCurrentState(InventoryMovementOperation::StockInitialized, $responsibleUser);
}
public function recordTransferInitialization(?User $responsibleUser = null): void
{
$this->recordCurrentState(InventoryMovementOperation::InventoryTransferred, $responsibleUser);
}
/** @param array<string, int> $counterDeltas */
public function transferCounters(array $counterDeltas, ?User $responsibleUser = null): void
{
$counterDeltas = array_filter($counterDeltas, fn (int $delta): bool => $delta !== 0);
if ($counterDeltas === []) {
return;
}
$this->mutate(
InventoryMovementOperation::InventoryTransferred,
$counterDeltas,
function (self $inventory) use ($counterDeltas): void {
foreach ($counterDeltas as $counter => $delta) {
if ((int) $inventory->getAttribute($counter) + $delta < 0) {
throw new \LogicException("El traslado dejaría {$counter} en un valor negativo.");
}
}
},
$responsibleUser,
);
}
private function recordCurrentState(
InventoryMovementOperation $operation,
?User $responsibleUser,
): void {
if (! Schema::hasTable('inventory_movements')) {
return;
}
$this->refresh();
$counterDeltas = array_filter([
'real_stock' => $this->real_stock,
'sold_units' => $this->sold_units,
'reserved_stock' => $this->reserved_stock,
'entry_reserved_stock' => $this->entry_reserved_stock,
'refunded_units' => $this->refunded_units,
], fn (int $delta): bool => $delta !== 0);
$this->movements()->create([
'operation' => $operation,
'available_stock_delta' => $this->availableStock(),
'available_stock_before' => 0,
'available_stock_after' => $this->availableStock(),
'counter_deltas' => $counterDeltas,
'responsible_user_id' => $responsibleUser?->getKey() ?? Auth::id(),
]);
}
public function resetTransactionCounters(?User $responsibleUser = null): void
{
$this->refresh();
$counterDeltas = array_filter([
'sold_units' => -$this->sold_units,
'reserved_stock' => -$this->reserved_stock,
'entry_reserved_stock' => -$this->entry_reserved_stock,
'refunded_units' => -$this->refunded_units,
], fn (int $delta): bool => $delta !== 0);
if ($counterDeltas === []) {
return;
}
$this->mutate(
InventoryMovementOperation::InventoryReset,
$counterDeltas,
static function (): void {},
$responsibleUser,
);
}
/**
* @param array<string, int> $counterDeltas
* @param callable(self): void $validate
*/
private function mutate(
InventoryMovementOperation $operation,
array $counterDeltas,
callable $validate,
?User $responsibleUser = null,
?string $idempotencyKey = null,
): void {
DB::transaction(function () use ($operation, $counterDeltas, $validate, $responsibleUser, $idempotencyKey): void {
/** @var self $inventory */
$inventory = self::query()->lockForUpdate()->findOrFail($this->getKey());
$this->setRawAttributes($inventory->getAttributes(), true);
$recordsMovements = Schema::hasTable('inventory_movements');
if ($recordsMovements && $idempotencyKey !== null) {
$existing = $this->movements()
->where('idempotency_key', $idempotencyKey)
->first();
if ($existing !== null) {
if ($existing->counter_deltas !== $counterDeltas) {
throw ValidationException::withMessages([
'stock_adjustment_id' => ['La operación ya fue utilizada con otro ajuste.'],
]);
}
return;
}
}
$validate($this);
$counterDeltas = array_filter($counterDeltas, fn (int $delta): bool => $delta !== 0);
if ($counterDeltas === []) {
return;
}
$availableBefore = $this->availableStock();
foreach ($counterDeltas as $counter => $delta) {
$this->setAttribute($counter, (int) $this->getAttribute($counter) + $delta);
}
$this->save();
$this->refresh();
$availableAfter = $this->availableStock();
if ($recordsMovements) {
$this->movements()->create([
'operation' => $operation,
'available_stock_delta' => $availableAfter - $availableBefore,
'available_stock_before' => $availableBefore,
'available_stock_after' => $availableAfter,
'counter_deltas' => $counterDeltas,
'responsible_user_id' => $responsibleUser?->getKey() ?? Auth::id(),
'idempotency_key' => $idempotencyKey,
]);
}
});
}
}

View File

@@ -0,0 +1,45 @@
<?php
namespace App\Domains\Commerce\Catalog\Models;
use App\Domains\Commerce\Catalog\Enums\InventoryMovementOperation;
use App\Domains\Core\Auth\Models\User;
use Illuminate\Database\Eloquent\Attributes\Fillable;
use Illuminate\Database\Eloquent\Model;
use Illuminate\Database\Eloquent\Relations\BelongsTo;
#[Fillable([
'inventory_id',
'operation',
'available_stock_delta',
'available_stock_before',
'available_stock_after',
'counter_deltas',
'responsible_user_id',
'idempotency_key',
])]
class InventoryMovement extends Model
{
protected function casts(): array
{
return [
'operation' => InventoryMovementOperation::class,
'available_stock_delta' => 'integer',
'available_stock_before' => 'integer',
'available_stock_after' => 'integer',
'counter_deltas' => 'array',
];
}
/** @return BelongsTo<Inventory, $this> */
public function inventory(): BelongsTo
{
return $this->belongsTo(Inventory::class);
}
/** @return BelongsTo<User, $this> */
public function responsibleUser(): BelongsTo
{
return $this->belongsTo(User::class, 'responsible_user_id');
}
}

View File

@@ -64,6 +64,7 @@ class CatalogInventoryService
$selection->loadMissing('variants.inventory');
return $selection->variants
->each(fn (Variant $variant) => $variant->setRelation('catalogItem', $selection))
->filter(fn (Variant $variant): bool => $variant->isSellable())
->unique(fn (Variant $variant): string => $variant->inventory_id === null
? 'object:'.spl_object_id($variant->inventory)
@@ -153,7 +154,7 @@ class CatalogInventoryService
if ($operation === 'commit'
&& $requirement['tracks_inventory']
&& $inventory->real_stock - $inventory->entry_reserved_stock < $requiredQuantity) {
&& $inventory->availableStock() < 0) {
throw new \InvalidArgumentException('No hay suficiente stock real para confirmar la compra.');
}
}

View File

@@ -370,9 +370,12 @@ class CatalogService
private function createInventory(int $realStock): Inventory
{
return Inventory::query()->create([
$inventory = Inventory::query()->create([
'real_stock' => $realStock,
]);
$inventory->recordInitialization();
return $inventory;
}
/**

View File

@@ -225,7 +225,7 @@ class StockReservationService
$inventory = $inventories->get($line->inventory_id)
?? throw new \InvalidArgumentException('No se encontró el inventario reservado.');
if ($inventory->reserved_stock < $line->quantity
|| ($line->tracks_inventory && $inventory->real_stock - $inventory->entry_reserved_stock < $line->quantity)) {
|| ($line->tracks_inventory && $inventory->availableStock() < 0)) {
throw new \InvalidArgumentException('La reserva de stock no alcanza para confirmar la compra.');
}
}

View File

@@ -194,6 +194,7 @@ class VariantReplacementService
'entry_reserved_stock' => $sourceInventory->entry_reserved_stock,
'real_stock' => $sourceInventory->real_stock,
]);
$replacementInventory->recordTransferInitialization();
if ($activeLines->isNotEmpty()) {
StockReservationLine::query()
@@ -202,7 +203,10 @@ class VariantReplacementService
}
EntryReservation::query()->where('inventory_id', $sourceInventory->id)
->update(['inventory_id' => $replacementInventory->id]);
$sourceInventory->update(['reserved_stock' => 0, 'entry_reserved_stock' => 0]);
$sourceInventory->transferCounters([
'reserved_stock' => -$sourceInventory->reserved_stock,
'entry_reserved_stock' => -$sourceInventory->entry_reserved_stock,
]);
return $replacementInventory;
}
@@ -236,13 +240,14 @@ class VariantReplacementService
throw new \LogicException('El inventario reservado de la variante es inconsistente.');
}
$destinationInventory->update([
'real_stock' => $destinationInventory->real_stock + $sourceInventory->real_stock,
'reserved_stock' => $destinationInventory->reserved_stock + $sourceInventory->reserved_stock,
'entry_reserved_stock' => $destinationInventory->entry_reserved_stock + $sourceInventory->entry_reserved_stock,
'sold_units' => $destinationInventory->sold_units + $sourceInventory->sold_units,
'refunded_units' => $destinationInventory->refunded_units + $sourceInventory->refunded_units,
]);
$transferredCounters = [
'real_stock' => $sourceInventory->real_stock,
'reserved_stock' => $sourceInventory->reserved_stock,
'entry_reserved_stock' => $sourceInventory->entry_reserved_stock,
'sold_units' => $sourceInventory->sold_units,
'refunded_units' => $sourceInventory->refunded_units,
];
$destinationInventory->transferCounters($transferredCounters);
if ($activeLines->isNotEmpty()) {
StockReservationLine::query()
->whereKey($activeLines->modelKeys())
@@ -250,13 +255,10 @@ class VariantReplacementService
}
EntryReservation::query()->where('inventory_id', $sourceInventory->id)
->update(['inventory_id' => $destinationInventory->id]);
$sourceInventory->update([
'real_stock' => 0,
'reserved_stock' => 0,
'entry_reserved_stock' => 0,
'sold_units' => 0,
'refunded_units' => 0,
]);
$sourceInventory->transferCounters(array_map(
fn (int $value): int => -$value,
$transferredCounters,
));
}
/** @return list<string> */

View File

@@ -34,8 +34,3 @@ Bajo `/v1/adminapp/tenant/featured-groups`, con `auth:sanctum` y `adminapp.tenan
## Dependencias y reglas
Usa `Attachable` para imágenes/archivos, `Tenant` para aislamiento y `Ticket`/`Event` para vigencia y fechas. `Cart` y `Purchase` consumen sus precios, variantes e inventario. Los cambios de stock deben pasar por `CatalogInventoryService` para conservar reservas y disponibilidad.
## Menús deprecados
Los menús `adminapp.combos` y `adminapp.categories` están retirados; las
categorías del catálogo y sus datos comerciales no se eliminan.

View File

@@ -8,13 +8,12 @@ use Illuminate\Database\Eloquent\Builder;
class PurchaseRefundSummaryService
{
public function totalForTenant(Tenant $tenant, ?int $eventId = null): string
public function totalForTenant(Tenant $tenant): string
{
$total = TicketRefund::query()
->whereHas(
'purchaseItem.purchase',
fn (Builder $query): Builder => $query->where('tenant_codigo', $tenant->codigo)
->when($eventId !== null, fn (Builder $purchase) => $purchase->where('event_id', $eventId))
)
->sum('amount');

View File

@@ -2,6 +2,7 @@
namespace App\Domains\Commerce\Purchase\Services;
use App\Domains\Commerce\Catalog\Models\Inventory;
use App\Domains\Commerce\Purchase\Models\Purchase;
use Illuminate\Database\Query\Builder;
use Illuminate\Support\Collection;
@@ -69,15 +70,12 @@ class TenantTransactionResetService
'users_preserved' => DB::table('users')->where('tenant_codigo', $tenantCode)->count(),
];
DB::table('inventories')
->whereIn('id', $scope['inventory_ids'])
->update([
'real_stock' => DB::raw('real_stock + sold_units - refunded_units'),
'reserved_stock' => 0,
'entry_reserved_stock' => 0,
'sold_units' => 0,
'refunded_units' => 0,
]);
Inventory::query()
->whereKey($scope['inventory_ids'])
->orderBy('id')
->lockForUpdate()
->get()
->each(fn (Inventory $inventory) => $inventory->resetTransactionCounters());
return $summary;
});

View File

@@ -13,7 +13,6 @@ use App\Domains\Commerce\Sale\Resources\AdminApp\SaleTicketResource;
use App\Domains\Commerce\Sale\Services\AdminAppSaleExcelService;
use App\Domains\Commerce\Sale\Services\AdminAppSalePdfService;
use App\Domains\Commerce\Sale\Services\AdminAppSaleService;
use App\Domains\Core\Auth\Services\EventScopeService;
use App\Http\Controllers\Controller;
use Illuminate\Http\Request;
use Illuminate\Http\Resources\Json\AnonymousResourceCollection;
@@ -28,20 +27,15 @@ class SaleController extends Controller
protected AdminAppSaleExcelService $saleExcelService,
) {}
private function eventId(Request $request): ?int
{
return app(EventScopeService::class)->eventId($request->user());
}
public function index(AdminAppSaleIndexRequest $request): AnonymousResourceCollection
{
$tenant = $request->user()->tenant()->firstOrFail();
return SaleResource::collection(
$this->saleService->sales($tenant, $request->validated(), $this->eventId($request))
$this->saleService->sales($tenant, $request->validated())
)->additional([
'confirmed_sales_total' => $this->saleService->confirmedSalesTotal($tenant, $this->eventId($request)),
'refunded_total' => $this->saleService->refundedTotal($tenant, $this->eventId($request)),
'confirmed_sales_total' => $this->saleService->confirmedSalesTotal($tenant),
'refunded_total' => $this->saleService->refundedTotal($tenant),
]);
}
@@ -49,7 +43,7 @@ class SaleController extends Controller
{
$tenant = $request->user()->tenant()->firstOrFail();
return new SaleDetailResource($this->saleService->detail($tenant, $sale, $this->eventId($request)));
return new SaleDetailResource($this->saleService->detail($tenant, $sale));
}
public function tickets(Request $request, int $sale): AnonymousResourceCollection
@@ -57,7 +51,7 @@ class SaleController extends Controller
$tenant = $request->user()->tenant()->firstOrFail();
return SaleTicketResource::collection(
$this->saleService->tickets($tenant, $sale, $this->eventId($request))
$this->saleService->tickets($tenant, $sale)
);
}
@@ -65,14 +59,14 @@ class SaleController extends Controller
{
$tenant = $request->user()->tenant()->firstOrFail();
return new SaleResource($this->saleService->confirm($tenant, $sale, $this->eventId($request)));
return new SaleResource($this->saleService->confirm($tenant, $sale));
}
public function cancel(Request $request, int $sale): SaleResource
{
$tenant = $request->user()->tenant()->firstOrFail();
return new SaleResource($this->saleService->cancel($tenant, $sale, $this->eventId($request)));
return new SaleResource($this->saleService->cancel($tenant, $sale));
}
public function modifications(
@@ -82,7 +76,6 @@ class SaleController extends Controller
$this->saleService->modifications(
$request->user()->tenant()->firstOrFail(),
$request->validated(),
$this->eventId($request),
)
);
}
@@ -93,7 +86,7 @@ class SaleController extends Controller
return $this->salePdfService->downloadSales(
$tenant,
$this->saleService->salesForExport($tenant, $request->validated(), $this->eventId($request)),
$this->saleService->salesForExport($tenant, $request->validated()),
$request->validated('timezone'),
);
}
@@ -104,7 +97,7 @@ class SaleController extends Controller
return $this->salePdfService->downloadModifications(
$tenant,
$this->saleService->modificationsForExport($tenant, $request->validated(), $this->eventId($request)),
$this->saleService->modificationsForExport($tenant, $request->validated()),
$request->validated('timezone'),
);
}
@@ -115,7 +108,7 @@ class SaleController extends Controller
return $this->saleExcelService->downloadSales(
$tenant,
$this->saleService->salesForExport($tenant, $request->validated(), $this->eventId($request)),
$this->saleService->salesForExport($tenant, $request->validated()),
$request->validated('timezone'),
);
}
@@ -127,7 +120,7 @@ class SaleController extends Controller
return $this->saleExcelService->downloadModifications(
$tenant,
$this->saleService->modificationsForExport($tenant, $request->validated(), $this->eventId($request)),
$this->saleService->modificationsForExport($tenant, $request->validated()),
$request->validated('timezone'),
);
}

View File

@@ -2,6 +2,7 @@
namespace App\Domains\Commerce\Sale\Services;
use App\Shared\Logging\Models\ValueChange;
use App\Domains\Commerce\Purchase\Models\Purchase;
use App\Domains\Commerce\Purchase\Services\CheckoutService;
use App\Domains\Commerce\Purchase\Services\PurchaseRefundSummaryService;
@@ -9,7 +10,6 @@ use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Ticketing\Ticket\Models\Ticket;
use App\Domains\Ticketing\Ticket\Services\TicketPresentationResolver;
use App\Domains\Ticketing\Ticket\Services\TicketValidityResolver;
use App\Shared\Logging\Models\ValueChange;
use Illuminate\Database\Eloquent\Builder;
use Illuminate\Pagination\LengthAwarePaginator;
use Illuminate\Support\Collection;
@@ -21,20 +21,19 @@ class AdminAppSaleService
protected PurchaseRefundSummaryService $refundSummaryService,
) {}
public function confirmedSalesTotal(Tenant $tenant, ?int $eventId = null): string
public function confirmedSalesTotal(Tenant $tenant): string
{
$total = Purchase::query()
->where('tenant_codigo', $tenant->codigo)
->when($eventId !== null, fn (Builder $query) => $query->where('event_id', $eventId))
->where('status', Purchase::STATUS_PAID)
->sum('total');
return number_format((float) $total, 2, '.', '');
}
public function refundedTotal(Tenant $tenant, ?int $eventId = null): string
public function refundedTotal(Tenant $tenant): string
{
return $this->refundSummaryService->totalForTenant($tenant, $eventId);
return $this->refundSummaryService->totalForTenant($tenant);
}
/**
@@ -48,44 +47,43 @@ class AdminAppSaleService
* } $filters
* @return LengthAwarePaginator<Purchase>
*/
public function sales(Tenant $tenant, array $filters = [], ?int $eventId = null): LengthAwarePaginator
public function sales(Tenant $tenant, array $filters = []): LengthAwarePaginator
{
return $this->salesQuery($tenant, $filters, $eventId)
return $this->salesQuery($tenant, $filters)
->paginateFromRequest()
->withQueryString();
}
public function detail(Tenant $tenant, int $saleId, ?int $eventId = null): Purchase
public function detail(Tenant $tenant, int $saleId): Purchase
{
return Purchase::query()
->where('tenant_codigo', $tenant->codigo)
->when($eventId !== null, fn (Builder $query) => $query->where('event_id', $eventId))
->with('items')
->findOrFail($saleId);
}
/** @return Collection<int, Ticket> */
public function tickets(Tenant $tenant, int $saleId, ?int $eventId = null): Collection
public function tickets(Tenant $tenant, int $saleId): Collection
{
return $this->findForTenant($tenant, $saleId, $eventId)
return $this->findForTenant($tenant, $saleId)
->tickets()
->with([...TicketValidityResolver::RELATIONS, ...TicketPresentationResolver::RELATIONS, 'refund'])
->orderBy('id')
->get();
}
public function confirm(Tenant $tenant, int $saleId, ?int $eventId = null): Purchase
public function confirm(Tenant $tenant, int $saleId): Purchase
{
$sale = $this->findForTenant($tenant, $saleId, $eventId);
$sale = $this->findForTenant($tenant, $saleId);
return $this->saleForResponse(
$this->checkoutService->confirmPaidPurchase($sale)
);
}
public function cancel(Tenant $tenant, int $saleId, ?int $eventId = null): Purchase
public function cancel(Tenant $tenant, int $saleId): Purchase
{
$sale = $this->findForTenant($tenant, $saleId, $eventId);
$sale = $this->findForTenant($tenant, $saleId);
return $this->saleForResponse(
$this->checkoutService->cancelPurchaseFromAdmin($sale)
@@ -96,18 +94,18 @@ class AdminAppSaleService
* @param array<string, mixed> $filters
* @return Collection<int, Purchase>
*/
public function salesForExport(Tenant $tenant, array $filters = [], ?int $eventId = null): Collection
public function salesForExport(Tenant $tenant, array $filters = []): Collection
{
return $this->salesQuery($tenant, $filters, $eventId)->get();
return $this->salesQuery($tenant, $filters)->get();
}
/**
* @param array<string, mixed> $filters
* @return LengthAwarePaginator<ValueChange>
*/
public function modifications(Tenant $tenant, array $filters = [], ?int $eventId = null): LengthAwarePaginator
public function modifications(Tenant $tenant, array $filters = []): LengthAwarePaginator
{
return $this->modificationsQuery($tenant, $filters, $eventId)
return $this->modificationsQuery($tenant, $filters)
->paginateFromRequest()
->withQueryString();
}
@@ -116,13 +114,13 @@ class AdminAppSaleService
* @param array<string, mixed> $filters
* @return Collection<int, ValueChange>
*/
public function modificationsForExport(Tenant $tenant, array $filters = [], ?int $eventId = null): Collection
public function modificationsForExport(Tenant $tenant, array $filters = []): Collection
{
return $this->modificationsQuery($tenant, $filters, $eventId)->get();
return $this->modificationsQuery($tenant, $filters)->get();
}
/** @param array<string, mixed> $filters */
protected function salesQuery(Tenant $tenant, array $filters, ?int $eventId = null): Builder
protected function salesQuery(Tenant $tenant, array $filters): Builder
{
$sortColumns = [
'id' => 'id',
@@ -141,7 +139,6 @@ class AdminAppSaleService
return Purchase::query()
->where('tenant_codigo', $tenant->codigo)
->when($eventId !== null, fn (Builder $query) => $query->where('event_id', $eventId))
->when($filters['q'] ?? null, function (Builder $query, string $search): void {
$term = trim($search);
@@ -179,14 +176,11 @@ class AdminAppSaleService
* @param array<string, mixed> $filters
* @return Builder<ValueChange>
*/
protected function modificationsQuery(Tenant $tenant, array $filters, ?int $eventId = null): Builder
protected function modificationsQuery(Tenant $tenant, array $filters): Builder
{
return ValueChange::query()
->where('tenant_code', $tenant->codigo)
->where('trackable_type', (new Purchase)->getMorphClass())
->when($eventId !== null, fn (Builder $query) => $query->whereHasMorph(
'trackable', [Purchase::class],
fn (Builder $sales) => $sales->where('event_id', $eventId)))
->when($filters['q'] ?? null, function (Builder $query, string $search): void {
$term = trim($search);
@@ -227,11 +221,10 @@ class AdminAppSaleService
->orderByDesc('id');
}
protected function findForTenant(Tenant $tenant, int $saleId, ?int $eventId = null): Purchase
protected function findForTenant(Tenant $tenant, int $saleId): Purchase
{
return Purchase::query()
->where('tenant_codigo', $tenant->codigo)
->when($eventId !== null, fn (Builder $query) => $query->where('event_id', $eventId))
->findOrFail($saleId);
}

View File

@@ -30,10 +30,3 @@ Consume compras de `Purchase`, datos del tenant y entradas de `Logging`. No es d
La consulta paginada y la colección de exportación deben aplicar los mismos filtros para evitar diferencias entre pantalla, PDF y Excel.
El historial comparte con ventas los filtros de búsqueda, ID, fecha de venta y estado. En el historial, el estado se evalúa sobre `ValueChange.new_value`: representa el resultado de esa modificación y no el estado actual de la venta.
## Alcance por evento
Las rutas usan `adminapp.tenant:event`. Para admins de evento, listados, totales,
detalles, tickets de compras, confirmación, cancelación, historial y exportaciones
se filtran por `user.event_id` además del tenant. Las compras pertenecen a un
único evento. Un admin de tenant conserva acceso a sus compras de todos los eventos.

View File

@@ -4,7 +4,7 @@ use App\Domains\Commerce\Sale\Controllers\AdminApp\SaleController;
use Illuminate\Support\Facades\Route;
Route::prefix('v1/adminapp/tenant')
->middleware(['auth:sanctum', 'adminapp.tenant:event'])
->middleware(['auth:sanctum', 'adminapp.tenant'])
->group(function (): void {
Route::get('sales', [SaleController::class, 'index']);
Route::get('sales/pdf', [SaleController::class, 'downloadPdf']);

View File

@@ -1,9 +0,0 @@
<?php
namespace App\Domains\Core\Auth\Enums;
enum AdminScope: string
{
case Tenant = 'tenant';
case Event = 'event';
}

View File

@@ -2,13 +2,11 @@
namespace App\Domains\Core\Auth\Models;
use App\Domains\Commerce\Catalog\Models\Category;
use App\Domains\Core\Auth\Enums\AdminScope;
use App\Domains\Core\Authorization\Enums\RoleCode;
use App\Domains\Core\Authorization\Models\Role;
use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Ticketing\Event\Models\Event;
use App\Domains\Commerce\Catalog\Models\Category;
use App\Domains\Ticketing\Event\Models\EventDateChangeView;
use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Ticketing\Ticket\Models\ScanAttempt;
use Database\Factories\UserFactory;
use Illuminate\Database\Eloquent\Attributes\Fillable;
@@ -22,7 +20,7 @@ use Illuminate\Foundation\Auth\User as Authenticatable;
use Illuminate\Notifications\Notifiable;
use Laravel\Sanctum\HasApiTokens;
#[Fillable(['nombre_apellido', 'email', 'password', 'dni', 'telefono', 'google_id', 'rol_codigo', 'tenant_codigo', 'admin_scope', 'event_id'])]
#[Fillable(['nombre_apellido', 'email', 'password', 'dni', 'telefono', 'google_id', 'rol_codigo', 'tenant_codigo'])]
#[Hidden(['password', 'remember_token', 'active_email', 'active_google_id'])]
class User extends Authenticatable
{
@@ -31,7 +29,6 @@ class User extends Authenticatable
protected $attributes = [
'rol_codigo' => RoleCode::User->value,
'admin_scope' => AdminScope::Tenant->value,
];
protected static function newFactory(): UserFactory
@@ -89,19 +86,6 @@ class User extends Authenticatable
return $this->belongsTo(Tenant::class, 'tenant_codigo', 'codigo');
}
/** @return BelongsTo<Event, $this> */
public function event(): BelongsTo
{
return $this->belongsTo(Event::class);
}
public function isTenantAdministrator(): bool
{
return $this->rol_codigo === RoleCode::AdminApp->value
&& $this->admin_scope === AdminScope::Tenant->value
&& $this->event_id === null;
}
/** @return BelongsToMany<Category, $this> */
public function scanCategories(): BelongsToMany
{
@@ -119,7 +103,6 @@ class User extends Authenticatable
protected function casts(): array
{
return [
'event_id' => 'integer',
'email_verified_at' => 'datetime',
'password' => 'hashed',
'failed_login_attempts' => 'integer',

View File

@@ -20,11 +20,6 @@ class AdminAppMeResource extends JsonResource
return [
'user' => UserResource::make($this->resource),
'tenant' => TenantResource::make($this->tenant),
'event' => $this->whenLoaded('event', fn () => $this->event === null ? null : [
'id' => $this->event->id,
'title' => $this->event->title,
'tenant_code' => $this->event->tenant_code,
]),
];
}
}

View File

@@ -16,9 +16,6 @@ class ScannerMeResource extends JsonResource
return [
'user' => UserResource::make($this->resource),
'tenant' => TenantResource::make($this->tenant),
'event' => $this->whenLoaded('event', fn () => $this->event === null ? null : [
'id' => $this->event->id, 'title' => $this->event->title,
]),
];
}
}

View File

@@ -3,7 +3,6 @@
namespace App\Domains\Core\Auth\Resources;
use App\Domains\Core\Auth\Models\User;
use App\Domains\Core\Authorization\Enums\RoleCode;
use Illuminate\Http\Request;
use Illuminate\Http\Resources\Json\JsonResource;
@@ -25,8 +24,6 @@ class UserResource extends JsonResource
'telefono' => $this->telefono,
'rol_codigo' => $this->rol_codigo,
'tenant_codigo' => $this->tenant_codigo,
'admin_scope' => $this->when($this->rol_codigo === RoleCode::AdminApp->value, $this->admin_scope),
'event_id' => $this->when(in_array($this->rol_codigo, [RoleCode::AdminApp->value, RoleCode::Scanner->value], true), $this->event_id),
'categories' => $this->whenLoaded('scanCategories', fn () => $this->scanCategories
->map(fn ($category) => [
'id' => $category->id,

View File

@@ -1,27 +0,0 @@
<?php
namespace App\Domains\Core\Auth\Services;
use App\Domains\Core\Auth\Enums\AdminScope;
use App\Domains\Core\Auth\Models\User;
use App\Domains\Core\Authorization\Enums\RoleCode;
class AdminAppAccessService
{
public function hasValidScope(User $user): bool
{
if ($user->rol_codigo !== RoleCode::AdminApp->value
|| ! $user->tenant_codigo
|| ! $user->tenant()->exists()) {
return false;
}
if ($user->isTenantAdministrator()) {
return true;
}
return $user->admin_scope === AdminScope::Event->value
&& $user->event_id !== null
&& $user->event()->where('tenant_code', $user->tenant_codigo)->exists();
}
}

View File

@@ -20,7 +20,6 @@ class AdminAppContextService
->firstOrFail();
$user->setRelation('tenant', $tenant);
$user->load('event');
return $user;
}

View File

@@ -1,24 +0,0 @@
<?php
namespace App\Domains\Core\Auth\Services;
use App\Domains\Core\Auth\Enums\AdminScope;
use App\Domains\Core\Auth\Models\User;
use Illuminate\Auth\Access\AuthorizationException;
class EventScopeService
{
public function eventId(User $user): ?int
{
if ($user->admin_scope === AdminScope::Event->value || $user->event_id !== null) {
if ($user->event_id === null
|| ! $user->event()->where('tenant_code', $user->tenant_codigo)->exists()) {
throw new AuthorizationException;
}
return $user->event_id;
}
return null;
}
}

View File

@@ -10,7 +10,6 @@ use App\Domains\Core\Authorization\Enums\PermissionCode;
use App\Domains\Core\Authorization\Enums\RoleCode;
use App\Shared\Notification\Events\PasswordResetRequested;
use Carbon\CarbonImmutable;
use Illuminate\Auth\Access\AuthorizationException;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Hash;
use Illuminate\Support\Facades\Log;
@@ -20,7 +19,6 @@ class PasswordLoginService
{
public function __construct(
private readonly ResetPasswordAttemptService $resetPasswordAttemptService,
private readonly AdminAppAccessService $adminAppAccessService,
) {}
/**
@@ -198,26 +196,6 @@ class PasswordLoginService
];
}
if ($requiredRole === RoleCode::AdminApp && ! $this->adminAppAccessService->hasValidScope($user)) {
$this->recordAttempt(
$user, $normalizedEmail, $attemptTenantCode,
LoginAttempt::OUTCOME_INVALID_CREDENTIALS, $ipAddress, $userAgent,
);
return ['outcome' => LoginAttempt::OUTCOME_INVALID_CREDENTIALS, 'user' => $user, 'locked_until' => null];
}
if ($requiredRole === RoleCode::Scanner) {
try {
app(EventScopeService::class)->eventId($user);
} catch (AuthorizationException) {
$this->recordAttempt($user, $normalizedEmail, $attemptTenantCode,
LoginAttempt::OUTCOME_INVALID_CREDENTIALS, $ipAddress, $userAgent);
return ['outcome' => LoginAttempt::OUTCOME_INVALID_CREDENTIALS, 'user' => $user, 'locked_until' => null];
}
}
$user->forceFill([
'failed_login_attempts' => 0,
'last_failed_login_at' => null,

View File

@@ -18,7 +18,6 @@ class ScannerContextService
->firstOrFail();
$user->setRelation('tenant', $tenant);
$user->load('event');
if ($tenant->requiresScannerCategoryValidation()) {
$categories = $user->scanCategories()

View File

@@ -17,6 +17,6 @@ Route::prefix('v1/adminapp')->group(function (): void {
Route::post('password/reset', ResetPasswordController::class)
->defaults('reset_role', 'adminapp')
->middleware('throttle:5,1');
Route::middleware(['auth:sanctum', 'adminapp.tenant:context'])
Route::middleware(['auth:sanctum', 'adminapp.tenant'])
->get('me', AdminAppMeController::class);
});

View File

@@ -2,7 +2,6 @@
namespace App\Domains\Core\Staff\Controllers;
use App\Domains\Core\Auth\Services\EventScopeService;
use App\Domains\Core\Staff\Requests\StoreStaffRequest;
use App\Domains\Core\Staff\Requests\UpdateStaffRequest;
use App\Domains\Core\Staff\Resources\StaffResource;
@@ -22,17 +21,11 @@ class AdminAppStaffController extends Controller
private readonly ScannerTicketService $scannerTicketService,
) {}
private function eventId(Request $request): ?int
{
return app(EventScopeService::class)->eventId($request->user());
}
public function index(Request $request): AnonymousResourceCollection
{
return StaffResource::collection($this->staffService->list(
$request->user()->tenant()->firstOrFail(),
$request->string('search')->trim()->toString() ?: null,
$this->eventId($request),
));
}
@@ -41,7 +34,6 @@ class AdminAppStaffController extends Controller
return StaffResource::make($this->staffService->create(
$request->user()->tenant()->firstOrFail(),
$request->validated(),
$this->eventId($request),
));
}
@@ -51,13 +43,12 @@ class AdminAppStaffController extends Controller
$request->user()->tenant()->firstOrFail(),
$staff,
$request->validated(),
$this->eventId($request),
));
}
public function destroy(Request $request, int $staff): Response
{
$this->staffService->delete($request->user()->tenant()->firstOrFail(), $staff, $this->eventId($request));
$this->staffService->delete($request->user()->tenant()->firstOrFail(), $staff);
return response()->noContent();
}
@@ -69,7 +60,6 @@ class AdminAppStaffController extends Controller
$scanner = $this->staffService->find(
$request->user()->tenant()->firstOrFail(),
$staff,
$this->eventId($request),
);
return ScanAttemptResource::collection(

View File

@@ -14,7 +14,6 @@ class StaffResource extends JsonResource
{
return [
'id' => $this->id,
'event_id' => $this->event_id,
'nombre_apellido' => $this->nombre_apellido,
'dni' => $this->dni,
'email' => $this->email,

View File

@@ -2,13 +2,12 @@
namespace App\Domains\Core\Staff\Services;
use App\Domains\Commerce\Catalog\Models\Category;
use App\Domains\Core\Auth\Models\ResetPasswordAttempt;
use App\Domains\Core\Auth\Models\User;
use App\Domains\Core\Auth\Services\ResetPasswordAttemptService;
use App\Domains\Core\Authorization\Enums\RoleCode;
use App\Domains\Commerce\Catalog\Models\Category;
use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Ticketing\Event\Models\Event;
use Illuminate\Database\Eloquent\Builder;
use Illuminate\Database\Eloquent\Collection;
use Illuminate\Support\Arr;
@@ -23,9 +22,9 @@ class StaffService
) {}
/** @return Collection<int, User> */
public function list(Tenant $tenant, ?string $search = null, ?int $eventId = null): Collection
public function list(Tenant $tenant, ?string $search = null): Collection
{
return $this->staffQuery($tenant, $eventId)
return $this->staffQuery($tenant)
->with(['role', 'scanCategories' => fn ($query) => $query->orderBy('nombre')])
->when($search, function (Builder $query, string $search): void {
$query->where(function (Builder $query) use ($search): void {
@@ -39,7 +38,7 @@ class StaffService
}
/** @return Collection<int, Category> */
private function assignableCategories(Tenant $tenant, ?int $eventId = null): Collection
private function assignableCategories(Tenant $tenant): Collection
{
return Category::query()
->whereNull('categoria_id')
@@ -48,30 +47,23 @@ class StaffService
->orWhereHas('catalogItems', fn (Builder $items) => $items
->where('tenant_code', $tenant->codigo));
})
->when($eventId !== null, fn (Builder $query) => $query->whereHas(
'catalogItems', fn (Builder $items) => $items->where('tenant_code', $tenant->codigo)->where('event_id', $eventId)))
->orderBy('nombre')
->get();
}
/** @param array<string, mixed> $data */
public function create(Tenant $tenant, array $data, ?int $eventId = null): User
public function create(Tenant $tenant, array $data): User
{
$eventId ??= $tenant->active_event_id;
Event::query()
->where('tenant_code', $tenant->codigo)->findOrFail($eventId);
$categoryIds = $this->categoryIdsFor($tenant, $data);
$this->assertCategoriesBelongToTenant($tenant, $categoryIds, $eventId);
$this->assertCategoriesBelongToTenant($tenant, $categoryIds);
return DB::transaction(function () use ($tenant, $data, $categoryIds, $eventId): User {
return DB::transaction(function () use ($tenant, $data, $categoryIds): User {
$staff = User::query()->create([
...Arr::only($data, ['nombre_apellido', 'dni', 'email']),
'email' => mb_strtolower(trim((string) $data['email'])),
'password' => Str::random(64),
'rol_codigo' => RoleCode::Scanner->value,
'tenant_codigo' => $tenant->codigo,
'event_id' => $eventId,
'admin_scope' => $eventId === null ? 'tenant' : 'event',
]);
$staff->scanCategories()->sync($categoryIds);
$this->resetPasswordAttemptService->createForScannerEmail(
@@ -84,11 +76,11 @@ class StaffService
}
/** @param array<string, mixed> $data */
public function update(Tenant $tenant, int $staffId, array $data, ?int $eventId = null): User
public function update(Tenant $tenant, int $staffId, array $data): User
{
$staff = $this->find($tenant, $staffId, $eventId);
$staff = $this->find($tenant, $staffId);
$categoryIds = $this->categoryIdsFor($tenant, $data);
$this->assertCategoriesBelongToTenant($tenant, $categoryIds, $eventId);
$this->assertCategoriesBelongToTenant($tenant, $categoryIds);
return DB::transaction(function () use ($staff, $data, $categoryIds): User {
$attributes = Arr::only($data, ['nombre_apellido', 'dni', 'email']);
@@ -100,9 +92,9 @@ class StaffService
});
}
public function delete(Tenant $tenant, int $staffId, ?int $eventId = null): void
public function delete(Tenant $tenant, int $staffId): void
{
$staff = $this->find($tenant, $staffId, $eventId);
$staff = $this->find($tenant, $staffId);
DB::transaction(function () use ($staff): void {
$staff->tokens()->delete();
@@ -110,24 +102,23 @@ class StaffService
});
}
public function find(Tenant $tenant, int $staffId, ?int $eventId = null): User
public function find(Tenant $tenant, int $staffId): User
{
return $this->staffQuery($tenant, $eventId)->findOrFail($staffId);
return $this->staffQuery($tenant)->findOrFail($staffId);
}
private function staffQuery(Tenant $tenant, ?int $eventId = null): Builder
private function staffQuery(Tenant $tenant): Builder
{
return User::query()
->where('tenant_codigo', $tenant->codigo)
->where('rol_codigo', RoleCode::Scanner->value)
->when($eventId !== null, fn (Builder $query) => $query->where('event_id', $eventId));
->where('rol_codigo', RoleCode::Scanner->value);
}
/**
* @param array<string, mixed> $data
* @return array<int, int>
*/
private function categoryIdsFor(Tenant $tenant, array $data, ?int $eventId = null): array
private function categoryIdsFor(Tenant $tenant, array $data): array
{
if (! $tenant->requiresScannerCategoryValidation()) {
return [];
@@ -137,9 +128,9 @@ class StaffService
}
/** @param array<int, int> $categoryIds */
private function assertCategoriesBelongToTenant(Tenant $tenant, array $categoryIds, ?int $eventId = null): void
private function assertCategoriesBelongToTenant(Tenant $tenant, array $categoryIds): void
{
$validIds = $this->assignableCategories($tenant, $eventId)
$validIds = $this->assignableCategories($tenant)
->whereIn('id', $categoryIds)
->pluck('id');

View File

@@ -18,13 +18,3 @@ Recurso REST `/v1/adminapp/tenant/staff`, excepto detalle individual, protegido
## Dependencias y reglas
Usa `Auth/User` como entidad de personal, `Authorization` para su rol, `Catalog/Category` para asignaciones y `Tenant` para aislamiento. Toda búsqueda, edición o borrado debe comprobar que el usuario pertenece al tenant autenticado.
## Alcance por evento
Los endpoints de Staff y su formulario aceptan `adminapp.tenant:event`. Un admin
de evento lista, edita, elimina y consulta el historial solo de scanners de su
evento. El backend asigna el evento al crear un scanner y no acepta cambios de
asignación desde el formulario. Las categorías autorizables se limitan a las
usadas por productos del evento. Los scanners aplican además su evento en
lectura de tickets, escaneo e historial. Los intentos registran `event_id` para
conservar el aislamiento aunque cambie la asignación del scanner.

View File

@@ -4,7 +4,7 @@ use App\Domains\Core\Staff\Controllers\AdminAppStaffController;
use Illuminate\Support\Facades\Route;
Route::prefix('v1/adminapp/tenant')
->middleware(['auth:sanctum', 'adminapp.tenant:event'])
->middleware(['auth:sanctum', 'adminapp.tenant'])
->group(function (): void {
Route::get('staff/{staff}/scan-attempts', [AdminAppStaffController::class, 'scanAttempts']);
Route::apiResource('staff', AdminAppStaffController::class)->except('show');

View File

@@ -2,6 +2,7 @@
namespace App\Domains\Ticketing\Desfile\Services;
use App\Domains\Commerce\Catalog\Models\Inventory;
use DateTimeInterface;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Hash;
@@ -393,14 +394,22 @@ class InvitationPurchaseProvisioner
$inventory = DB::table('inventories')->where('id', $variant->inventory_id)->lockForUpdate()->first();
if ($inventory === null || $inventory->real_stock < 1 || $inventory->reserved_stock > 0 || ($inventory->entry_reserved_stock ?? 0) > 0) {
$available = $inventory?->available_stock
?? ($inventory === null ? 0 : $inventory->real_stock - $inventory->reserved_stock - ($inventory->entry_reserved_stock ?? 0));
if ($available < 1) {
throw new RuntimeException("El asiento {$variant->descripcion} ya no está disponible.");
}
if (property_exists($inventory, 'available_stock')) {
Inventory::query()->findOrFail($inventory->id)->commitDirectSale(1);
} else {
// This provisioner is also used by historical migrations that run
// before generated availability and the movement ledger exist.
DB::table('inventories')->where('id', $inventory->id)->update([
'real_stock' => $inventory->real_stock - 1,
'sold_units' => $inventory->sold_units + 1,
]);
}
$reservationId = DB::table('compras')->where('id', $purchaseId)->value('stock_reservation_id');
if ($reservationId === null) {

View File

@@ -5,28 +5,28 @@ use App\Domains\Ticketing\Desfile\Controllers\EntryReservationController;
use Illuminate\Support\Facades\Route;
Route::get('v1/adminapp/tenant/desfile/entry-reservations', [EntryReservationController::class, 'index'])
->middleware(['auth:sanctum', 'adminapp.tenant', 'tenant.menu:adminapp.desfile.reservas'])
->middleware(['auth:sanctum', 'adminapp.tenant', 'tenant.menu:onticket.adminapp.desfile.reservas'])
->name('adminapp.desfile.entry-reservations.index');
Route::get('v1/adminapp/tenant/desfile/entry-reservations/pdf', [EntryReservationController::class, 'downloadPdf'])
->middleware(['auth:sanctum', 'adminapp.tenant', 'tenant.menu:adminapp.desfile.reservas'])
->middleware(['auth:sanctum', 'adminapp.tenant', 'tenant.menu:onticket.adminapp.desfile.reservas'])
->name('adminapp.desfile.entry-reservations.pdf');
Route::get('v1/adminapp/tenant/desfile/entry-reservations/excel', [EntryReservationController::class, 'downloadExcel'])
->middleware(['auth:sanctum', 'adminapp.tenant', 'tenant.menu:adminapp.desfile.reservas'])
->middleware(['auth:sanctum', 'adminapp.tenant', 'tenant.menu:onticket.adminapp.desfile.reservas'])
->name('adminapp.desfile.entry-reservations.excel');
Route::get('v1/adminapp/tenant/desfile/entry-reservations/{reservation}/ticket/pdf', [EntryReservationController::class, 'downloadTicketPdf'])
->whereNumber('reservation')
->middleware(['auth:sanctum', 'adminapp.tenant', 'tenant.menu:adminapp.desfile.reservas'])
->middleware(['auth:sanctum', 'adminapp.tenant', 'tenant.menu:onticket.adminapp.desfile.reservas'])
->name('adminapp.desfile.entry-reservations.ticket.pdf');
Route::post('v1/adminapp/tenant/desfile/entry-reservations', [EntryReservationController::class, 'store'])
->middleware(['auth:sanctum', 'adminapp.tenant', 'tenant.menu:adminapp.desfile.reservas'])
->middleware(['auth:sanctum', 'adminapp.tenant', 'tenant.menu:onticket.adminapp.desfile.reservas'])
->name('adminapp.desfile.entry-reservations.store');
Route::delete('v1/adminapp/tenant/desfile/entry-reservations/{reservation}', [EntryReservationController::class, 'destroy'])
->whereNumber('reservation')
->middleware(['auth:sanctum', 'adminapp.tenant', 'tenant.menu:adminapp.desfile.reservas'])
->middleware(['auth:sanctum', 'adminapp.tenant', 'tenant.menu:onticket.adminapp.desfile.reservas'])
->name('adminapp.desfile.entry-reservations.destroy');
Route::prefix('v1/adminapp/tenant/desfile')
->middleware(['auth:sanctum', 'adminapp.tenant', 'tenant.menu:adminapp.desfile.entradas'])
->middleware(['auth:sanctum', 'adminapp.tenant', 'tenant.menu:onticket.adminapp.desfile.entradas'])
->group(function (): void {
Route::get('entries', [EntryController::class, 'show'])
->name('adminapp.desfile.entries.show');

View File

@@ -2,7 +2,6 @@
namespace App\Domains\Ticketing\Event\Controllers\AdminApp;
use App\Domains\Core\Auth\Services\EventScopeService;
use App\Domains\Ticketing\Event\Models\EventDate;
use App\Domains\Ticketing\Event\Requests\RescheduleEventDateRequest;
use App\Domains\Ticketing\Event\Requests\StoreEventDateRequest;
@@ -20,8 +19,7 @@ class EventController extends Controller
public function show(Request $request): EventResource
{
return EventResource::make(
$this->eventService->forTenant($request->user()->tenant()->firstOrFail(),
app(EventScopeService::class)->eventId($request->user()))
$this->eventService->forTenant($request->user()->tenant()->firstOrFail())
);
}
@@ -30,8 +28,7 @@ class EventController extends Controller
return EventResource::make(
$this->eventService->updateForTenant(
$request->user()->tenant()->firstOrFail(),
$request->validated(),
app(EventScopeService::class)->eventId($request->user())
$request->validated()
)
);
}
@@ -42,7 +39,6 @@ class EventController extends Controller
$this->eventService->createDateForTenant(
$request->user()->tenant()->firstOrFail(),
$request->validated(),
app(EventScopeService::class)->eventId($request->user()),
)
);
}

View File

@@ -15,27 +15,14 @@ use Illuminate\Database\Eloquent\Relations\BelongsTo;
use Illuminate\Database\Eloquent\Relations\BelongsToMany;
use Illuminate\Database\Eloquent\Relations\HasMany;
#[Fillable(['client_id', 'tenant_code', 'slug', 'event_category_id', 'title', 'subtitle', 'description', 'location', 'exact_location', 'date_text', 'published_at', 'attachment_id', 'allow_ticket_refund', 'allow_ticket_total_refund', 'allow_ticket_partial_refund', 'ticket_partial_refund_percentage'])]
#[Fillable(['client_id', 'tenant_code', 'slug', 'event_category_id', 'title', 'subtitle', 'description', 'location', 'exact_location', 'date_text', 'published_at', 'attachment_id'])]
class Event extends Model
{
use HasFactory;
protected function casts(): array
{
return ['allow_ticket_refund' => 'boolean', 'allow_ticket_total_refund' => 'boolean',
'allow_ticket_partial_refund' => 'boolean', 'ticket_partial_refund_percentage' => 'decimal:2', 'client_id' => 'integer', 'published_at' => 'datetime', 'exact_location' => 'array'];
}
public function allow_refund(): bool
{
return (bool) $this->allow_ticket_refund
&& ((bool) $this->allow_ticket_total_refund || $this->allow_partial_refund());
}
public function allow_partial_refund(): bool
{
return (bool) $this->allow_ticket_refund && (bool) $this->allow_ticket_partial_refund
&& (float) $this->ticket_partial_refund_percentage > 0;
return ['client_id' => 'integer', 'published_at' => 'datetime', 'exact_location' => 'array'];
}
/** @return BelongsTo<Tenant, $this> */

View File

@@ -26,10 +26,10 @@ class EventResource extends JsonResource
'date_text' => $this->date_text,
'published_at' => $this->published_at?->toIso8601String(),
'attachment_id' => $this->attachment_id,
'allow_ticket_refund' => $this->allow_ticket_refund,
'allow_ticket_total_refund' => $this->allow_ticket_total_refund,
'allow_ticket_partial_refund' => $this->allow_ticket_partial_refund,
'ticket_partial_refund_percentage' => $this->ticket_partial_refund_percentage,
'allow_ticket_refund' => $this->tenant->allow_ticket_refund,
'allow_ticket_total_refund' => $this->tenant->allow_ticket_total_refund,
'allow_ticket_partial_refund' => $this->tenant->allow_ticket_partial_refund,
'ticket_partial_refund_percentage' => $this->tenant->ticket_partial_refund_percentage,
'dates' => EventDateResource::collection(
app(EventDateGroupingService::class)->group($this->dates)
),

View File

@@ -2,19 +2,18 @@
namespace App\Domains\Ticketing\Event\Services;
use App\Domains\Core\Auth\Models\User;
use App\Domains\Commerce\Cart\Services\InvalidateEventDateCartsService;
use App\Domains\Commerce\Catalog\Models\Variant;
use App\Domains\Commerce\Catalog\Services\StockReservationService;
use App\Domains\Commerce\Catalog\Services\VariantReplacementService;
use App\Domains\Core\Auth\Models\User;
use App\Domains\Core\Auth\Services\EventScopeService;
use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Ticketing\Event\Enums\EventDateChangeType;
use App\Domains\Ticketing\Event\Events\EventDateRescheduled;
use App\Domains\Ticketing\Event\Events\EventDateSuspended;
use App\Domains\Ticketing\Event\Models\Event;
use App\Domains\Ticketing\Event\Models\EventDate;
use App\Domains\Ticketing\Event\Models\EventDateChange;
use App\Domains\Ticketing\Event\Models\Event;
use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Ticketing\Ticket\Models\Ticket;
use Illuminate\Support\Collection;
use Illuminate\Support\Facades\DB;
@@ -35,22 +34,22 @@ class EventService
private readonly InvalidateEventDateCartsService $invalidateEventDateCarts,
) {}
public function forTenant(Tenant $tenant, ?int $eventId = null): Event
public function forTenant(Tenant $tenant): Event
{
return $this->resolveEvent($tenant, $eventId)->load(['dates.validityTime', 'socialMedia']);
return $tenant->activeEvent->load(['dates.validityTime', 'socialMedia']);
}
/** @param array<string, mixed> $data */
public function updateForTenant(Tenant $tenant, array $data, ?int $eventId = null): Event
public function updateForTenant(Tenant $tenant, array $data): Event
{
return DB::transaction(function () use ($tenant, $data, $eventId): Event {
$event = $this->resolveEvent($tenant, $eventId);
return DB::transaction(function () use ($tenant, $data): Event {
$event = $tenant->activeEvent;
$event->update([
'title' => $data['title'],
'location' => $data['location'],
...array_intersect_key($data, ['attachment_id' => true, 'exact_location' => true]),
]);
$event->update([
$tenant->update([
...array_intersect_key($data, array_flip([
'allow_ticket_refund',
'allow_ticket_total_refund',
@@ -70,10 +69,10 @@ class EventService
}
/** @param array{date: string, start_time: string, end_time: string} $data */
public function createDateForTenant(Tenant $tenant, array $data, ?int $eventId = null): EventDate
public function createDateForTenant(Tenant $tenant, array $data): EventDate
{
return DB::transaction(function () use ($tenant, $data, $eventId): EventDate {
$event = $this->resolveEvent($tenant, $eventId);
return DB::transaction(function () use ($tenant, $data): EventDate {
$event = $tenant->activeEvent;
$attributes = $this->dateAttributes($data);
if ($event->dates()->where($attributes)->exists()) {
@@ -94,7 +93,7 @@ class EventService
?User $createdBy = null,
): EventDate {
return DB::transaction(function () use ($tenant, $eventDate, $data, $createdBy): EventDate {
$source = $this->lockedDateForTenant($tenant, $eventDate, $createdBy);
$source = $this->lockedDateForTenant($tenant, $eventDate);
if ($source->suspended_at !== null) {
throw ValidationException::withMessages([
@@ -173,7 +172,7 @@ class EventService
?User $createdBy = null,
): EventDate {
return DB::transaction(function () use ($tenant, $eventDate, $createdBy): EventDate {
$date = $this->lockedDateForTenant($tenant, $eventDate, $createdBy);
$date = $this->lockedDateForTenant($tenant, $eventDate);
if ($date->rescheduled_to_event_date_id !== null) {
throw ValidationException::withMessages([
@@ -217,18 +216,10 @@ class EventService
});
}
private function resolveEvent(Tenant $tenant, ?int $eventId): Event
{
return Event::query()->where('tenant_code', $tenant->codigo)
->findOrFail($eventId ?? $tenant->active_event_id);
}
private function lockedDateForTenant(Tenant $tenant, EventDate $eventDate, ?User $actor = null): EventDate
private function lockedDateForTenant(Tenant $tenant, EventDate $eventDate): EventDate
{
return $tenant->eventDates()
->whereKey($eventDate->getKey())
->when($actor !== null && ! $actor->isTenantAdministrator(),
fn ($query) => $query->where('event_id', app(EventScopeService::class)->eventId($actor)))
->lockForUpdate()
->firstOrFail();
}

View File

@@ -37,10 +37,10 @@ se guardan en el evento. Sin evento activo se conservan las redes propias del te
## API
Los endpoints de AdminApp usan `auth:sanctum` y `adminapp.tenant:event`:
Los endpoints de AdminApp usan `auth:sanctum` y `adminapp.tenant`:
- `GET/PUT /v1/adminapp/tenant/event`: acceso al evento asociado al usuario con scope de evento;
para admins de tenant se conserva el evento activo.
- `GET/PUT /v1/adminapp/tenant/event`: acceso al evento seleccionado para el
storefront de evento único.
- `POST /v1/adminapp/tenant/event-dates`: crea una fecha para ese evento.
- `POST /v1/adminapp/tenant/event-dates/{eventDate}/reschedule` y
`POST /v1/adminapp/tenant/event-dates/{eventDate}/suspend`: cambios de fecha.
@@ -53,8 +53,3 @@ una lista de eventos ni existe todavía una pantalla para gestionarlos.
Las fechas se vinculan con variantes de `Catalog`, que a su vez pueden generar
tickets. Los avisos por suspensión y reprogramación se construyen dinámicamente
después de excluir los cambios que el usuario ya vio tres veces.
La configuración de devoluciones se persiste en `events`, se entrega en
`EventResource` y se aplica al evento de cada ticket. La migración inicial copia
los valores anteriores del tenant a sus eventos. Las fechas se autorizan por
tenant y por evento antes de cualquier suspensión o reprogramación.

View File

@@ -4,7 +4,7 @@ use App\Domains\Ticketing\Event\Controllers\AdminApp\EventController;
use Illuminate\Support\Facades\Route;
Route::prefix('v1/adminapp/tenant')
->middleware(['auth:sanctum', 'adminapp.tenant:event'])
->middleware(['auth:sanctum', 'adminapp.tenant'])
->group(function (): void {
Route::get('event', [EventController::class, 'show']);
Route::put('event', [EventController::class, 'update']);

View File

@@ -28,6 +28,7 @@ class AccommodationController extends Controller
$this->accommodationService->upsertMany(
$tenant,
$request->validated('variants'),
$request->validated('stock_adjustment_id'),
)
);
}

View File

@@ -29,6 +29,7 @@ class EntryController extends Controller
$entries = $this->entryService->upsertMany(
$tenant,
$request->validated('entries'),
$request->validated('stock_adjustment_id'),
);
return EntryResource::collection($entries)

View File

@@ -29,6 +29,7 @@ class FoodController extends Controller
$this->foodService->upsertMany(
$tenant,
$request->validated('variants'),
$request->validated('stock_adjustment_id'),
)
);
}
@@ -39,6 +40,7 @@ class FoodController extends Controller
$this->foodService->updateHistoricalStock(
$request->user()->tenant()->firstOrFail(),
$request->validated('variants'),
$request->validated('stock_adjustment_id'),
)
);
}

View File

@@ -28,6 +28,7 @@ class MerchandiseController extends Controller
$items = $this->merchandiseService->upsertMany(
$tenant,
$request->validated('items'),
$request->validated('stock_adjustment_id'),
);
return MerchandiseResource::collection($items)

View File

@@ -16,9 +16,10 @@ class UpdateHistoricalFoodStockRequest extends FormRequest
{
return [
'variants' => ['required', 'array', 'min:1', 'max:500'],
'variants.*' => ['required', 'array:id,stock'],
'stock_adjustment_id' => ['nullable', 'uuid'],
'variants.*' => ['required', 'array:id,stock_difference'],
'variants.*.id' => ['required', 'integer', 'distinct'],
'variants.*.stock' => ['required', 'integer', 'min:0'],
'variants.*.stock_difference' => ['required', 'integer'],
];
}
}

View File

@@ -3,6 +3,7 @@
namespace App\Domains\Ticketing\FiestaFutbolInfantil\Requests;
use Illuminate\Foundation\Http\FormRequest;
use Illuminate\Validation\Validator;
class UpsertAccommodationVariantsRequest extends FormRequest
{
@@ -16,12 +17,42 @@ class UpsertAccommodationVariantsRequest extends FormRequest
{
return [
'variants' => ['required', 'array', 'min:1', 'max:500'],
'variants.*' => ['required', 'array:id,title,description,stock,price'],
'stock_adjustment_id' => ['nullable', 'uuid'],
'variants.*' => ['required', 'array:id,title,description,stock,stock_difference,price'],
'variants.*.id' => ['sometimes', 'nullable', 'integer', 'distinct'],
'variants.*.title' => ['required', 'string', 'max:255'],
'variants.*.description' => ['sometimes', 'nullable', 'string'],
'variants.*.stock' => ['required', 'integer', 'min:0'],
'variants.*.stock' => ['sometimes', 'integer', 'min:0'],
'variants.*.stock_difference' => ['sometimes', 'integer'],
'variants.*.price' => ['required', 'numeric', 'min:0', 'max:99999999.99'],
];
}
/** @return array<int, callable> */
public function after(): array
{
return [
function (Validator $validator): void {
foreach ($this->input('variants', []) as $index => $variant) {
if (! is_array($variant)) {
continue;
}
if (isset($variant['id']) && ! array_key_exists('stock_difference', $variant)) {
$validator->errors()->add(
"variants.{$index}.stock_difference",
'La diferencia de stock es obligatoria al actualizar una variante.',
);
}
if (! isset($variant['id']) && ! array_key_exists('stock', $variant)) {
$validator->errors()->add(
"variants.{$index}.stock",
'El stock inicial es obligatorio al crear una variante.',
);
}
}
},
];
}
}

View File

@@ -20,7 +20,8 @@ class UpsertEntriesRequest extends FormRequest
return [
'entries' => ['required', 'array', 'min:1', 'max:100'],
'entries.*' => ['required', 'array:id,title,description,event_date_ids,stock,price'],
'stock_adjustment_id' => ['nullable', 'uuid'],
'entries.*' => ['required', 'array:id,title,description,event_date_ids,stock,stock_difference,price'],
'entries.*.id' => [
'sometimes',
'nullable',
@@ -46,7 +47,8 @@ class UpsertEntriesRequest extends FormRequest
fn ($query) => $query->where('tenant_code', $tenantCode)
),
],
'entries.*.stock' => ['required', 'integer', 'min:0'],
'entries.*.stock' => ['sometimes', 'integer', 'min:0'],
'entries.*.stock_difference' => ['sometimes', 'integer'],
'entries.*.price' => ['required', 'numeric', 'min:0', 'max:99999999.99'],
];
}
@@ -61,6 +63,20 @@ class UpsertEntriesRequest extends FormRequest
continue;
}
if (isset($entry['id']) && ! array_key_exists('stock_difference', $entry)) {
$validator->errors()->add(
"entries.{$index}.stock_difference",
'La diferencia de stock es obligatoria al actualizar una entrada.',
);
}
if (! isset($entry['id']) && ! array_key_exists('stock', $entry)) {
$validator->errors()->add(
"entries.{$index}.stock",
'El stock inicial es obligatorio al crear una entrada.',
);
}
$dateIds = $entry['event_date_ids'] ?? [];
if (! is_array($dateIds)) {

View File

@@ -20,7 +20,8 @@ class UpsertFoodVariantsRequest extends FormRequest
return [
'variants' => ['required', 'array', 'min:1', 'max:500'],
'variants.*' => ['required', 'array:id,event_date_id,schedule,service,description,stock,price'],
'stock_adjustment_id' => ['nullable', 'uuid'],
'variants.*' => ['required', 'array:id,event_date_id,schedule,service,description,stock,stock_difference,price'],
'variants.*.id' => ['sometimes', 'nullable', 'integer', 'distinct'],
'variants.*.event_date_id' => [
'required',
@@ -32,7 +33,8 @@ class UpsertFoodVariantsRequest extends FormRequest
'variants.*.schedule' => ['required', 'string', 'max:255'],
'variants.*.service' => ['required', 'string', 'max:255'],
'variants.*.description' => ['sometimes', 'nullable', 'string'],
'variants.*.stock' => ['required', 'integer', 'min:0'],
'variants.*.stock' => ['sometimes', 'integer', 'min:0'],
'variants.*.stock_difference' => ['sometimes', 'integer'],
'variants.*.price' => ['required', 'numeric', 'min:0', 'max:99999999.99'],
];
}
@@ -49,6 +51,20 @@ class UpsertFoodVariantsRequest extends FormRequest
continue;
}
if (isset($variant['id']) && ! array_key_exists('stock_difference', $variant)) {
$validator->errors()->add(
"variants.{$index}.stock_difference",
'La diferencia de stock es obligatoria al actualizar una variante.',
);
}
if (! isset($variant['id']) && ! array_key_exists('stock', $variant)) {
$validator->errors()->add(
"variants.{$index}.stock",
'El stock inicial es obligatorio al crear una variante.',
);
}
$key = implode('|', [
$variant['event_date_id'] ?? '',
mb_strtolower(trim((string) ($variant['schedule'] ?? ''))),

View File

@@ -4,6 +4,7 @@ namespace App\Domains\Ticketing\FiestaFutbolInfantil\Requests;
use Illuminate\Foundation\Http\FormRequest;
use Illuminate\Validation\Rule;
use Illuminate\Validation\Validator;
class UpsertMerchandiseRequest extends FormRequest
{
@@ -39,12 +40,49 @@ class UpsertMerchandiseRequest extends FormRequest
'items.*.description' => ['sometimes', 'nullable', 'string'],
'items.*.max_units_per_user' => ['required', 'integer', 'min:1'],
'items.*.variants' => ['required', 'array', 'min:1', 'max:500'],
'items.*.variants.*' => ['required', 'array:id,color,size,stock,price'],
'stock_adjustment_id' => ['nullable', 'uuid'],
'items.*.variants.*' => ['required', 'array:id,color,size,stock,stock_difference,price'],
'items.*.variants.*.id' => ['sometimes', 'nullable', 'integer', 'distinct'],
'items.*.variants.*.color' => ['required', 'string', 'max:255'],
'items.*.variants.*.size' => ['required', 'string', 'max:255'],
'items.*.variants.*.stock' => ['required', 'integer', 'min:0'],
'items.*.variants.*.stock' => ['sometimes', 'integer', 'min:0'],
'items.*.variants.*.stock_difference' => ['sometimes', 'integer'],
'items.*.variants.*.price' => ['required', 'numeric', 'min:0', 'max:99999999.99'],
];
}
/** @return array<int, callable> */
public function after(): array
{
return [
function (Validator $validator): void {
foreach ($this->input('items', []) as $itemIndex => $item) {
if (! is_array($item)) {
continue;
}
foreach ($item['variants'] ?? [] as $variantIndex => $variant) {
if (! is_array($variant)) {
continue;
}
$prefix = "items.{$itemIndex}.variants.{$variantIndex}";
if (isset($variant['id']) && ! array_key_exists('stock_difference', $variant)) {
$validator->errors()->add(
"{$prefix}.stock_difference",
'La diferencia de stock es obligatoria al actualizar una variante.',
);
}
if (! isset($variant['id']) && ! array_key_exists('stock', $variant)) {
$validator->errors()->add(
"{$prefix}.stock",
'El stock inicial es obligatorio al crear una variante.',
);
}
}
}
},
];
}
}

View File

@@ -37,7 +37,7 @@ class AccommodationResource extends JsonResource
'title' => $options->get($value)?->label ?? $value,
'value' => $value,
'description' => $variant->descripcion,
'stock' => $variant->inventory->real_stock,
'stock' => $variant->inventory->availableStock(),
'price' => number_format($variant->getPrice(), 2, '.', ''),
];
})->values(),

View File

@@ -33,7 +33,7 @@ class EntryResource extends JsonResource
'title' => $this->nombre,
'description' => $this->descripcion,
'event_date_ids' => $variant->selectedEventDates()->pluck('id')->values(),
'stock' => $variant->inventory->real_stock,
'stock' => $variant->inventory->availableStock(),
'price' => $this->precio,
];
}

View File

@@ -81,7 +81,7 @@ class FoodResource extends JsonResource
'schedule' => $values->get('horario'),
'service' => $values->get('servicio'),
'description' => $variant->descripcion,
'stock' => $variant->inventory->real_stock,
'stock' => $variant->inventory->availableStock(),
'price' => number_format($variant->getPrice(), 2, '.', ''),
];
}

View File

@@ -44,7 +44,7 @@ class MerchandiseResource extends JsonResource
'color_value' => $colorValue,
'size' => $sizeOptions->get($sizeValue)?->label ?? $sizeValue,
'size_value' => $sizeValue,
'stock' => $variant->inventory->real_stock,
'stock' => $variant->inventory->availableStock(),
'price' => number_format($variant->getPrice(), 2, '.', ''),
];
})->values(),

View File

@@ -39,9 +39,9 @@ class AccommodationService
/**
* @param array<int, array<string, mixed>> $variants
*/
public function upsertMany(Tenant $tenant, array $variants): CatalogItem
public function upsertMany(Tenant $tenant, array $variants, ?string $stockAdjustmentId = null): CatalogItem
{
return DB::transaction(function () use ($tenant, $variants): CatalogItem {
return DB::transaction(function () use ($tenant, $variants, $stockAdjustmentId): CatalogItem {
$attribute = $this->attribute($tenant);
$accommodation = $this->accommodation($tenant, $variants);
$itemAttribute = $accommodation->itemAttributes()->firstOrCreate(
@@ -70,7 +70,7 @@ class AccommodationService
if ($variant === null) {
$this->createVariant($attribute, $accommodation, $itemAttribute, $data);
} else {
$this->updateVariant($attribute, $variant, $itemAttribute, $data, $index);
$this->updateVariant($attribute, $variant, $itemAttribute, $data, $index, $stockAdjustmentId);
}
}
@@ -169,7 +169,7 @@ class AccommodationService
'title' => trim($variant['title']),
'value' => $this->valueCode($variant['title']),
'description' => $variant['description'] ?? null,
'stock' => (int) $variant['stock'],
...(array_key_exists('stock', $variant) ? ['stock' => (int) $variant['stock']] : []),
])->all();
}
@@ -212,6 +212,7 @@ class AccommodationService
$this->createOption($attribute, $data['value'], $data['title']);
$inventory = Inventory::query()->create(['real_stock' => $data['stock']]);
$inventory->recordInitialization();
$variant = $accommodation->variants()->create([
'inventory_id' => $inventory->id,
'descripcion' => $data['description'],
@@ -230,20 +231,13 @@ class AccommodationService
ItemAttribute $itemAttribute,
array $data,
int $index,
?string $stockAdjustmentId,
): void {
$inventory = Inventory::query()
->whereKey($variant->inventory_id)
->lockForUpdate()
->firstOrFail();
if ($data['stock'] < $inventory->reserved_stock) {
throw ValidationException::withMessages([
"variants.{$index}.stock" => [
'El stock no puede ser menor que la cantidad actualmente reservada.',
],
]);
}
$definition = $variant->definitions
->firstWhere('item_attribute_id', $itemAttribute->id);
$option = $definition === null
@@ -263,7 +257,10 @@ class AccommodationService
'descripcion' => $data['description'],
'precio' => $data['price'],
]);
$inventory->update(['real_stock' => $data['stock']]);
$inventory->adjustAvailableStock(
(int) $data['stock_difference'],
idempotencyKey: $stockAdjustmentId,
);
$variant->definitions()->updateOrCreate(
['item_attribute_id' => $itemAttribute->id],
['value' => $data['value']],

View File

@@ -43,18 +43,18 @@ class EntryService
* @param array<int, array<string, mixed>> $entries
* @return Collection<int, CatalogItem>
*/
public function upsertMany(Tenant $tenant, array $entries): Collection
public function upsertMany(Tenant $tenant, array $entries, ?string $stockAdjustmentId = null): Collection
{
return DB::transaction(function () use ($tenant, $entries): Collection {
return DB::transaction(function () use ($tenant, $entries, $stockAdjustmentId): Collection {
$reservedSlugs = [];
$category = Category::query()->firstOrCreate([
'tenant_code' => $tenant->codigo,
'nombre' => 'Entradas',
]);
return collect($entries)->map(function (array $entry, int $index) use ($tenant, $category, &$reservedSlugs): CatalogItem {
return collect($entries)->map(function (array $entry, int $index) use ($tenant, $category, $stockAdjustmentId, &$reservedSlugs): CatalogItem {
if (isset($entry['id'])) {
return $this->update($tenant, $category, $entry, $index);
return $this->update($tenant, $category, $entry, $index, $stockAdjustmentId);
}
$slug = $this->uniqueSlug($tenant, $entry['title'], $reservedSlugs);
@@ -92,7 +92,7 @@ class EntryService
}
/** @param array<string, mixed> $entry */
private function update(Tenant $tenant, Category $category, array $entry, int $index): CatalogItem
private function update(Tenant $tenant, Category $category, array $entry, int $index, ?string $stockAdjustmentId): CatalogItem
{
$catalogItem = CatalogItem::query()
->whereKey($entry['id'])
@@ -121,14 +121,6 @@ class EntryService
->lockForUpdate()
->firstOrFail();
if ((int) $entry['stock'] < $inventory->reserved_stock) {
throw ValidationException::withMessages([
"entries.{$index}.stock" => [
'El stock no puede ser menor que la cantidad actualmente reservada.',
],
]);
}
$eventDateIds = collect($entry['event_date_ids'])
->map(fn ($id): int => (int) $id)
->unique()
@@ -149,7 +141,10 @@ class EntryService
$catalogItem->itemAttributes()
->whereHas('attribute', fn ($query) => $query->where('codigo', 'event_date'))
->update(['allow_multi_select' => true]);
$inventory->update(['real_stock' => $entry['stock']]);
$inventory->adjustAvailableStock(
(int) $entry['stock_difference'],
idempotencyKey: $stockAdjustmentId,
);
return $catalogItem->load([
'variants.inventory',

View File

@@ -11,9 +11,9 @@ use App\Domains\Commerce\Catalog\Models\Inventory;
use App\Domains\Commerce\Catalog\Models\ItemAttribute;
use App\Domains\Commerce\Catalog\Models\Variant;
use App\Domains\Commerce\Catalog\Services\CatalogService;
use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Ticketing\Event\Enums\EventDateStatus;
use App\Domains\Ticketing\Event\Models\EventDate;
use App\Domains\Core\Tenant\Models\Tenant;
use Illuminate\Support\Collection;
use Illuminate\Support\Facades\DB;
use Illuminate\Validation\ValidationException;
@@ -50,9 +50,9 @@ class FoodService
/**
* @param array<int, array<string, mixed>> $variants
*/
public function upsertMany(Tenant $tenant, array $variants): CatalogItem
public function upsertMany(Tenant $tenant, array $variants, ?string $stockAdjustmentId = null): CatalogItem
{
return DB::transaction(function () use ($tenant, $variants): CatalogItem {
return DB::transaction(function () use ($tenant, $variants, $stockAdjustmentId): CatalogItem {
$attributes = $this->attributes($tenant);
$food = $this->food($tenant, $variants);
$itemAttributes = $this->itemAttributes($food, $attributes);
@@ -85,7 +85,7 @@ class FoodService
if ($variant === null) {
$this->createVariant($food, $itemAttributes, $data);
} else {
$this->updateVariant($variant, $itemAttributes, $data, $index);
$this->updateVariant($variant, $itemAttributes, $data, $index, $stockAdjustmentId);
}
}
@@ -113,11 +113,11 @@ class FoodService
}
/**
* @param array<int, array{id: int, stock: int}> $variants
* @param array<int, array{id: int, stock_difference: int}> $variants
*/
public function updateHistoricalStock(Tenant $tenant, array $variants): CatalogItem
public function updateHistoricalStock(Tenant $tenant, array $variants, ?string $stockAdjustmentId = null): CatalogItem
{
return DB::transaction(function () use ($tenant, $variants): CatalogItem {
return DB::transaction(function () use ($tenant, $variants, $stockAdjustmentId): CatalogItem {
$food = CatalogItem::query()
->forTenantCatalog($tenant)
->where('slug', 'comida')
@@ -142,17 +142,11 @@ class FoodService
]);
}
$stock = (int) $data['stock'];
$inventory = $this->inventoryForHistoricalStockUpdate($variant);
if ($stock < $inventory->reserved_stock) {
throw ValidationException::withMessages([
"variants.{$index}.stock" => [
'El stock no puede ser menor que la cantidad actualmente reservada.',
],
]);
}
$inventory->update(['real_stock' => $stock]);
$inventory->adjustAvailableStock(
(int) $data['stock_difference'],
idempotencyKey: $stockAdjustmentId,
);
}
return $this->current($tenant) ?? $food;
@@ -181,6 +175,7 @@ class FoodService
'reserved_stock' => 0,
'real_stock' => $inventory->real_stock,
]);
$historicalInventory->recordTransferInitialization();
$variant->update(['inventory_id' => $historicalInventory->getKey()]);
return $historicalInventory;
@@ -301,7 +296,7 @@ class FoodService
'schedule' => $schedule->value,
'service' => $service->value,
'description' => (string) ($variant['description'] ?? ''),
'stock' => (int) $variant['stock'],
...(array_key_exists('stock', $variant) ? ['stock' => (int) $variant['stock']] : []),
];
})->all();
}
@@ -384,6 +379,7 @@ class FoodService
private function createVariant(CatalogItem $food, Collection $itemAttributes, array $data): void
{
$inventory = Inventory::query()->create(['real_stock' => $data['stock']]);
$inventory->recordInitialization();
$variant = $food->variants()->create([
'event_date_id' => $data['event_date_id'],
'inventory_id' => $inventory->id,
@@ -400,27 +396,23 @@ class FoodService
Collection $itemAttributes,
array $data,
int $index,
?string $stockAdjustmentId,
): void {
$inventory = Inventory::query()
->whereKey($variant->inventory_id)
->lockForUpdate()
->firstOrFail();
if ($data['stock'] < $inventory->reserved_stock) {
throw ValidationException::withMessages([
"variants.{$index}.stock" => [
'El stock no puede ser menor que la cantidad actualmente reservada.',
],
]);
}
$variant->update([
'event_date_id' => $data['event_date_id'],
'descripcion' => $data['description'],
'precio' => $data['price'],
]);
$variant->eventDates()->sync([$data['event_date_id']]);
$inventory->update(['real_stock' => $data['stock']]);
$inventory->adjustAvailableStock(
(int) $data['stock_difference'],
idempotencyKey: $stockAdjustmentId,
);
$this->syncDefinitions($variant, $itemAttributes, $data);
}

View File

@@ -43,9 +43,9 @@ class MerchandiseService
* @param array<int, array<string, mixed>> $items
* @return Collection<int, CatalogItem>
*/
public function upsertMany(Tenant $tenant, array $items): Collection
public function upsertMany(Tenant $tenant, array $items, ?string $stockAdjustmentId = null): Collection
{
return DB::transaction(function () use ($tenant, $items): Collection {
return DB::transaction(function () use ($tenant, $items, $stockAdjustmentId): Collection {
$attributes = $this->attributes($tenant);
$category = Category::query()->firstOrCreate([
'tenant_code' => $tenant->codigo,
@@ -57,6 +57,7 @@ class MerchandiseService
$tenant,
$attributes,
$category,
$stockAdjustmentId,
&$reservedSlugs,
): CatalogItem {
$item = isset($data['id'])
@@ -101,7 +102,7 @@ class MerchandiseService
if ($variant === null) {
$this->createVariant($item, $itemAttributes, $variantData);
} else {
$this->updateVariant($variant, $itemAttributes, $variantData, $index, $variantIndex);
$this->updateVariant($variant, $itemAttributes, $variantData, $index, $variantIndex, $stockAdjustmentId);
}
}
@@ -244,7 +245,7 @@ class MerchandiseService
...$variant,
'color' => $color->value,
'size' => $size->value,
'stock' => (int) $variant['stock'],
...(array_key_exists('stock', $variant) ? ['stock' => (int) $variant['stock']] : []),
];
})->all();
}
@@ -342,6 +343,7 @@ class MerchandiseService
array $data,
): void {
$inventory = Inventory::query()->create(['real_stock' => $data['stock']]);
$inventory->recordInitialization();
$variant = $item->variants()->create([
'inventory_id' => $inventory->id,
'precio' => $data['price'],
@@ -359,22 +361,18 @@ class MerchandiseService
array $data,
int $itemIndex,
int $variantIndex,
?string $stockAdjustmentId,
): void {
$inventory = Inventory::query()
->whereKey($variant->inventory_id)
->lockForUpdate()
->firstOrFail();
if ($data['stock'] < $inventory->reserved_stock) {
throw ValidationException::withMessages([
"items.{$itemIndex}.variants.{$variantIndex}.stock" => [
'El stock no puede ser menor que la cantidad actualmente reservada.',
],
]);
}
$variant->update(['precio' => $data['price']]);
$inventory->update(['real_stock' => $data['stock']]);
$inventory->adjustAvailableStock(
(int) $data['stock_difference'],
idempotencyKey: $stockAdjustmentId,
);
$this->syncDefinitions($variant, $itemAttributes, $data);
}

View File

@@ -19,48 +19,48 @@ Route::prefix('v1/adminapp/tenant')
->middleware("tenant.menu:{$menuCode}");
};
$visibilityRoutes('entries', 'entries', 'adminapp.fiesta-futbol-infantil.entradas');
$visibilityRoutes('foods', 'foods', 'adminapp.fiesta-futbol-infantil.comida');
$visibilityRoutes('accommodations', 'accommodations', 'adminapp.fiesta-futbol-infantil.alojamientos');
$visibilityRoutes('merchandise', 'merchandise', 'adminapp.fiesta-futbol-infantil.merchandising');
$visibilityRoutes('entries', 'entries', 'onticket.adminapp.fiesta-futbol-infantil.entradas');
$visibilityRoutes('foods', 'foods', 'onticket.adminapp.fiesta-futbol-infantil.comida');
$visibilityRoutes('accommodations', 'accommodations', 'onticket.adminapp.fiesta-futbol-infantil.alojamientos');
$visibilityRoutes('merchandise', 'merchandise', 'onticket.adminapp.fiesta-futbol-infantil.merchandising');
Route::get('entries', [EntryController::class, 'index'])
->middleware('tenant.menu:adminapp.fiesta-futbol-infantil.entradas')
->middleware('tenant.menu:onticket.adminapp.fiesta-futbol-infantil.entradas')
->name('adminapp.fiesta-futbol-infantil.entries.index');
Route::post('entries', [EntryController::class, 'store'])
->middleware('tenant.menu:adminapp.fiesta-futbol-infantil.entradas')
->middleware('tenant.menu:onticket.adminapp.fiesta-futbol-infantil.entradas')
->name('adminapp.fiesta-futbol-infantil.entries.store');
Route::delete('entries/{entry}', [EntryController::class, 'destroy'])
->middleware('tenant.menu:adminapp.fiesta-futbol-infantil.entradas')
->middleware('tenant.menu:onticket.adminapp.fiesta-futbol-infantil.entradas')
->name('adminapp.fiesta-futbol-infantil.entries.destroy');
Route::get('foods', [FoodController::class, 'index'])
->middleware('tenant.menu:adminapp.fiesta-futbol-infantil.comida')
->middleware('tenant.menu:onticket.adminapp.fiesta-futbol-infantil.comida')
->name('adminapp.fiesta-futbol-infantil.foods.index');
Route::post('foods', [FoodController::class, 'store'])
->middleware('tenant.menu:adminapp.fiesta-futbol-infantil.comida')
->middleware('tenant.menu:onticket.adminapp.fiesta-futbol-infantil.comida')
->name('adminapp.fiesta-futbol-infantil.foods.store');
Route::patch('foods/history-stock', [FoodController::class, 'updateHistoricalStock'])
->middleware('tenant.menu:adminapp.fiesta-futbol-infantil.comida')
->middleware('tenant.menu:onticket.adminapp.fiesta-futbol-infantil.comida')
->name('adminapp.fiesta-futbol-infantil.foods.history-stock.update');
Route::delete('foods/{food}', [FoodController::class, 'destroy'])
->middleware('tenant.menu:adminapp.fiesta-futbol-infantil.comida')
->middleware('tenant.menu:onticket.adminapp.fiesta-futbol-infantil.comida')
->name('adminapp.fiesta-futbol-infantil.foods.destroy');
Route::get('accommodations', [AccommodationController::class, 'index'])
->middleware('tenant.menu:adminapp.fiesta-futbol-infantil.alojamientos')
->middleware('tenant.menu:onticket.adminapp.fiesta-futbol-infantil.alojamientos')
->name('adminapp.fiesta-futbol-infantil.accommodations.index');
Route::post('accommodations', [AccommodationController::class, 'store'])
->middleware('tenant.menu:adminapp.fiesta-futbol-infantil.alojamientos')
->middleware('tenant.menu:onticket.adminapp.fiesta-futbol-infantil.alojamientos')
->name('adminapp.fiesta-futbol-infantil.accommodations.store');
Route::delete('accommodations/{accommodation}', [AccommodationController::class, 'destroy'])
->middleware('tenant.menu:adminapp.fiesta-futbol-infantil.alojamientos')
->middleware('tenant.menu:onticket.adminapp.fiesta-futbol-infantil.alojamientos')
->name('adminapp.fiesta-futbol-infantil.accommodations.destroy');
Route::get('merchandise', [MerchandiseController::class, 'index'])
->middleware('tenant.menu:adminapp.fiesta-futbol-infantil.merchandising')
->middleware('tenant.menu:onticket.adminapp.fiesta-futbol-infantil.merchandising')
->name('adminapp.fiesta-futbol-infantil.merchandise.index');
Route::post('merchandise', [MerchandiseController::class, 'store'])
->middleware('tenant.menu:adminapp.fiesta-futbol-infantil.merchandising')
->middleware('tenant.menu:onticket.adminapp.fiesta-futbol-infantil.merchandising')
->name('adminapp.fiesta-futbol-infantil.merchandise.store');
Route::delete('merchandise/{merchandise}', [MerchandiseController::class, 'destroy'])
->middleware('tenant.menu:adminapp.fiesta-futbol-infantil.merchandising')
->middleware('tenant.menu:onticket.adminapp.fiesta-futbol-infantil.merchandising')
->name('adminapp.fiesta-futbol-infantil.merchandise.destroy');
});

View File

@@ -11,7 +11,6 @@ use Illuminate\Database\Eloquent\Relations\BelongsTo;
#[Fillable([
'tenant_code',
'event_id',
'scanner_user_id',
'ticket_id',
'data',
@@ -44,7 +43,6 @@ class ScanAttempt extends Model
{
return [
'scanner_user_id' => 'integer',
'event_id' => 'integer',
'ticket_id' => 'integer',
'result' => ScanAttemptResult::class,
'created_at' => 'datetime',

View File

@@ -148,9 +148,7 @@ class Ticket extends Model
public function allow_refund(): bool
{
return $this->event_id === null
? ($this->tenant?->allow_refund() ?? false)
: ($this->event?->allow_refund() ?? false);
return $this->tenant?->allow_refund() ?? false;
}
public function allowRefund(): bool

View File

@@ -32,7 +32,7 @@ class ScanAttemptResource extends JsonResource
ScanAttemptResult::Processing => 'Error',
ScanAttemptResult::Accepted => 'Verificado',
ScanAttemptResult::InvalidQr => 'QR no pertenece al evento',
ScanAttemptResult::TicketNotFound => 'QR no pertenece al evento',
ScanAttemptResult::TicketNotFound => 'Error',
ScanAttemptResult::CategoryForbidden => 'Error',
ScanAttemptResult::AlreadyScanned => 'Usado',
ScanAttemptResult::Expired => 'Vencido',

View File

@@ -9,7 +9,6 @@ use App\Domains\Commerce\Purchase\Models\PurchaseItem;
use App\Domains\Commerce\Purchase\Services\PurchaseRefundSummaryService;
use App\Domains\Core\Auth\Models\User;
use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Ticketing\Event\Models\Event;
use App\Domains\Ticketing\Ticket\Models\Ticket;
use App\Domains\Ticketing\Ticket\Models\TicketRefund;
use Illuminate\Database\Eloquent\Builder;
@@ -24,7 +23,6 @@ class AdminAppTicketService
...TicketValidityResolver::RELATIONS,
...TicketPresentationResolver::RELATIONS,
'tenant',
'event',
'user',
'scannerUser',
'sourceCatalogItem.category',
@@ -147,20 +145,19 @@ class AdminAppTicketService
]);
}
$configuration = $ticket->event_id === null ? $tenant : $ticket->event;
$unitPrice = (float) $purchaseItem->precio_unitario;
$itemTotal = (float) $purchaseItem->total;
$itemRefundedAmount = $this->refundedAmountForPurchaseItem($purchaseItem);
$remainingItemAmount = max(0.0, round($itemTotal - $itemRefundedAmount, 2));
$total = null;
if ($configuration->allow_refund() && $configuration->allow_ticket_total_refund && $unitPrice <= $remainingItemAmount) {
if ($tenant->allow_refund() && $tenant->allow_ticket_total_refund && $unitPrice <= $remainingItemAmount) {
$total = number_format($unitPrice, 2, '.', '');
}
$partial = null;
if ($configuration->allow_refund() && $configuration->allow_partial_refund()) {
$partialAmount = $this->refundAmount($purchaseItem, $configuration, 'partial');
if ($tenant->allow_refund() && $tenant->allow_partial_refund()) {
$partialAmount = $this->refundAmount($purchaseItem, $tenant, 'partial');
if ($partialAmount <= $remainingItemAmount) {
$partial = number_format($partialAmount, 2, '.', '');
}
@@ -178,15 +175,14 @@ class AdminAppTicketService
string $refundType,
?User $createdBy = null,
): Ticket {
$this->ensureRefundIsAllowed($tenant, $refundType);
return DB::transaction(function () use ($tenant, $ticketId, $refundType, $createdBy): Ticket {
$ticket = Ticket::query()
->where('tenant_code', $tenant->codigo)
->lockForUpdate()
->findOrFail($ticketId);
$configuration = $ticket->event_id === null ? $tenant : $ticket->event;
$this->ensureRefundIsAllowed($configuration, $refundType);
if (! $ticket->can_refund()) {
if ($ticket->status !== Ticket::STATUS_ACTIVE) {
throw ValidationException::withMessages([
@@ -209,7 +205,7 @@ class AdminAppTicketService
]);
}
$refundAmount = $this->refundAmount($purchaseItem, $configuration, $refundType);
$refundAmount = $this->refundAmount($purchaseItem, $tenant, $refundType);
$refundedAmount = round(
$this->refundedAmountForPurchaseItem($purchaseItem) + $refundAmount,
2,
@@ -232,13 +228,13 @@ class AdminAppTicketService
'amount' => number_format($refundAmount, 2, '.', ''),
]);
$this->restoreInventory($ticket, $purchaseItem);
$this->restoreInventory($ticket, $purchaseItem, $createdBy);
return $ticket->refresh()->load(self::RELATIONS);
});
}
private function restoreInventory(Ticket $ticket, PurchaseItem $purchaseItem): void
private function restoreInventory(Ticket $ticket, PurchaseItem $purchaseItem, ?User $createdBy): void
{
$catalogItem = $ticket->sourceCatalogItem;
if ($catalogItem === null) {
@@ -276,11 +272,7 @@ class AdminAppTicketService
throw ValidationException::withMessages(['ticket' => 'No se encontró el inventario del ticket.']);
}
if ($catalogItem->inventory_policy === InventoryPolicy::Tracked) {
$inventory->real_stock++;
}
$inventory->refunded_units++;
$inventory->save();
$inventory->refundStock(1, $createdBy);
}
private function refundedAmountForPurchaseItem(PurchaseItem $purchaseItem): float
@@ -290,7 +282,7 @@ class AdminAppTicketService
->sum('amount'), 2);
}
private function ensureRefundIsAllowed(Tenant|Event $tenant, string $refundType): void
private function ensureRefundIsAllowed(Tenant $tenant, string $refundType): void
{
$isAllowed = match ($refundType) {
TicketRefund::TYPE_PARTIAL => $tenant->allow_refund() && $tenant->allow_partial_refund(),
@@ -304,7 +296,7 @@ class AdminAppTicketService
}
}
private function refundAmount(PurchaseItem $purchaseItem, Tenant|Event $tenant, string $refundType): float
private function refundAmount(PurchaseItem $purchaseItem, Tenant $tenant, string $refundType): float
{
$ticketAmount = (float) $purchaseItem->precio_unitario;

View File

@@ -2,6 +2,7 @@
namespace App\Domains\Ticketing\Ticket\Services;
use App\Domains\Commerce\Catalog\Models\Inventory;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Log;
use RuntimeException;
@@ -64,14 +65,9 @@ class BackfillRefundedUnitsService
}, 'refunds.id', 'id');
foreach ($counts as $inventoryId => $count) {
$updates = ['refunded_units' => DB::raw('refunded_units + '.$count['refunded'])];
if (($count['stock'] ?? 0) > 0) {
$updates['real_stock'] = DB::raw('real_stock + '.$count['stock']);
}
if (DB::table('inventories')->where('id', $inventoryId)->update($updates) !== 1) {
throw new RuntimeException("No se encontró el inventario {$inventoryId} para reponerlo.");
}
$inventory = Inventory::query()->lockForUpdate()->find($inventoryId)
?? throw new RuntimeException("No se encontró el inventario {$inventoryId} para reponerlo.");
$inventory->refundStock($count['refunded']);
}
$refundedUnitsAdded = array_sum(array_column($counts, 'refunded'));
@@ -82,7 +78,8 @@ class BackfillRefundedUnitsService
'bundles_skipped' => $bundlesSkipped,
'inventories_updated' => count($counts),
'refunded_units_added' => $refundedUnitsAdded,
'real_stock_added' => array_sum(array_column($counts, 'stock')),
'real_stock_added' => 0,
'available_stock_added' => $refundedUnitsAdded,
];
});

View File

@@ -3,7 +3,6 @@
namespace App\Domains\Ticketing\Ticket\Services;
use App\Domains\Core\Auth\Models\User;
use App\Domains\Core\Auth\Services\EventScopeService;
use App\Domains\Ticketing\Ticket\Enums\ScanAttemptResult;
use App\Domains\Ticketing\Ticket\Models\ScanAttempt;
use App\Domains\Ticketing\Ticket\Models\Ticket;
@@ -28,7 +27,6 @@ class ScannerTicketService
->with('ticket.sourceCatalogItem.category')
->where('tenant_code', $scanner->tenant_codigo)
->where('scanner_user_id', $scanner->getKey())
->when($this->eventId($scanner) !== null, fn (Builder $query) => $query->where('event_id', $this->eventId($scanner)))
->when($search !== '', function (Builder $query) use ($search): void {
$attemptedAtDate = $this->parseSearchDate($search);
@@ -62,7 +60,6 @@ class ScannerTicketService
->with('ticket.sourceCatalogItem.category')
->where('tenant_code', $scanner->tenant_codigo)
->where('scanner_user_id', $scanner->getKey())
->when($this->eventId($scanner) !== null, fn (Builder $query) => $query->where('event_id', $this->eventId($scanner)))
->when($search !== '', function (Builder $query) use ($search): void {
$attemptedAtDate = $this->parseSearchDate($search);
$attemptedAtDayMonth = $this->parseSearchDayMonth($search);
@@ -109,7 +106,6 @@ class ScannerTicketService
->with('ticket')
->where('tenant_code', $scanner->tenant_codigo)
->where('scanner_user_id', $scanner->getKey())
->when($this->eventId($scanner) !== null, fn (Builder $query) => $query->where('event_id', $this->eventId($scanner)))
->findOrFail($scanAttemptId);
$scanAttempt->ticket?->loadMissing($this->relations());
@@ -117,11 +113,6 @@ class ScannerTicketService
return $scanAttempt;
}
private function eventId(User $scanner): ?int
{
return app(EventScopeService::class)->eventId($scanner);
}
private function parseSearchDate(string $search): ?string
{
if (preg_match('/^(\d{4})-(\d{2})-(\d{2})$/', $search, $matches) === 1) {
@@ -163,8 +154,7 @@ class ScannerTicketService
{
$query = $this->baseQuery()
->where('tenant_code', $scanner->tenant_codigo)
->where('ticket', $ticketUuid)
->when($this->eventId($scanner) !== null, fn (Builder $query) => $query->where('event_id', $this->eventId($scanner)));
->where('ticket', $ticketUuid);
if ($this->requiresCategoryValidation($scanner)) {
$categoryIds = $this->scannerCategoryIds($scanner);
@@ -188,7 +178,6 @@ class ScannerTicketService
$scanAttempt = ScanAttempt::query()->create([
'tenant_code' => $scanner->tenant_codigo,
'scanner_user_id' => $scanner->getKey(),
'event_id' => $this->eventId($scanner),
'data' => $this->serializeScannedData($scannedData),
'result' => ScanAttemptResult::Processing,
]);
@@ -211,7 +200,6 @@ class ScannerTicketService
$ticket = $this->baseQuery()
->where('tenant_code', $scanner->tenant_codigo)
->where('ticket', $scannedData)
->when($this->eventId($scanner) !== null, fn (Builder $query) => $query->where('event_id', $this->eventId($scanner)))
->lockForUpdate()
->firstOrFail();
$ticketId = (int) $ticket->getKey();

View File

@@ -82,7 +82,7 @@ Bajo `/tenants/{tenant:codigo}`, protegidos por `auth:sanctum`:
- `POST /tickets/pdf`.
Bajo `/v1/adminapp/tenant`, protegido por `auth:sanctum`, `adminapp.tenant` y el menú
`adminapp.tickets`:
`onticket.adminapp.tickets`:
- `GET /tickets`, paginado y con búsqueda opcional mediante `q`. La respuesta incluye
`scanned_tickets` y `total_tickets` para el tenant autenticado.

View File

@@ -7,24 +7,24 @@ Route::prefix('v1/adminapp/tenant')
->middleware(['auth:sanctum', 'adminapp.tenant'])
->group(function (): void {
Route::get('tickets', [TicketController::class, 'index'])
->middleware('tenant.menu:adminapp.tickets')
->middleware('tenant.menu:onticket.adminapp.tickets')
->name('adminapp.tickets.index');
Route::post('tickets/{ticket}/cancel', [TicketController::class, 'cancel'])
->whereNumber('ticket')
->middleware('tenant.menu:adminapp.tickets')
->middleware('tenant.menu:onticket.adminapp.tickets')
->name('adminapp.tickets.cancel');
Route::get('tickets/{ticket}/refund', [TicketController::class, 'calculateRefund'])
->whereNumber('ticket')
->middleware('tenant.menu:adminapp.tickets')
->middleware('tenant.menu:onticket.adminapp.tickets')
->name('adminapp.tickets.calculate-refund');
Route::post('tickets/{ticket}/refund', [TicketController::class, 'refund'])
->whereNumber('ticket')
->middleware('tenant.menu:adminapp.tickets')
->middleware('tenant.menu:onticket.adminapp.tickets')
->name('adminapp.tickets.refund');
Route::get('tickets/pdf', [TicketController::class, 'downloadPdf'])
->middleware('tenant.menu:adminapp.tickets')
->middleware('tenant.menu:onticket.adminapp.tickets')
->name('adminapp.tickets.pdf');
Route::get('tickets/excel', [TicketController::class, 'downloadExcel'])
->middleware('tenant.menu:adminapp.tickets')
->middleware('tenant.menu:onticket.adminapp.tickets')
->name('adminapp.tickets.excel');
});

View File

@@ -2,7 +2,6 @@
namespace App\Http\Middleware;
use App\Domains\Core\Auth\Services\AdminAppAccessService;
use App\Domains\Core\Authorization\Enums\RoleCode;
use Closure;
use Illuminate\Auth\Access\AuthorizationException;
@@ -11,12 +10,10 @@ use Symfony\Component\HttpFoundation\Response;
class EnsureAdminAppTenant
{
public function __construct(private readonly AdminAppAccessService $accessService) {}
/**
* Ensure the authenticated user is an AdminApp user bound to a tenant.
*/
public function handle(Request $request, Closure $next, string $access = 'tenant'): Response
public function handle(Request $request, Closure $next): Response
{
$user = $request->user();
@@ -24,9 +21,6 @@ class EnsureAdminAppTenant
! $user
|| $user->rol_codigo !== RoleCode::AdminApp->value
|| ! $user->tenant_codigo
|| ! $this->accessService->hasValidScope($user)
// Only routes implementing event authorization may accept event administrators.
|| (! in_array($access, ['context', 'event'], true) && ! $user->isTenantAdministrator())
) {
throw new AuthorizationException;
}

View File

@@ -2,7 +2,6 @@
namespace App\Http\Middleware;
use App\Domains\Core\Auth\Services\EventScopeService;
use App\Domains\Core\Authorization\Enums\PermissionCode;
use App\Domains\Core\Authorization\Enums\RoleCode;
use Closure;
@@ -28,8 +27,6 @@ class EnsureScannerTenant
throw new AuthorizationException;
}
app(EventScopeService::class)->eventId($user);
return $next($request);
}
}

View File

@@ -2,10 +2,9 @@
namespace App\Shared\Forms\Controllers\AdminApp;
use App\Domains\Core\Auth\Services\EventScopeService;
use App\Http\Controllers\Controller;
use App\Shared\Forms\Resources\EventFormResource;
use App\Shared\Forms\Services\EventFormService;
use App\Http\Controllers\Controller;
use Illuminate\Http\Request;
class EventFormController extends Controller
@@ -16,8 +15,7 @@ class EventFormController extends Controller
{
return EventFormResource::make(
$this->eventFormService->get(
$request->user('sanctum')->tenant()->firstOrFail(),
app(EventScopeService::class)->eventId($request->user())
$request->user('sanctum')->tenant()->firstOrFail()
)
);
}

View File

@@ -2,10 +2,9 @@
namespace App\Shared\Forms\Controllers\AdminApp;
use App\Domains\Core\Auth\Services\EventScopeService;
use App\Http\Controllers\Controller;
use App\Shared\Forms\Resources\StaffFormResource;
use App\Shared\Forms\Services\StaffFormService;
use App\Http\Controllers\Controller;
use Illuminate\Http\Request;
class StaffFormController extends Controller
@@ -16,8 +15,7 @@ class StaffFormController extends Controller
{
return StaffFormResource::make(
$this->staffFormService->get(
$request->user('sanctum')->tenant()->firstOrFail(),
app(EventScopeService::class)->eventId($request->user())
$request->user('sanctum')->tenant()->firstOrFail()
)
);
}

View File

@@ -4,17 +4,14 @@ namespace App\Shared\Forms\Services;
use App\Domains\Core\Tenant\Models\SocialMedia;
use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Ticketing\Event\Models\Event;
use Illuminate\Database\Eloquent\Collection;
class EventFormService
{
/** @return array{social_media: Collection<int, SocialMedia>} */
public function get(Tenant $tenant, ?int $eventId = null): array
public function get(Tenant $tenant): array
{
$event = $eventId === null ? $tenant->activeEvent
: Event::query()
->where('tenant_code', $tenant->codigo)->findOrFail($eventId);
$event = $tenant->activeEvent;
$urls = $event?->socialMedia()
->pluck('event_social_media.url', 'social_media.code') ?? collect();

View File

@@ -10,7 +10,7 @@ use Illuminate\Database\Eloquent\Collection;
class StaffFormService
{
/** @return array{categories: Collection<int, Category>} */
public function get(Tenant $tenant, ?int $eventId = null): array
public function get(Tenant $tenant): array
{
return [
'categories' => Category::query()
@@ -20,8 +20,6 @@ class StaffFormService
->orWhereHas('catalogItems', fn (Builder $items) => $items
->where('tenant_code', $tenant->codigo));
})
->when($eventId !== null, fn (Builder $query) => $query->whereHas(
'catalogItems', fn (Builder $items) => $items->where('tenant_code', $tenant->codigo)->where('event_id', $eventId)))
->orderBy('nombre')
->get(),
];

View File

@@ -12,33 +12,33 @@ use App\Shared\Forms\Controllers\AdminApp\TicketFormController;
use Illuminate\Support\Facades\Route;
Route::prefix('v1/adminapp/forms')
->middleware(['auth:sanctum', 'adminapp.tenant:event'])
->middleware(['auth:sanctum', 'adminapp.tenant'])
->group(function (): void {
Route::get('event', EventFormController::class);
Route::get(
'desfile/entry-reservation',
DesfileEntryReservationFormController::class
)->middleware('adminapp.tenant')->middleware('tenant.menu:adminapp.desfile.reservas')
)->middleware('tenant.menu:onticket.adminapp.desfile.reservas')
->name('adminapp.forms.desfile.entry-reservation');
Route::get('sale', SaleFormController::class);
Route::get('staff', StaffFormController::class);
Route::get('tickets-filter', TicketFilterFormController::class)->middleware('adminapp.tenant')
->middleware('tenant.menu:adminapp.tickets')
Route::get('tickets-filter', TicketFilterFormController::class)
->middleware('tenant.menu:onticket.adminapp.tickets')
->name('adminapp.forms.tickets-filter');
Route::get(
'fiesta-futbol-infantil/ticket',
TicketFormController::class
)->middleware('adminapp.tenant');
);
Route::get(
'fiesta-futbol-infantil/entry',
EntryFormController::class
)->middleware('adminapp.tenant');
);
Route::get(
'fiesta-futbol-infantil/merchandise',
MerchandiseFormController::class
)->middleware('adminapp.tenant');
);
Route::get(
'fiesta-futbol-infantil/food',
FoodFormController::class
)->middleware('adminapp.tenant');
);
});

View File

@@ -41,7 +41,7 @@ return new class extends Migration
return;
}
$sourcePath = public_path('images/website_types/'.self::FILENAME);
$sourcePath = public_path('images/website_types/onticket/'.self::FILENAME);
if (! is_file($sourcePath)) {
throw new RuntimeException("Favicon not found at path: {$sourcePath}");

View File

@@ -0,0 +1,89 @@
<?php
use Illuminate\Database\Migrations\Migration;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Schema;
return new class extends Migration
{
public $withinTransaction = false;
private const FORMULA = 'CAST(real_stock AS SIGNED) - CAST(sold_units AS SIGNED) - CAST(reserved_stock AS SIGNED) - CAST(entry_reserved_stock AS SIGNED) + CAST(refunded_units AS SIGNED)';
public function up(): void
{
$conversion = 'CAST(real_stock AS SIGNED) + CAST(sold_units AS SIGNED) - CAST(refunded_units AS SIGNED)';
$this->assertNonNegative($conversion, 'la conversión produciría un stock real negativo');
$this->assertNonNegative(
"({$conversion}) - CAST(sold_units AS SIGNED) - CAST(reserved_stock AS SIGNED) - CAST(entry_reserved_stock AS SIGNED) + CAST(refunded_units AS SIGNED)",
'el stock disponible actual es negativo',
);
if (DB::getDriverName() === 'sqlite') {
Schema::table('inventories', function (Blueprint $table): void {
$table->bigInteger('available_stock')->virtualAs(self::FORMULA);
});
DB::table('inventories')->update(['real_stock' => DB::raw($conversion)]);
} else {
Schema::table('inventories', function (Blueprint $table): void {
$table->unsignedBigInteger('real_stock')->default(0)->change();
$table->bigInteger('available_stock')->storedAs(self::FORMULA);
});
DB::table('inventories')->update(['real_stock' => DB::raw($conversion)]);
}
}
public function down(): void
{
$conversion = 'CAST(real_stock AS SIGNED) - CAST(sold_units AS SIGNED) + CAST(refunded_units AS SIGNED)';
$this->assertNonNegative($conversion, 'el rollback produciría un stock real negativo');
if (DB::getDriverName() === 'sqlite') {
DB::table('inventories')->update(['real_stock' => DB::raw($conversion)]);
Schema::table('inventories', fn (Blueprint $table) => $table->dropColumn('available_stock'));
return;
}
DB::table('inventories')->update(['real_stock' => DB::raw($conversion)]);
Schema::table('inventories', fn (Blueprint $table) => $table->dropColumn('available_stock'));
}
private function assertNonNegative(string $expression, string $reason): void
{
$invalidInventories = DB::table('inventories')
->select([
'id',
'real_stock',
'sold_units',
'refunded_units',
'reserved_stock',
'entry_reserved_stock',
])
->selectRaw("({$expression}) as calculated_stock")
->whereRaw("({$expression}) < 0")
->orderBy('id')
->limit(20)
->get();
if ($invalidInventories->isNotEmpty()) {
$details = $invalidInventories
->map(static fn (object $inventory): string => sprintf(
'id=%d [real=%d, vendidas=%d, reintegradas=%d, reservadas=%d, reservas_entradas=%d, resultado=%d]',
$inventory->id,
$inventory->real_stock,
$inventory->sold_units,
$inventory->refunded_units,
$inventory->reserved_stock,
$inventory->entry_reserved_stock,
$inventory->calculated_stock,
))
->implode('; ');
throw new RuntimeException(
"Hay inventarios inconsistentes: {$reason}. Inventarios detectados (máximo 20): {$details}."
);
}
}
};

View File

@@ -0,0 +1,33 @@
<?php
use Illuminate\Database\Migrations\Migration;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\Schema;
return new class extends Migration
{
public function up(): void
{
Schema::create('inventory_movements', function (Blueprint $table): void {
$table->id();
$table->foreignId('inventory_id')->constrained('inventories')->restrictOnDelete();
$table->string('operation', 40);
$table->bigInteger('available_stock_delta');
$table->bigInteger('available_stock_before');
$table->bigInteger('available_stock_after');
$table->json('counter_deltas');
$table->foreignId('responsible_user_id')->nullable()->constrained('users')->restrictOnDelete();
$table->uuid('idempotency_key')->nullable();
$table->timestamps();
$table->unique(['inventory_id', 'idempotency_key']);
$table->index(['inventory_id', 'created_at']);
$table->index(['operation', 'created_at']);
});
}
public function down(): void
{
Schema::dropIfExists('inventory_movements');
}
};

View File

@@ -0,0 +1,47 @@
<?php
use App\Domains\Core\Tenant\Models\AdminWebsiteType;
use App\Domains\Core\Tenant\Services\AdminWebsiteTypeService;
use Illuminate\Database\Migrations\Migration;
use Illuminate\Http\UploadedFile;
use Illuminate\Support\Facades\Storage;
return new class extends Migration
{
public function up(): void
{
if (app()->environment('testing')) {
Storage::fake('s3');
}
if (! AdminWebsiteType::query()->where('codigo', 'shopit')->exists()) {
return;
}
app(AdminWebsiteTypeService::class)->updateOrCreate(
['codigo' => 'shopit'],
[
'primary_color' => '#2FD3AC',
'site_logo' => $this->uploadedImage('shopit_logo.png', 'image/png'),
'footer_logo' => $this->uploadedImage('shopit_footer_logo.png', 'image/png'),
'favicon' => $this->uploadedImage('shopit-favicon.svg', 'image/svg+xml'),
],
);
}
public function down(): void
{
// Brand assets are operational data and are intentionally preserved.
}
private function uploadedImage(string $filename, string $mimeType): UploadedFile
{
$path = public_path("images/website_types/shopit/{$filename}");
if (! is_file($path)) {
throw new RuntimeException("ShopIt image not found at path: {$path}");
}
return new UploadedFile($path, $filename, $mimeType, null, true);
}
};

View File

@@ -0,0 +1,236 @@
<?php
use Illuminate\Database\Migrations\Migration;
use Illuminate\Support\Facades\DB;
return new class extends Migration
{
private const ONTICKET_MENUS = [
'adminapp.event' => ['onticket.adminapp.event', 'Eventos', '/admin/event'],
'adminapp.inicio' => ['onticket.adminapp.inicio', 'Inicio', '/admin/inicio'],
'adminapp.catalog' => ['onticket.adminapp.catalog', 'Catálogo', '/admin/catalog'],
'adminapp.combos' => ['onticket.adminapp.combos', 'Combos', '/admin/combos'],
'adminapp.categories' => ['onticket.adminapp.categories', 'Categorías', '/admin/categories'],
'adminapp.ventas' => ['onticket.adminapp.ventas', 'Ventas', '/admin/ventas'],
'adminapp.staff' => ['onticket.adminapp.staff', 'Usuarios', '/admin/staff'],
'adminapp.tickets' => ['onticket.adminapp.tickets', 'Tickets', '/admin/tickets'],
'adminapp.fiesta-futbol-infantil.entradas' => [
'onticket.adminapp.fiesta-futbol-infantil.entradas',
'Entradas',
'/admin/entradas',
],
'adminapp.fiesta-futbol-infantil.alojamientos' => [
'onticket.adminapp.fiesta-futbol-infantil.alojamientos',
'Alojamientos',
'/admin/alojamientos',
],
'adminapp.fiesta-futbol-infantil.merchandising' => [
'onticket.adminapp.fiesta-futbol-infantil.merchandising',
'Merchandising',
'/admin/merchandising',
],
'adminapp.fiesta-futbol-infantil.comida' => [
'onticket.adminapp.fiesta-futbol-infantil.comida',
'Comida',
'/admin/comidas',
],
'adminapp.desfile.entradas' => [
'onticket.adminapp.desfile.entradas',
'Entradas',
'/admin/desfile/entradas',
],
'adminapp.desfile.reservas' => [
'onticket.adminapp.desfile.reservas',
'Reserva de Tickets',
'/admin/desfile/reservas',
],
];
private const SHOPIT_MENUS = [
'shopit.adminapp.marca' => ['Marca', '/admin/marca'],
'shopit.adminapp.contacto' => ['Contacto', '/admin/contacto'],
'shopit.adminapp.productos' => ['Productos', '/admin/productos'],
'shopit.adminapp.categorias' => ['Categorías', '/admin/categorias'],
'shopit.adminapp.transacciones' => ['Transacciones', '/admin/transacciones'],
'shopit.adminapp.reportes' => ['Reportes', '/admin/reportes'],
'shopit.adminapp.usuarios_roles' => ['Usuarios y roles', '/admin/usuarios-roles'],
];
private const LEGACY_SHOPIT_ADMIN_MENUS = [
'adminapp.event',
'adminapp.inicio',
'adminapp.catalog',
'adminapp.combos',
'adminapp.categories',
'adminapp.ventas',
'adminapp.staff',
];
public function up(): void
{
DB::transaction(function (): void {
if (! DB::table('menues')->where('code', 'main.adminapp')->exists()) {
return;
}
foreach (self::ONTICKET_MENUS as $legacyCode => [$code, $label, $route]) {
$this->replaceMenuCode($legacyCode, $code, $label, $route);
$this->assignMenuToAdminRoles($code);
}
foreach (self::SHOPIT_MENUS as $code => [$label, $route]) {
$this->upsertMenu($code, $label, $route);
$this->assignMenuToAdminRoles($code);
}
$shopItTenantCodes = DB::table('tenants')
->where('admin_website_type_code', 'shopit')
->pluck('codigo');
if ($shopItTenantCodes->isEmpty()) {
return;
}
$adminMenuCodes = DB::table('menues')
->where('parent_menu_code', 'main.adminapp')
->pluck('code');
DB::table('tenants_menues')
->whereIn('tenant_code', $shopItTenantCodes)
->whereIn('menu_code', $adminMenuCodes)
->delete();
foreach ($shopItTenantCodes as $tenantCode) {
$this->assignMenuToTenant($tenantCode, 'main.adminapp');
foreach (array_keys(self::SHOPIT_MENUS) as $menuCode) {
$this->assignMenuToTenant($tenantCode, $menuCode);
}
}
});
}
public function down(): void
{
DB::transaction(function (): void {
if (! DB::table('menues')->where('code', 'main.adminapp')->exists()) {
return;
}
$shopItTenantCodes = DB::table('tenants')
->where('admin_website_type_code', 'shopit')
->pluck('codigo');
DB::table('tenants_menues')
->whereIn('tenant_code', $shopItTenantCodes)
->whereIn('menu_code', array_keys(self::SHOPIT_MENUS))
->delete();
DB::table('roles_menues')
->whereIn('menu_codigo', array_keys(self::SHOPIT_MENUS))
->delete();
DB::table('menues')
->whereIn('code', array_keys(self::SHOPIT_MENUS))
->delete();
foreach (self::ONTICKET_MENUS as $legacyCode => [$code, $label, $route]) {
$this->replaceMenuCode($code, $legacyCode, $label, $route);
}
foreach ($shopItTenantCodes as $tenantCode) {
foreach (self::LEGACY_SHOPIT_ADMIN_MENUS as $menuCode) {
$this->assignMenuToTenant($tenantCode, $menuCode);
}
}
});
}
private function replaceMenuCode(
string $sourceCode,
string $targetCode,
string $label,
string $route,
): void {
$source = DB::table('menues')->where('code', $sourceCode)->first();
$this->upsertMenu($targetCode, $label, $route, $source);
if ($source === null) {
return;
}
DB::table('tenants_menues')
->where('menu_code', $sourceCode)
->get()
->each(function (object $assignment) use ($targetCode): void {
DB::table('tenants_menues')->updateOrInsert(
[
'tenant_code' => $assignment->tenant_code,
'menu_code' => $targetCode,
],
[
'static_content' => $assignment->static_content,
'created_at' => $assignment->created_at ?? now(),
'updated_at' => now(),
],
);
});
DB::table('roles_menues')
->where('menu_codigo', $sourceCode)
->pluck('rol_codigo')
->each(fn (string $roleCode) => DB::table('roles_menues')->updateOrInsert([
'rol_codigo' => $roleCode,
'menu_codigo' => $targetCode,
]));
DB::table('tenants_menues')->where('menu_code', $sourceCode)->delete();
DB::table('roles_menues')->where('menu_codigo', $sourceCode)->delete();
DB::table('menues')->where('code', $sourceCode)->delete();
}
private function upsertMenu(
string $code,
string $label,
string $route,
?object $source = null,
): void {
DB::table('menues')->updateOrInsert(
['code' => $code],
[
'label' => $source->label ?? $label,
'parent_menu_code' => 'main.adminapp',
'content_type' => $source->content_type ?? 'dynamic',
'static_content_schema' => $source->static_content_schema ?? null,
'route' => $source->route ?? $route,
'created_at' => $source->created_at ?? now(),
'updated_at' => now(),
],
);
}
private function assignMenuToAdminRoles(string $menuCode): void
{
DB::table('roles')
->whereIn('codigo', ['admin', 'adminapp'])
->pluck('codigo')
->each(fn (string $roleCode) => DB::table('roles_menues')->updateOrInsert([
'rol_codigo' => $roleCode,
'menu_codigo' => $menuCode,
]));
}
private function assignMenuToTenant(string $tenantCode, string $menuCode): void
{
DB::table('tenants_menues')->updateOrInsert(
[
'tenant_code' => $tenantCode,
'menu_code' => $menuCode,
],
[
'static_content' => null,
'created_at' => now(),
'updated_at' => now(),
],
);
}
};

View File

@@ -1,25 +0,0 @@
<?php
use Illuminate\Database\Migrations\Migration;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\Schema;
return new class extends Migration
{
public function up(): void
{
Schema::table('users', function (Blueprint $table): void {
// Existing administrators keep their tenant-wide access.
$table->string('admin_scope', 20)->default('tenant');
$table->foreignId('event_id')->nullable()->constrained('events')->nullOnDelete();
});
}
public function down(): void
{
Schema::table('users', function (Blueprint $table): void {
$table->dropConstrainedForeignId('event_id');
$table->dropColumn('admin_scope');
});
}
};

View File

@@ -1,44 +0,0 @@
<?php
use Illuminate\Database\Migrations\Migration;
use Illuminate\Support\Facades\DB;
return new class extends Migration
{
public function up(): void
{
DB::transaction(function (): void {
DB::table('tenants')
->join('events', 'events.id', '=', 'tenants.active_event_id')
->whereColumn('events.tenant_code', 'tenants.codigo')
->select('tenants.codigo', 'tenants.active_event_id')
->get()
->each(function (object $tenant): void {
DB::table('users')
->whereIn('rol_codigo', ['adminapp', 'scanner'])
->where('tenant_codigo', $tenant->codigo)
->where('admin_scope', 'tenant')
->whereNull('event_id')
->whereNull('deleted_at')
->update([
'admin_scope' => 'event',
'event_id' => $tenant->active_event_id,
'updated_at' => now(),
]);
});
// Missing or mismatched active events must not leave legacy staff with tenant-wide access.
DB::table('users')
->whereIn('rol_codigo', ['adminapp', 'scanner'])
->where('admin_scope', 'tenant')
->whereNull('event_id')
->whereNull('deleted_at')
->update(['admin_scope' => 'event', 'updated_at' => now()]);
});
}
public function down(): void
{
// Do not broaden permissions or overwrite subsequent assignments on rollback.
}
};

View File

@@ -1,38 +0,0 @@
<?php
use Illuminate\Database\Migrations\Migration;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Schema;
return new class extends Migration
{
public function up(): void
{
Schema::table('events', function (Blueprint $table): void {
$table->boolean('allow_ticket_refund')->default(false);
$table->boolean('allow_ticket_total_refund')->default(false);
$table->boolean('allow_ticket_partial_refund')->default(false);
$table->decimal('ticket_partial_refund_percentage', 5, 2)->default(0);
});
DB::table('tenants')->select([
'codigo', 'allow_ticket_refund', 'allow_ticket_total_refund',
'allow_ticket_partial_refund', 'ticket_partial_refund_percentage',
])->get()->each(function (object $tenant): void {
DB::table('events')->where('tenant_code', $tenant->codigo)->update([
'allow_ticket_refund' => $tenant->allow_ticket_refund,
'allow_ticket_total_refund' => $tenant->allow_ticket_total_refund,
'allow_ticket_partial_refund' => $tenant->allow_ticket_partial_refund,
'ticket_partial_refund_percentage' => $tenant->ticket_partial_refund_percentage ?? 0,
]);
});
}
public function down(): void
{
Schema::table('events', fn (Blueprint $table) => $table->dropColumn([
'allow_ticket_refund', 'allow_ticket_total_refund',
'allow_ticket_partial_refund', 'ticket_partial_refund_percentage',
]));
}
};

View File

@@ -1,22 +0,0 @@
<?php
use Illuminate\Database\Migrations\Migration;
use Illuminate\Support\Facades\DB;
return new class extends Migration
{
public function up(): void
{
DB::transaction(function (): void {
$codes = ['adminapp.combos', 'adminapp.categories'];
DB::table('roles_menues')->whereIn('menu_codigo', $codes)->delete();
DB::table('tenants_menues')->whereIn('menu_code', $codes)->delete();
DB::table('menues')->whereIn('code', $codes)->delete();
});
}
public function down(): void
{
// Deprecated menus must not be restored by rollback.
}
};

View File

@@ -1,28 +0,0 @@
<?php
use Illuminate\Database\Migrations\Migration;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Schema;
return new class extends Migration
{
public function up(): void
{
Schema::table('scan_attempts', function (Blueprint $table): void {
$table->foreignId('event_id')->nullable()->constrained('events')->nullOnDelete();
$table->index(['scanner_user_id', 'event_id']);
});
DB::table('scan_attempts')->update([
'event_id' => DB::raw('(SELECT tickets.event_id FROM tickets WHERE tickets.id = scan_attempts.ticket_id)'),
]);
}
public function down(): void
{
Schema::table('scan_attempts', function (Blueprint $table): void {
$table->dropIndex(['scanner_user_id', 'event_id']);
$table->dropConstrainedForeignId('event_id');
});
}
};

View File

@@ -53,77 +53,131 @@ class MenuSeeder extends Seeder
'route' => '/scanner/detail/:id',
],
[
'code' => 'adminapp.event',
'code' => 'onticket.adminapp.event',
'label' => 'Eventos',
'parent_menu_code' => 'main.adminapp',
'route' => '/admin/event',
],
[
'code' => 'adminapp.inicio',
'code' => 'onticket.adminapp.inicio',
'label' => 'Inicio',
'parent_menu_code' => 'main.adminapp',
'route' => '/admin/inicio',
],
[
'code' => 'adminapp.catalog',
'code' => 'onticket.adminapp.catalog',
'label' => 'Catálogo',
'parent_menu_code' => 'main.adminapp',
'route' => '/admin/catalog',
],
[
'code' => 'adminapp.ventas',
'code' => 'onticket.adminapp.combos',
'label' => 'Combos',
'parent_menu_code' => 'main.adminapp',
'route' => '/admin/combos',
],
[
'code' => 'onticket.adminapp.categories',
'label' => 'Categorías',
'parent_menu_code' => 'main.adminapp',
'route' => '/admin/categories',
],
[
'code' => 'onticket.adminapp.ventas',
'label' => 'Ventas',
'parent_menu_code' => 'main.adminapp',
'route' => '/admin/ventas',
],
[
'code' => 'adminapp.staff',
'code' => 'onticket.adminapp.staff',
'label' => 'Usuarios',
'parent_menu_code' => 'main.adminapp',
'route' => '/admin/staff',
],
[
'code' => 'adminapp.tickets',
'code' => 'onticket.adminapp.tickets',
'label' => 'Tickets',
'parent_menu_code' => 'main.adminapp',
'route' => '/admin/tickets',
],
[
'code' => 'adminapp.fiesta-futbol-infantil.entradas',
'code' => 'onticket.adminapp.fiesta-futbol-infantil.entradas',
'label' => 'Entradas',
'parent_menu_code' => 'main.adminapp',
'route' => '/admin/entradas',
],
[
'code' => 'adminapp.fiesta-futbol-infantil.alojamientos',
'code' => 'onticket.adminapp.fiesta-futbol-infantil.alojamientos',
'label' => 'Alojamientos',
'parent_menu_code' => 'main.adminapp',
'route' => '/admin/alojamientos',
],
[
'code' => 'adminapp.fiesta-futbol-infantil.merchandising',
'code' => 'onticket.adminapp.fiesta-futbol-infantil.merchandising',
'label' => 'Merchandising',
'parent_menu_code' => 'main.adminapp',
'route' => '/admin/merchandising',
],
[
'code' => 'adminapp.fiesta-futbol-infantil.comida',
'code' => 'onticket.adminapp.fiesta-futbol-infantil.comida',
'label' => 'Comida',
'parent_menu_code' => 'main.adminapp',
'route' => '/admin/comidas',
],
[
'code' => 'adminapp.desfile.entradas',
'code' => 'onticket.adminapp.desfile.entradas',
'label' => 'Entradas',
'parent_menu_code' => 'main.adminapp',
'route' => '/admin/desfile/entradas',
],
[
'code' => 'adminapp.desfile.reservas',
'code' => 'onticket.adminapp.desfile.reservas',
'label' => 'Reserva de Tickets',
'parent_menu_code' => 'main.adminapp',
'route' => '/admin/desfile/reservas',
],
[
'code' => 'shopit.adminapp.marca',
'label' => 'Marca',
'parent_menu_code' => 'main.adminapp',
'route' => '/admin/marca',
],
[
'code' => 'shopit.adminapp.contacto',
'label' => 'Contacto',
'parent_menu_code' => 'main.adminapp',
'route' => '/admin/contacto',
],
[
'code' => 'shopit.adminapp.productos',
'label' => 'Productos',
'parent_menu_code' => 'main.adminapp',
'route' => '/admin/productos',
],
[
'code' => 'shopit.adminapp.categorias',
'label' => 'Categorías',
'parent_menu_code' => 'main.adminapp',
'route' => '/admin/categorias',
],
[
'code' => 'shopit.adminapp.transacciones',
'label' => 'Transacciones',
'parent_menu_code' => 'main.adminapp',
'route' => '/admin/transacciones',
],
[
'code' => 'shopit.adminapp.reportes',
'label' => 'Reportes',
'parent_menu_code' => 'main.adminapp',
'route' => '/admin/reportes',
],
[
'code' => 'shopit.adminapp.usuarios_roles',
'label' => 'Usuarios y roles',
'parent_menu_code' => 'main.adminapp',
'route' => '/admin/usuarios-roles',
],
[
'code' => 'account',
'label' => 'Mi cuenta',
@@ -230,8 +284,6 @@ class MenuSeeder extends Seeder
->whereIn('code', [
'admin.event',
'admin.catalog',
'adminapp.combos',
'adminapp.categories',
'admin.combos',
'admin.categories',
'admin.ventas',
@@ -245,6 +297,10 @@ class MenuSeeder extends Seeder
])
->delete();
Menu::query()
->where('code', 'like', 'adminapp.%')
->delete();
$allRoleMenuCodes = Menu::query()->pluck('code');
$adminAppMenuCodes = Menu::query()
->where('code', 'main.adminapp')
@@ -289,24 +345,32 @@ class MenuSeeder extends Seeder
'mutual_smep',
];
$ticketAdminMenuCodes = [
'adminapp.tickets',
'onticket.adminapp.tickets',
];
$fiestaCategoryMenuCodes = [
'adminapp.fiesta-futbol-infantil.entradas',
'adminapp.fiesta-futbol-infantil.alojamientos',
'adminapp.fiesta-futbol-infantil.merchandising',
'adminapp.fiesta-futbol-infantil.comida',
'onticket.adminapp.fiesta-futbol-infantil.entradas',
'onticket.adminapp.fiesta-futbol-infantil.alojamientos',
'onticket.adminapp.fiesta-futbol-infantil.merchandising',
'onticket.adminapp.fiesta-futbol-infantil.comida',
];
$fiestaExcludedAdminMenuCodes = [
'adminapp.inicio',
'adminapp.catalog',
'adminapp.categories',
'adminapp.combos',
'onticket.adminapp.inicio',
'onticket.adminapp.catalog',
'onticket.adminapp.categories',
'onticket.adminapp.combos',
];
$desfileMenuCodes = [
'adminapp.desfile.entradas',
'adminapp.desfile.reservas',
'onticket.adminapp.desfile.entradas',
'onticket.adminapp.desfile.reservas',
];
$shopItAdminMenuCodes = Menu::query()
->where('code', 'like', 'shopit.adminapp.%')
->pluck('code')
->all();
$onTicketAdminMenuCodes = Menu::query()
->where('code', 'like', 'onticket.adminapp.%')
->pluck('code')
->all();
$onTicketMenuCodes = [
'event.index',
'event.category',
@@ -396,6 +460,13 @@ class MenuSeeder extends Seeder
foreach ($tenants as $tenant) {
$menuCodes = $allMenus;
$menuCodes = array_diff(
$menuCodes,
$tenant->admin_website_type_code === 'shopit'
? $onTicketAdminMenuCodes
: $shopItAdminMenuCodes,
);
if ($tenant->codigo === 'sonder') {
// Sonder NO tiene tickets
$menuCodes = array_diff($menuCodes, ['account.tickets']);

View File

@@ -40,7 +40,7 @@ class WebsiteTypeSeeder extends Seeder
public function run(): void
{
$shopIt = $this->websiteTypeService->updateOrCreate(
$this->websiteTypeService->updateOrCreate(
['codigo' => 'shopit'],
[
'nombre' => 'ShopIt',
@@ -48,9 +48,10 @@ class WebsiteTypeSeeder extends Seeder
'scanner_domain' => 'scanner.localhost',
'site_title' => 'ShopIt',
...self::PRESENTATION,
'site_logo' => $this->onTicketLogo(),
'footer_logo' => $this->onTicketFooterLogo(),
'favicon' => $this->onTicketFavicon(),
'primary_color' => '#2FD3AC',
'site_logo' => $this->shopItLogo(),
'footer_logo' => $this->shopItFooterLogo(),
'favicon' => $this->shopItFavicon(),
],
);
@@ -83,7 +84,7 @@ class WebsiteTypeSeeder extends Seeder
...self::PRESENTATION,
'site_logo' => $this->onTicketLogo(),
'footer_logo' => $this->onTicketFooterLogo(),
'favicon' => $shopIt->favicon()->firstOrFail()->key,
'favicon' => $this->onTicketFavicon(),
],
);
@@ -204,7 +205,7 @@ class WebsiteTypeSeeder extends Seeder
private function onTicketLogo(): UploadedFile
{
$path = public_path('images/website_types/onticket_logo.png');
$path = public_path('images/website_types/onticket/onticket_logo.png');
if (! file_exists($path)) {
throw new RuntimeException("OnTicket logo not found at path: {$path}");
@@ -221,7 +222,7 @@ class WebsiteTypeSeeder extends Seeder
private function onTicketFooterLogo(): UploadedFile
{
$path = public_path('images/website_types/onticket_footer_logo.png');
$path = public_path('images/website_types/onticket/onticket_footer_logo.png');
if (! file_exists($path)) {
throw new RuntimeException("OnTicket footer logo not found at path: {$path}");
@@ -238,7 +239,7 @@ class WebsiteTypeSeeder extends Seeder
private function onTicketFavicon(): UploadedFile
{
$path = public_path('images/website_types/onticket_favicon.svg');
$path = public_path('images/website_types/onticket/onticket_favicon.svg');
if (! file_exists($path)) {
throw new RuntimeException("OnTicket favicon not found at path: {$path}");
@@ -252,4 +253,30 @@ class WebsiteTypeSeeder extends Seeder
true,
);
}
private function shopItLogo(): UploadedFile
{
return $this->uploadedImage('shopit', 'shopit_logo.png', 'image/png');
}
private function shopItFooterLogo(): UploadedFile
{
return $this->uploadedImage('shopit', 'shopit_footer_logo.png', 'image/png');
}
private function shopItFavicon(): UploadedFile
{
return $this->uploadedImage('shopit', 'shopit-favicon.svg', 'image/svg+xml');
}
private function uploadedImage(string $websiteType, string $filename, string $mimeType): UploadedFile
{
$path = public_path("images/website_types/{$websiteType}/{$filename}");
if (! file_exists($path)) {
throw new RuntimeException("Website type image not found at path: {$path}");
}
return new UploadedFile($path, $filename, $mimeType, null, true);
}
}

View File

Before

Width:  |  Height:  |  Size: 422 B

After

Width:  |  Height:  |  Size: 422 B

View File

Before

Width:  |  Height:  |  Size: 1.2 KiB

After

Width:  |  Height:  |  Size: 1.2 KiB

View File

Before

Width:  |  Height:  |  Size: 3.0 KiB

After

Width:  |  Height:  |  Size: 3.0 KiB

View File

@@ -0,0 +1,10 @@
<svg width="41" height="41" viewBox="0 0 41 41" fill="none" xmlns="http://www.w3.org/2000/svg" xmlns:se="http://svg-edit.googlecode.com" se:swatches="W3siaWQiOiJCMDBEREFFMy0zMjUwLTRERDgtOEU0RS0zMDYxREJGNUE3QTMiLCJuYW1lIjoiIzVCNUI1QiIsImhleCI6IiM1QjVCNUIifSx7ImlkIjoiRjI4QjU4NTYtNUM2OC00QkY4LTk3MDMtOTk5NDJCOTgzNTVBIiwibmFtZSI6IiMyRkQzQUMiLCJoZXgiOiIjMkZEM0FDIn1d">
<g><se:title>Layer 1</se:title><path d="m16.32,27.13c2.29,0 3.13,-0.37 3.73,-0.76c0.65,-0.42 1.17,-1.06 1.24,-1.97c0.06,-0.76 -0.29,-1.4 -0.81,-1.78c-0.7,-0.5 -2.05,-0.81 -3.21,-1.05c-1.13,-0.24 -2.14,-0.6 -3.03,-1.22c-1.06,-0.73 -1.61,-1.47 -1.96,-2.52c-0.45,-1.32 -0.36,-3.12 -0.11,-4.02c0.43,-1.54 1.35,-2.86 2.59,-3.84001c1.6,-1.26 3.58,-2.01999 6.46,-2.17999c0.3,-0.02 0.71,-0.04 1.21,-0.04c0,0 0.16,0 0.21,0h13.3c-3.68,-4.71 -9.41,-7.75 -15.85,-7.75c-11.1,0 -20.09,9 -20.09,20.09c0,2.47 0.45,4.84 1.27,7.03h15.06l-0.01,0.01z" fill="#2FD3AC" id="svg_7"/><path d="m23.11,12.59c-0.65,0 -1.64,0.03 -1.95,0.07c-1.3,0.17 -2.25,0.55 -2.82,1.31c-0.3199,0.43 -0.48,0.99 -0.29,1.66c0.31,1.07 2.1501,1.44 3.4001,1.7c1.49,0.31 2.5599,0.57 3.5899,1.08c1.06,0.53 2.03,1.41 2.51,2.43c0.46,0.98 0.6001,1.96 0.5201,3.08c-0.11,1.56 -0.4701,2.72 -0.9901,3.69c-0.49,0.91 -1.32,1.87 -2.03,2.44c-0.74,0.59 -1.81,1.38 -3.15,1.83c-1.35,0.45 -3.1399,0.63 -5.2999,0.63h-12.30005c3.68,4.68 9.39005,7.68 15.80005,7.68c11.1,0 20.0899,-9 20.0899,-20.09c0,-2.65 -0.5199,-5.18 -1.4499,-7.5h-15.6201l-0.01,-0.01z" fill="#5B5B5B" id="svg_8"/></g></svg>

After

Width:  |  Height:  |  Size: 1.5 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 1.1 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 2.8 KiB

View File

@@ -1,236 +0,0 @@
<?php
namespace Tests\Feature\Auth;
use App\Domains\Core\Auth\Models\User;
use Illuminate\Database\Migrations\Migration;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Hash;
use Illuminate\Support\Facades\Schema;
use Illuminate\Testing\TestResponse;
use Tests\TestCase;
class AdminAppEventScopeTest extends TestCase
{
private User $user;
protected function setUp(): void
{
parent::setUp();
// Focused pre-migration schema: do not replay unrelated provisioning migrations.
// Tests\TestCase and tests/bootstrap.php enforce SQLite :memory:.
Schema::create('tenants', function (Blueprint $table): void {
$table->id();
$table->string('codigo')->unique();
$table->string('nombre');
$table->string('dominio');
$table->string('search_product_layout')->default('column_with_image');
$table->string('search_group_layout')->default('paginated');
});
Schema::create('events', function (Blueprint $table): void {
$table->id();
$table->string('tenant_code');
$table->string('title');
$table->timestamps();
});
Schema::create('users', function (Blueprint $table): void {
$table->id();
$table->string('nombre_apellido');
$table->string('email');
$table->string('active_email')->virtualAs('CASE WHEN deleted_at IS NULL THEN lower(email) ELSE NULL END');
$table->string('password');
$table->string('rol_codigo')->default('user');
$table->string('tenant_codigo')->nullable();
$table->softDeletes();
$table->timestamps();
$table->unique(['active_email', 'rol_codigo']);
});
Schema::create('menues', function (Blueprint $table): void {
$table->id();
$table->string('code')->unique();
$table->string('label');
$table->string('route');
$table->string('parent_menu_code')->nullable();
$table->string('content_type')->default('dynamic');
});
Schema::create('roles_menues', function (Blueprint $table): void {
$table->string('rol_codigo');
$table->string('menu_codigo');
});
Schema::create('tenants_menues', function (Blueprint $table): void {
$table->string('tenant_code');
$table->string('menu_code');
$table->json('static_content')->nullable();
$table->timestamps();
});
foreach ([
'2026_06_18_130006_create_personal_access_tokens_table.php',
'2026_07_28_000000_create_roles_and_permissions_tables.php',
'2026_07_29_000000_add_login_security_fields_to_users_table.php',
'2026_07_29_000100_create_login_attempts_table.php',
] as $file) {
(require database_path('migrations/'.$file))->up();
}
DB::table('roles')->insert(['codigo' => 'adminapp', 'nombre' => 'AdminApp']);
DB::table('tenants')->insert([
['codigo' => 'onticket', 'nombre' => 'OnTicket', 'dominio' => 'onticket.test'],
['codigo' => 'other', 'nombre' => 'Other', 'dominio' => 'other.test'],
]);
DB::table('events')->insert([
['id' => 1, 'tenant_code' => 'onticket', 'title' => 'Evento A'],
['id' => 2, 'tenant_code' => 'onticket', 'title' => 'Evento B'],
['id' => 3, 'tenant_code' => 'other', 'title' => 'Evento ajeno'],
]);
// An existing administrator must remain general after applying the new migration.
DB::table('users')->insert([
'id' => 1, 'nombre_apellido' => 'Admin', 'email' => 'admin@example.test',
'password' => Hash::make('secret123'), 'rol_codigo' => 'adminapp', 'tenant_codigo' => 'onticket',
]);
$this->scopeMigration()->up();
$this->user = User::query()->findOrFail(1);
DB::table('menues')->insert([
['code' => 'main.adminapp', 'label' => 'Administración', 'route' => '/', 'parent_menu_code' => null],
['code' => 'adminapp.ventas', 'label' => 'Ventas', 'route' => '/admin/ventas', 'parent_menu_code' => 'main.adminapp'],
]);
foreach (['main.adminapp', 'adminapp.ventas'] as $code) {
DB::table('roles_menues')->insert(['rol_codigo' => 'adminapp', 'menu_codigo' => $code]);
DB::table('tenants_menues')->insert(['tenant_code' => 'onticket', 'menu_code' => $code]);
}
}
private function scopeMigration(): Migration
{
return require database_path('migrations/2026_09_30_000000_add_admin_scope_to_users.php');
}
private function login(array $extra = []): TestResponse
{
return $this->postJson('/api/v1/adminapp/login', [
'email' => ' ADMIN@EXAMPLE.TEST ', 'password' => 'secret123', ...$extra,
]);
}
public function test_existing_admin_keeps_general_access_after_migration(): void
{
$this->assertTrue($this->user->isTenantAdministrator());
$token = $this->login()->assertOk()->assertJsonPath('user.admin_scope', 'tenant')
->assertJsonPath('user.event_id', null)->json('token');
$this->withToken($token)->getJson('/api/v1/adminapp/me')->assertOk()
->assertJsonPath('data.event', null)->assertJsonCount(1, 'data.tenant.menues.0.submenues');
}
public function test_event_admin_logs_in_and_restores_only_its_assigned_context(): void
{
$this->user->update(['admin_scope' => 'event', 'event_id' => 1]);
$this->assertSame(1, $this->user->event->id);
// Scope cannot be chosen by the caller during login.
$token = $this->login(['admin_scope' => 'tenant', 'event_id' => 2])->assertOk()
->assertJsonPath('user.admin_scope', 'event')->assertJsonPath('user.event_id', 1)->json('token');
$this->withToken($token)->getJson('/api/v1/adminapp/me')->assertOk()
->assertJsonPath('data.event.id', 1)->assertJsonPath('data.event.title', 'Evento A')
->assertJsonPath('data.tenant.codigo', 'onticket')
->assertJsonCount(1, 'data.tenant.menues.0.submenues');
$this->assertSame(['adminapp'], $this->user->tokens()->sole()->abilities);
}
public function test_event_admins_of_the_same_tenant_receive_the_same_assigned_menus(): void
{
DB::table('menues')->insert([
'code' => 'onticket.adminapp.event',
'label' => 'Eventos',
'route' => '/admin/event',
'parent_menu_code' => 'main.adminapp',
]);
DB::table('roles_menues')->insert([
'rol_codigo' => 'adminapp',
'menu_codigo' => 'onticket.adminapp.event',
]);
DB::table('tenants_menues')->insert([
'tenant_code' => 'onticket',
'menu_code' => 'onticket.adminapp.event',
]);
$this->user->update(['admin_scope' => 'event', 'event_id' => 1]);
$token = $this->login()->assertOk()->json('token');
$firstMenus = $this->withToken($token)->getJson('/api/v1/adminapp/me')
->assertOk()->json('data.tenant.menues');
$this->user->update(['event_id' => 2]);
$secondMenus = $this->withToken($token)->getJson('/api/v1/adminapp/me')
->assertOk()->json('data.tenant.menues');
$this->assertSame($firstMenus, $secondMenus);
$this->assertSame(
['adminapp.ventas', 'onticket.adminapp.event'],
collect($firstMenus[0]['submenues'])->pluck('code')->sort()->values()->all(),
);
}
public function test_invalid_scopes_never_issue_tokens_or_increment_password_failure_counts(): void
{
foreach ([
['admin_scope' => 'event', 'event_id' => null],
['admin_scope' => 'event', 'event_id' => 3],
['admin_scope' => 'tenant', 'event_id' => 1],
['admin_scope' => 'unknown', 'event_id' => null],
['admin_scope' => 'event', 'event_id' => 1, 'tenant_codigo' => null],
] as $attributes) {
$this->user->update($attributes);
$this->login()->assertUnprocessable()->assertJsonValidationErrors('email');
}
$this->assertDatabaseCount('personal_access_tokens', 0);
$this->assertSame(0, $this->user->refresh()->failed_login_attempts);
}
public function test_event_admin_cannot_access_tenant_operations_but_can_logout(): void
{
$this->user->update(['admin_scope' => 'event', 'event_id' => 1]);
$token = $this->login()->assertOk()->json('token');
foreach (['tenant/tickets', 'tenant/administrators', 'tenant/website-extras', 'forms/tickets-filter'] as $path) {
$this->withToken($token)->getJson('/api/v1/adminapp/'.$path)->assertForbidden();
}
$this->withToken($token)->postJson('/api/v1/adminapp/tenant/administrators', [])->assertForbidden();
$this->withToken($token)->postJson('/api/logout')->assertOk();
$this->assertDatabaseCount('personal_access_tokens', 0);
}
public function test_deleting_the_event_invalidates_an_existing_token_without_promoting_the_user(): void
{
$this->user->update(['admin_scope' => 'event', 'event_id' => 1]);
$token = $this->login()->assertOk()->json('token');
DB::table('events')->where('id', 1)->delete();
$this->assertNull($this->user->refresh()->event_id);
$this->assertSame('event', $this->user->admin_scope);
$this->withToken($token)->getJson('/api/v1/adminapp/me')->assertForbidden();
$this->withToken($token)->getJson('/api/v1/adminapp/tenant/administrators')->assertForbidden();
}
public function test_event_reassignment_and_tenant_changes_apply_to_existing_tokens(): void
{
$this->user->update(['admin_scope' => 'event', 'event_id' => 1]);
$token = $this->login()->assertOk()->json('token');
$this->user->update(['event_id' => 2]);
$this->withToken($token)->getJson('/api/v1/adminapp/me')->assertOk()->assertJsonPath('data.event.id', 2);
DB::table('events')->where('id', 2)->update(['tenant_code' => 'other']);
$this->withToken($token)->getJson('/api/v1/adminapp/me')->assertForbidden();
}
public function test_wrong_password_still_counts_as_a_failed_attempt(): void
{
$this->user->update(['admin_scope' => 'event', 'event_id' => 1]);
$this->login(['password' => 'wrong'])->assertUnprocessable()->assertJsonValidationErrors('email');
$this->assertSame(1, $this->user->refresh()->failed_login_attempts);
$this->assertDatabaseCount('personal_access_tokens', 0);
}
public function test_scope_migration_can_be_rolled_back_without_removing_users(): void
{
$this->scopeMigration()->down();
$this->assertFalse(Schema::hasColumn('users', 'admin_scope'));
$this->assertFalse(Schema::hasColumn('users', 'event_id'));
$this->assertDatabaseHas('users', ['id' => 1, 'email' => 'admin@example.test']);
}
}

View File

@@ -1,485 +0,0 @@
<?php
namespace Tests\Feature\Auth;
use App\Domains\Commerce\Purchase\Models\Purchase;
use App\Domains\Commerce\Sale\Services\AdminAppSaleService;
use App\Domains\Core\Auth\Models\User;
use App\Domains\Core\Auth\Services\ResetPasswordAttemptService;
use App\Domains\Ticketing\Ticket\Models\Ticket;
use App\Domains\Ticketing\Ticket\Services\AdminAppTicketService;
use Illuminate\Database\Migrations\Migration;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Hash;
use Illuminate\Support\Facades\Schema;
use Illuminate\Testing\TestResponse;
use Laravel\Sanctum\Sanctum;
use Tests\TestCase;
class EventScopedOperationsTest extends TestCase
{
private User $user;
protected function setUp(): void
{
parent::setUp();
// Focused pre-migration schema: do not replay unrelated provisioning migrations.
// Tests\TestCase and tests/bootstrap.php enforce SQLite :memory:.
Schema::create('tenants', function (Blueprint $table): void {
$table->id();
$table->string('codigo')->unique();
$table->string('nombre');
$table->string('dominio');
$table->string('search_product_layout')->default('column_with_image');
$table->string('search_group_layout')->default('paginated');
});
Schema::create('events', function (Blueprint $table): void {
$table->id();
$table->string('tenant_code');
$table->string('title');
$table->timestamps();
});
Schema::create('users', function (Blueprint $table): void {
$table->id();
$table->string('nombre_apellido');
$table->string('email');
$table->string('active_email')->virtualAs('CASE WHEN deleted_at IS NULL THEN lower(email) ELSE NULL END');
$table->string('password');
$table->string('rol_codigo')->default('user');
$table->string('tenant_codigo')->nullable();
$table->softDeletes();
$table->timestamps();
$table->unique(['active_email', 'rol_codigo']);
});
Schema::create('menues', function (Blueprint $table): void {
$table->id();
$table->string('code')->unique();
$table->string('label');
$table->string('route');
$table->string('parent_menu_code')->nullable();
$table->string('content_type')->default('dynamic');
});
Schema::create('roles_menues', function (Blueprint $table): void {
$table->string('rol_codigo');
$table->string('menu_codigo');
});
Schema::create('tenants_menues', function (Blueprint $table): void {
$table->string('tenant_code');
$table->string('menu_code');
$table->json('static_content')->nullable();
$table->timestamps();
});
foreach ([
'2026_06_18_130006_create_personal_access_tokens_table.php',
'2026_07_28_000000_create_roles_and_permissions_tables.php',
'2026_07_29_000000_add_login_security_fields_to_users_table.php',
'2026_07_29_000100_create_login_attempts_table.php',
] as $file) {
(require database_path('migrations/'.$file))->up();
}
DB::table('roles')->insert(['codigo' => 'adminapp', 'nombre' => 'AdminApp']);
DB::table('tenants')->insert([
['codigo' => 'onticket', 'nombre' => 'OnTicket', 'dominio' => 'onticket.test'],
['codigo' => 'other', 'nombre' => 'Other', 'dominio' => 'other.test'],
]);
DB::table('events')->insert([
['id' => 1, 'tenant_code' => 'onticket', 'title' => 'Evento A'],
['id' => 2, 'tenant_code' => 'onticket', 'title' => 'Evento B'],
['id' => 3, 'tenant_code' => 'other', 'title' => 'Evento ajeno'],
]);
// An existing administrator must remain general after applying the new migration.
DB::table('users')->insert([
'id' => 1, 'nombre_apellido' => 'Admin', 'email' => 'admin@example.test',
'password' => Hash::make('secret123'), 'rol_codigo' => 'adminapp', 'tenant_codigo' => 'onticket',
]);
$this->scopeMigration()->up();
$this->user = User::query()->findOrFail(1);
$this->createOperationsSchema();
DB::table('menues')->insert([
['code' => 'main.adminapp', 'label' => 'Administración', 'route' => '/', 'parent_menu_code' => null],
['code' => 'adminapp.ventas', 'label' => 'Ventas', 'route' => '/admin/ventas', 'parent_menu_code' => 'main.adminapp'],
]);
foreach (['main.adminapp', 'adminapp.ventas'] as $code) {
DB::table('roles_menues')->insert(['rol_codigo' => 'adminapp', 'menu_codigo' => $code]);
DB::table('tenants_menues')->insert(['tenant_code' => 'onticket', 'menu_code' => $code]);
}
}
private function scopeMigration(): Migration
{
return require database_path('migrations/2026_09_30_000000_add_admin_scope_to_users.php');
}
private function login(array $extra = []): TestResponse
{
return $this->postJson('/api/v1/adminapp/login', [
'email' => ' ADMIN@EXAMPLE.TEST ', 'password' => 'secret123', ...$extra,
]);
}
private function createOperationsSchema(): void
{
Schema::table('tenants', function (Blueprint $table): void {
$table->unsignedBigInteger('active_event_id')->nullable();
$table->boolean('scanner_category_validation_enabled')->default(false);
$table->boolean('allow_ticket_refund')->default(true);
$table->boolean('allow_ticket_total_refund')->default(true);
$table->boolean('allow_ticket_partial_refund')->default(true);
$table->decimal('ticket_partial_refund_percentage')->default(25);
});
Schema::table('users', fn (Blueprint $table) => $table->string('dni')->nullable());
Schema::table('events', function (Blueprint $table): void {
$table->string('location')->nullable();
$table->string('date_text')->nullable();
});
(require database_path('migrations/2026_09_30_000200_add_refund_configuration_to_events.php'))->up();
DB::table('tenants')->where('codigo', 'onticket')->update(['active_event_id' => 2]);
Schema::create('social_media', function (Blueprint $table): void {
$table->id();
$table->string('code')->unique();
$table->string('nombre');
});
Schema::create('event_social_media', function (Blueprint $table): void {
$table->unsignedBigInteger('event_id');
$table->string('social_media_code');
$table->string('url');
$table->integer('orden');
$table->timestamps();
});
Schema::create('event_dates', function (Blueprint $table): void {
$table->id();
$table->string('tenant_code');
$table->unsignedBigInteger('event_id');
$table->date('date');
$table->time('time_start');
$table->time('time_end');
$table->unsignedBigInteger('validity_time_id')->nullable();
$table->unsignedBigInteger('rescheduled_to_event_date_id')->nullable();
$table->timestamp('suspended_at')->nullable();
});
Schema::create('validity_times', function (Blueprint $table): void {
$table->id();
$table->string('type');
$table->time('start_time')->nullable();
$table->time('end_time')->nullable();
$table->timestamp('fixed_starts_at')->nullable();
$table->timestamp('fixed_expires_at')->nullable();
$table->timestamps();
});
Schema::create('categorias', function (Blueprint $table): void {
$table->id();
$table->string('tenant_code')->nullable();
$table->unsignedBigInteger('categoria_id')->nullable();
$table->string('nombre');
});
Schema::create('category_scanners', function (Blueprint $table): void {
$table->unsignedBigInteger('user_id');
$table->unsignedBigInteger('categoria_id');
$table->timestamps();
});
Schema::create('catalog_items', function (Blueprint $table): void {
$table->id();
$table->string('tenant_code');
$table->unsignedBigInteger('event_id');
$table->unsignedBigInteger('category_id')->nullable();
$table->string('nombre');
$table->string('slug');
$table->text('descripcion')->nullable();
$table->decimal('precio')->default(0);
$table->string('type')->default('standard');
$table->string('inventory_policy')->default('tracked');
$table->string('inventory_subject')->default('product');
$table->integer('group_order')->default(0);
$table->boolean('has_tickets')->default(false);
$table->softDeletes();
});
Schema::create('compras', function (Blueprint $table): void {
$table->id();
$table->string('tenant_codigo');
$table->unsignedBigInteger('event_id');
$table->string('status');
$table->decimal('total');
$table->string('nombre_apellido');
$table->timestamps();
});
Schema::create('compra_items', function (Blueprint $table): void {
$table->id();
$table->unsignedBigInteger('compra_id');
$table->integer('cantidad');
$table->string('item_nombre')->nullable();
$table->decimal('precio_unitario')->default(10);
$table->decimal('total')->default(10);
});
Schema::create('tickets', function (Blueprint $table): void {
$table->id();
$table->string('tenant_code');
$table->unsignedBigInteger('event_id')->nullable();
$table->uuid('ticket');
foreach (['source_purchase_item_id', 'source_catalog_item_id', 'source_variant_id', 'scanner_user_id', 'user_id'] as $column) {
$table->unsignedBigInteger($column)->nullable();
}
foreach (['used_at', 'disabled_at', 'cancelled_at', 'refunded_at'] as $column) {
$table->timestamp($column)->nullable();
}
});
Schema::create('ticket_refunds', function (Blueprint $table): void {
$table->id();
$table->unsignedBigInteger('purchase_item_id');
$table->decimal('amount');
});
Schema::create('scan_attempts', function (Blueprint $table): void {
$table->id();
$table->string('tenant_code');
$table->unsignedBigInteger('scanner_user_id');
$table->unsignedBigInteger('ticket_id')->nullable();
$table->text('data')->nullable();
$table->string('result');
$table->timestamp('created_at')->nullable();
$table->timestamp('resolved_at')->nullable();
});
(require database_path('migrations/2026_09_30_000400_add_event_id_to_scan_attempts.php'))->up();
Schema::create('value_changes', function (Blueprint $table): void {
$table->id();
$table->string('tenant_code');
$table->string('trackable_type');
$table->unsignedBigInteger('trackable_id');
$table->string('attribute');
$table->string('old_value')->nullable();
$table->string('new_value')->nullable();
$table->string('actor_type')->default('user');
$table->unsignedBigInteger('user_id')->nullable();
$table->timestamp('changed_at')->nullable();
});
DB::table('roles')->insert(['codigo' => 'scanner', 'nombre' => 'Scanner']);
DB::table('permisos')->insert(['codigo' => 'tickets.escanear', 'nombre' => 'Escanear']);
DB::table('roles_permisos')->insert(['rol_codigo' => 'scanner', 'codigo_permiso' => 'tickets.escanear']);
foreach (['adminapp.catalog', 'adminapp.event', 'adminapp.staff', 'adminapp.inicio'] as $code) {
DB::table('menues')->insert(['code' => $code, 'label' => $code, 'route' => '/admin/test', 'parent_menu_code' => 'main.adminapp']);
DB::table('roles_menues')->insert(['rol_codigo' => 'adminapp', 'menu_codigo' => $code]);
DB::table('tenants_menues')->insert(['tenant_code' => 'onticket', 'menu_code' => $code]);
}
}
private function actingEventAdmin(): void
{
$this->user->update(['admin_scope' => 'event', 'event_id' => 1]);
Sanctum::actingAs($this->user);
}
public function test_event_and_refund_settings_use_user_event_even_when_tenant_active_event_changes(): void
{
$this->actingEventAdmin();
$this->getJson('/api/v1/adminapp/tenant/event')->assertOk()->assertJsonPath('data.id', 1)
->assertJsonPath('data.allow_ticket_refund', true);
$this->putJson('/api/v1/adminapp/tenant/event', [
'title' => 'Solo A', 'location' => 'Predio A', 'social_media' => [], 'allow_ticket_refund' => false,
'allow_ticket_total_refund' => true, 'allow_ticket_partial_refund' => true,
'ticket_partial_refund_percentage' => 30,
])->assertOk()->assertJsonPath('data.id', 1)->assertJsonPath('data.allow_ticket_refund', false);
$this->assertDatabaseHas('events', ['id' => 1, 'title' => 'Solo A', 'allow_ticket_refund' => false]);
$this->assertDatabaseHas('events', ['id' => 2, 'title' => 'Evento B', 'allow_ticket_refund' => true]);
$this->assertDatabaseHas('tenants', ['codigo' => 'onticket', 'allow_ticket_refund' => true]);
$this->getJson('/api/v1/adminapp/forms/event')->assertOk();
$this->getJson('/api/v1/adminapp/tenant/website-extras')->assertForbidden();
}
public function test_dates_are_created_on_user_event_and_other_event_dates_cannot_be_changed(): void
{
$this->actingEventAdmin();
$this->postJson('/api/v1/adminapp/tenant/event-dates', [
'date' => '2027-01-20', 'start_time' => '10:00', 'end_time' => '12:00',
])->assertSuccessful();
$this->assertDatabaseHas('event_dates', ['event_id' => 1, 'date' => '2027-01-20']);
DB::table('event_dates')->insert(['id' => 20, 'event_id' => 2, 'tenant_code' => 'onticket',
'date' => '2027-01-20', 'time_start' => '10:00', 'time_end' => '12:00']);
$this->postJson('/api/v1/adminapp/tenant/event-dates/20/suspend')->assertNotFound();
$this->postJson('/api/v1/adminapp/tenant/event-dates/20/reschedule', ['date' => '2027-01-21'])->assertNotFound();
$this->assertDatabaseHas('event_dates', ['id' => 20, 'suspended_at' => null]);
}
public function test_sales_totals_details_exports_and_history_are_scoped_to_user_event(): void
{
$this->actingEventAdmin();
foreach ([1, 2] as $id) {
DB::table('compras')->insert(['id' => $id, 'tenant_codigo' => 'onticket', 'event_id' => $id,
'status' => 'paid', 'total' => $id * 100, 'nombre_apellido' => 'Cliente', 'created_at' => now()]);
DB::table('compra_items')->insert(['id' => $id, 'compra_id' => $id, 'cantidad' => 1]);
DB::table('ticket_refunds')->insert(['purchase_item_id' => $id, 'amount' => $id * 10]);
DB::table('value_changes')->insert(['tenant_code' => 'onticket',
'trackable_type' => (new Purchase)->getMorphClass(),
'trackable_id' => $id, 'attribute' => 'status', 'new_value' => 'paid', 'changed_at' => now()]);
}
$this->getJson('/api/v1/adminapp/tenant/sales')->assertOk()->assertJsonCount(1, 'data')
->assertJsonPath('confirmed_sales_total', '100.00')->assertJsonPath('refunded_total', '10.00');
$this->getJson('/api/v1/adminapp/tenant/sales/1')->assertOk();
foreach (['', '/tickets'] as $suffix) {
$this->getJson('/api/v1/adminapp/tenant/sales/2'.$suffix)->assertNotFound();
}
foreach (['confirm', 'cancel'] as $action) {
$this->postJson('/api/v1/adminapp/tenant/sales/2/'.$action)->assertNotFound();
}
$this->getJson('/api/v1/adminapp/tenant/sales/modifications')->assertOk()->assertJsonCount(1, 'data');
$service = app(AdminAppSaleService::class);
$tenant = $this->user->tenant;
$this->assertSame([1], $service->salesForExport($tenant, [], 1)->pluck('id')->all());
$this->assertSame([1], $service->modificationsForExport($tenant, [], 1)->pluck('trackable_id')->all());
}
private function scanner(int $eventId, int $id = 10): User
{
return User::query()->create(['id' => $id, 'nombre_apellido' => 'Scanner',
'email' => "scanner{$id}@example.test", 'password' => 'password', 'dni' => '123',
'tenant_codigo' => 'onticket', 'rol_codigo' => 'scanner', 'admin_scope' => 'event', 'event_id' => $eventId]);
}
public function test_staff_is_created_on_admin_event_and_other_staff_cannot_be_managed(): void
{
$this->actingEventAdmin();
$scanner = $this->scanner(2);
$this->getJson('/api/v1/adminapp/tenant/staff')->assertOk()->assertJsonCount(0, 'data');
$payload = ['nombre_apellido' => 'Nuevo', 'email' => 'nuevo@example.test', 'dni' => '123'];
$this->putJson('/api/v1/adminapp/tenant/staff/'.$scanner->id, $payload)->assertNotFound();
$this->deleteJson('/api/v1/adminapp/tenant/staff/'.$scanner->id)->assertNotFound();
$this->getJson('/api/v1/adminapp/tenant/staff/'.$scanner->id.'/scan-attempts')->assertNotFound();
$this->mock(ResetPasswordAttemptService::class,
fn ($mock) => $mock->shouldReceive('createForScannerEmail')->once());
$this->postJson('/api/v1/adminapp/tenant/staff', [...$payload, 'event_id' => 2])
->assertSuccessful()->assertJsonPath('data.event_id', 1);
$this->assertDatabaseHas('users', ['email' => 'nuevo@example.test', 'event_id' => 1, 'admin_scope' => 'event']);
}
public function test_scanner_rejects_foreign_event_qr_without_consuming_or_disclosing_ticket(): void
{
$scanner = $this->scanner(1);
Sanctum::actingAs($scanner);
$uuid = '11111111-1111-4111-8111-111111111111';
DB::table('tickets')->insert(['id' => 20, 'tenant_code' => 'onticket', 'event_id' => 2, 'ticket' => $uuid]);
$this->getJson('/api/v1/scanner/tickets/'.$uuid)->assertNotFound();
$this->postJson('/api/v1/scanner/tickets/scan', ['data' => $uuid])->assertOk()
->assertJsonPath('data.scan_attempt.result', 'ticket_not_found')->assertJsonPath('data.ticket', null);
$this->assertDatabaseHas('tickets', ['id' => 20, 'used_at' => null, 'scanner_user_id' => null]);
$this->assertDatabaseHas('scan_attempts', ['scanner_user_id' => $scanner->id, 'event_id' => 1, 'ticket_id' => null]);
}
public function test_scanner_history_and_detail_follow_assignment_changes_and_invalid_event_is_denied(): void
{
$scanner = $this->scanner(1);
Sanctum::actingAs($scanner);
$response = $this->postJson('/api/v1/scanner/tickets/scan', ['data' => 'invalid'])->assertOk();
$id = $response->json('data.scan_attempt.id');
$this->getJson('/api/v1/scanner/attempts')->assertOk()->assertJsonCount(1, 'data');
$scanner->update(['event_id' => 2]);
$this->getJson('/api/v1/scanner/attempts')->assertOk()->assertJsonCount(0, 'data');
$this->getJson('/api/v1/scanner/attempts/'.$id)->assertNotFound();
$scanner->update(['event_id' => null]);
$this->getJson('/api/v1/scanner/attempts')->assertForbidden();
}
public function test_initial_assignment_migration_preserves_existing_scopes_and_ignores_missing_events(): void
{
$this->user->update(['admin_scope' => 'event', 'event_id' => 1]);
$scanner = $this->scanner(1);
$scanner->update(['event_id' => null, 'admin_scope' => 'tenant']);
$migration = require database_path('migrations/2026_09_30_000100_assign_active_event_to_staff_users.php');
$migration->up();
$migration->up();
$this->assertDatabaseHas('users', ['id' => 1, 'event_id' => 1]);
$this->assertDatabaseHas('users', ['id' => $scanner->id, 'event_id' => 2, 'admin_scope' => 'event']);
DB::table('tenants')->where('codigo', 'onticket')->update(['active_event_id' => 3]);
$scanner->refresh()->update(['event_id' => null, 'admin_scope' => 'tenant']);
$migration->up();
$this->assertDatabaseHas('users', ['id' => $scanner->id, 'event_id' => null, 'admin_scope' => 'event']);
}
public function test_deprecated_menus_are_removed_with_their_role_and_tenant_assignments(): void
{
foreach (['adminapp.categories', 'adminapp.combos'] as $code) {
DB::table('menues')->insert(['code' => $code, 'label' => $code, 'route' => '/admin/old']);
DB::table('roles_menues')->insert(['rol_codigo' => 'adminapp', 'menu_codigo' => $code]);
DB::table('tenants_menues')->insert(['tenant_code' => 'onticket', 'menu_code' => $code]);
}
(require database_path('migrations/2026_09_30_000300_remove_deprecated_admin_menus.php'))->up();
foreach (['adminapp.categories', 'adminapp.combos'] as $code) {
$this->assertDatabaseMissing('menues', ['code' => $code]);
$this->assertDatabaseMissing('roles_menues', ['menu_codigo' => $code]);
$this->assertDatabaseMissing('tenants_menues', ['menu_code' => $code]);
}
}
public function test_scanner_accepts_ticket_from_its_event_and_cannot_consume_it_twice(): void
{
$scanner = $this->scanner(1);
Sanctum::actingAs($scanner);
$uuid = '11111111-1111-4111-8111-111111111111';
DB::table('tickets')->insert(['id' => 20, 'tenant_code' => 'onticket', 'event_id' => 1, 'ticket' => $uuid]);
$this->postJson('/api/v1/scanner/tickets/scan', ['data' => $uuid])->assertOk()
->assertJsonPath('data.scan_attempt.result', 'accepted')->assertJsonPath('data.ticket.id', 20);
$this->assertNotNull(DB::table('tickets')->where('id', 20)->value('used_at'));
$this->postJson('/api/v1/scanner/tickets/scan', ['data' => $uuid])->assertOk()
->assertJsonPath('data.scan_attempt.result', 'already_scanned');
$this->getJson('/api/v1/scanner/tickets/'.$uuid)->assertOk();
}
public function test_refund_calculation_uses_ticket_event_configuration_instead_of_tenant_defaults(): void
{
Schema::create('desfile_entry_reservations', function (Blueprint $table): void {
$table->id();
$table->unsignedBigInteger('ticket_id');
$table->softDeletes();
});
DB::table('ticket_refunds')->delete();
DB::table('compra_items')->insert(['id' => 1, 'compra_id' => 1, 'cantidad' => 1,
'precio_unitario' => 100, 'total' => 100]);
DB::table('tickets')->insert(['id' => 20, 'tenant_code' => 'onticket', 'event_id' => 1,
'ticket' => '11111111-1111-4111-8111-111111111111', 'source_purchase_item_id' => 1]);
DB::table('events')->where('id', 1)->update(['ticket_partial_refund_percentage' => 75]);
$calculation = app(AdminAppTicketService::class)
->calculateRefund($this->user->tenant, 20);
$this->assertSame(['total' => '100.00', 'partial' => '75.00'], $calculation);
DB::table('events')->where('id', 1)->update(['allow_ticket_refund' => false]);
$this->assertFalse(Ticket::query()->findOrFail(20)->allow_refund());
}
public function test_staff_category_options_and_assignments_exclude_other_event_products(): void
{
$this->actingEventAdmin();
DB::table('tenants')->where('codigo', 'onticket')->update(['scanner_category_validation_enabled' => true]);
foreach ([1, 2] as $id) {
DB::table('categorias')->insert(['id' => $id, 'nombre' => "Categoria {$id}", 'tenant_code' => 'onticket']);
DB::table('catalog_items')->insert(['id' => $id, 'tenant_code' => 'onticket', 'event_id' => $id,
'nombre' => "Producto {$id}", 'slug' => "producto-{$id}", 'category_id' => $id]);
}
$this->getJson('/api/v1/adminapp/forms/staff')->assertOk()->assertJsonCount(1, 'data.categories')
->assertJsonPath('data.categories.0.id', 1);
$this->postJson('/api/v1/adminapp/tenant/staff', ['nombre_apellido' => 'Nuevo', 'dni' => '123',
'email' => 'nuevo@example.test', 'category_ids' => [2]])->assertUnprocessable()->assertJsonValidationErrors('category_ids');
$this->assertDatabaseMissing('users', ['email' => 'nuevo@example.test']);
}
public function test_initial_migration_assigns_existing_tenant_admin_and_blocks_staff_without_active_event(): void
{
$unassigned = $this->scanner(1);
$unassigned->update(['tenant_codigo' => 'other', 'admin_scope' => 'tenant', 'event_id' => null]);
(require database_path('migrations/2026_09_30_000100_assign_active_event_to_staff_users.php'))->up();
$this->assertDatabaseHas('users', ['id' => 1, 'admin_scope' => 'event', 'event_id' => 2]);
$this->assertDatabaseHas('users', ['id' => $unassigned->id, 'admin_scope' => 'event', 'event_id' => null]);
$this->user->refresh();
$this->assertFalse($this->user->isTenantAdministrator());
$this->login()->assertOk()->assertJsonPath('user.event_id', 2);
}
public function test_scanner_login_validates_event_before_issuing_a_token(): void
{
$scanner = $this->scanner(1);
$this->postJson('/api/v1/scanner/login', ['email' => $scanner->email, 'password' => 'password'])
->assertOk()->assertJsonPath('user.event_id', 1);
$scanner->update(['event_id' => null]);
$this->postJson('/api/v1/scanner/login', ['email' => $scanner->email, 'password' => 'password'])
->assertUnprocessable()->assertJsonValidationErrors('email');
$this->assertDatabaseCount('personal_access_tokens', 1);
$this->assertSame(0, $scanner->refresh()->failed_login_attempts);
}
}

View File

@@ -43,7 +43,7 @@ class ScannerMeControllerTest extends TestCase
'route' => '/scanner/scan',
]);
$foreign = Menu::query()->create([
'code' => 'adminapp.inicio',
'code' => 'onticket.adminapp.inicio',
'label' => 'Administración',
'route' => '/admin/inicio',
]);

View File

@@ -186,7 +186,7 @@ class EntryControllerTest extends TestCase
'admin_website_type_code' => 'onticket',
]);
$menu = Menu::query()->firstOrCreate(
['code' => 'adminapp.desfile.entradas'],
['code' => 'onticket.adminapp.desfile.entradas'],
['label' => 'Entradas', 'route' => '/admin/desfile/entradas'],
);
$tenant->menues()->attach($menu->code);

View File

@@ -97,6 +97,8 @@ class AccommodationControllerTest extends TestCase
$updated = $this->variantPayload('Casa Rodante Premium', 'Con electricidad', 15, 50000);
$updated['id'] = $variantId;
unset($updated['stock']);
$updated['stock_difference'] = -5;
$this->postJson('/api/v1/adminapp/tenant/accommodations', [
'variants' => [
@@ -234,7 +236,7 @@ class AccommodationControllerTest extends TestCase
if ($withMenu) {
$menu = Menu::query()->firstOrCreate(
['code' => 'adminapp.fiesta-futbol-infantil.alojamientos'],
['code' => 'onticket.adminapp.fiesta-futbol-infantil.alojamientos'],
['label' => 'Alojamientos', 'route' => '/admin/alojamientos'],
);
$tenant->menues()->syncWithoutDetaching([$menu->code]);

View File

@@ -43,10 +43,10 @@ class EntryControllerTest extends TestCase
{
$tenant = $this->createFiestaTenant();
$categories = [
'entries' => ['Entradas', 'adminapp.fiesta-futbol-infantil.entradas'],
'foods' => ['Comidas', 'adminapp.fiesta-futbol-infantil.comida'],
'accommodations' => ['Alojamientos', 'adminapp.fiesta-futbol-infantil.alojamientos'],
'merchandise' => ['Merchandising', 'adminapp.fiesta-futbol-infantil.merchandising'],
'entries' => ['Entradas', 'onticket.adminapp.fiesta-futbol-infantil.entradas'],
'foods' => ['Comidas', 'onticket.adminapp.fiesta-futbol-infantil.comida'],
'accommodations' => ['Alojamientos', 'onticket.adminapp.fiesta-futbol-infantil.alojamientos'],
'merchandise' => ['Merchandising', 'onticket.adminapp.fiesta-futbol-infantil.merchandising'],
];
foreach ($categories as [$label, $menuCode]) {
@@ -194,7 +194,7 @@ class EntryControllerTest extends TestCase
'title' => 'Abono actualizado',
'description' => 'Ahora incluye ambas fechas',
'event_date_ids' => [$firstDate->id, $secondDate->id],
'stock' => 20,
'stock_difference' => 10,
'price' => 250,
],
[
@@ -268,7 +268,7 @@ class EntryControllerTest extends TestCase
'id' => $entryId,
'title' => 'Abono editado',
'event_date_ids' => [$date->id, $otherDate->id],
'stock' => 30,
'stock_difference' => 10,
'price' => 200,
]],
])->assertOk()
@@ -329,7 +329,7 @@ class EntryControllerTest extends TestCase
'title' => 'Entrada inválida',
'description' => null,
'event_date_ids' => [$foreignDate->id],
'stock' => 10,
'stock_difference' => 0,
'price' => 100,
]],
])
@@ -371,7 +371,7 @@ class EntryControllerTest extends TestCase
'title' => 'Entrada inválida',
'description' => null,
'event_date_ids' => [$eventDate->id],
'stock' => 10,
'stock_difference' => 0,
'price' => 100,
]],
])
@@ -405,7 +405,7 @@ class EntryControllerTest extends TestCase
{
$tenant = $this->createTenant('fiesta_futbol_infantil');
$menu = Menu::query()->create([
'code' => 'adminapp.fiesta-futbol-infantil.entradas',
'code' => 'onticket.adminapp.fiesta-futbol-infantil.entradas',
'label' => 'Entradas',
'route' => '/admin/entradas',
]);

View File

@@ -124,6 +124,8 @@ class FoodControllerTest extends TestCase
$updated = $this->variantPayload($secondDate->id, 'Cena', 'Vianda', 80, 8500);
$updated['id'] = $variantId;
unset($updated['stock']);
$updated['stock_difference'] = -20;
$updated['description'] = 'Cena para llevar';
$this->postJson('/api/v1/adminapp/tenant/foods', [
@@ -240,7 +242,7 @@ class FoodControllerTest extends TestCase
Inventory::query()->whereKey($replacementInventoryId)->delete();
$updated = $this->patchJson('/api/v1/adminapp/tenant/foods/history-stock', [
'variants' => [['id' => $historicalVariantId, 'stock' => 45]],
'variants' => [['id' => $historicalVariantId, 'stock_difference' => -55]],
])
->assertOk()
->assertJsonPath('data.history.0.variants.0.id', $historicalVariantId)
@@ -258,7 +260,7 @@ class FoodControllerTest extends TestCase
]);
$this->patchJson('/api/v1/adminapp/tenant/foods/history-stock', [
'variants' => [['id' => $activeVariantId, 'stock' => 20]],
'variants' => [['id' => $activeVariantId, 'stock_difference' => -60]],
])
->assertUnprocessable()
->assertJsonValidationErrors(['variants.0.id']);
@@ -365,7 +367,7 @@ class FoodControllerTest extends TestCase
'time_end' => '23:59',
]);
$menu = Menu::query()->create([
'code' => 'adminapp.fiesta-futbol-infantil.comida',
'code' => 'onticket.adminapp.fiesta-futbol-infantil.comida',
'label' => 'Comida',
'route' => '/admin/comidas',
]);

View File

@@ -112,6 +112,8 @@ class MerchandiseControllerTest extends TestCase
$updatedVariant = $this->variantPayload('Blanco', 'M', 80, 12500);
$updatedVariant['id'] = $variantId;
unset($updatedVariant['stock']);
$updatedVariant['stock_difference'] = -20;
$updatedItem = $this->itemPayload('Camiseta oficial', 2, [
$updatedVariant,
$this->variantPayload('Verde', 'L', 60, 15000),
@@ -234,6 +236,8 @@ class MerchandiseControllerTest extends TestCase
$secondItemVariantId = $created->json('data.1.variants.0.id');
$foreignVariant = $this->variantPayload('Azul Marino', 'XL', 20, 30000);
$foreignVariant['id'] = $secondItemVariantId;
unset($foreignVariant['stock']);
$foreignVariant['stock_difference'] = 0;
$firstItem = $this->itemPayload('Camiseta', 3, [$foreignVariant]);
$firstItem['id'] = $firstItemId;
@@ -289,7 +293,7 @@ class MerchandiseControllerTest extends TestCase
['value' => 'XL', 'label' => 'XL', 'sort_order' => 4],
]);
$menu = Menu::query()->create([
'code' => 'adminapp.fiesta-futbol-infantil.merchandising',
'code' => 'onticket.adminapp.fiesta-futbol-infantil.merchandising',
'label' => 'Merchandising',
'route' => '/admin/merchandising',
]);

View File

@@ -135,7 +135,7 @@ class AdminAppDesfileEntryReservationFormControllerTest extends TestCase
private function grantReservationsMenu(Tenant $tenant): void
{
$menu = Menu::query()->create([
'code' => 'adminapp.desfile.reservas',
'code' => 'onticket.adminapp.desfile.reservas',
'label' => 'Reserva de Tickets',
'route' => '/admin/desfile/reservas',
]);

View File

@@ -349,7 +349,7 @@ class AdminAppTicketFilterFormControllerTest extends TestCase
private function grantTicketsMenu(Tenant $tenant): void
{
$menu = Menu::query()->create([
'code' => 'adminapp.tickets',
'code' => 'onticket.adminapp.tickets',
'label' => 'Tickets',
'route' => '/admin/tickets',
]);

Some files were not shown because too many files have changed in this diff Show More