| @@ -1,17 +1,18 @@ | ||
| 1 | 1 | <?php |
| 2 | 2 | |
| 3 | 3 | namespace FluentBooking\App\Http\Controllers; |
| 4 | 4 | |
| 5 | +use FluentBooking\App\Models\Availability; | |
| 5 | 6 | use FluentBooking\App\Models\Calendar; |
| 6 | 7 | use FluentBooking\App\Models\CalendarSlot; |
| 7 | 8 | use FluentBooking\App\Services\Helper; |
| 8 | -use FluentBooking\App\Services\CurrenciesHelper; | |
| 9 | 9 | use FluentBooking\App\Services\LandingPage\LandingPageHelper; |
| 10 | 10 | use FluentBooking\App\Services\PermissionManager; |
| 11 | 11 | use FluentBooking\App\Services\AvailabilityService; |
| 12 | 12 | use FluentBooking\App\Services\SanitizeService; |
| 13 | 13 | use FluentBooking\App\Services\CalendarService; |
| 14 | +use FluentBooking\App\Services\OnboardingService; | |
| 14 | 15 | use FluentBooking\App\Services\CalendarEventService; |
| 15 | 16 | use FluentBooking\App\Services\BookingFieldService; |
| 16 | 17 | use FluentBooking\App\Hooks\Handlers\AdminMenuHandler; |
| 17 | 18 | use FluentBooking\Framework\Http\Request\Request; |
| @@ -32,9 +33,9 @@ | ||
| 32 | 33 | $query->where('title', 'LIKE', '%' . $search . '%'); |
| 33 | 34 | } |
| 34 | 35 | }; |
| 35 | 36 | |
| 36 | - $calendarsQuery = Calendar::with(['slots' => function($query) use ($applySearchFilter) { | |
| 37 | + $calendarsQuery = Calendar::with(['metas', 'slots' => function($query) use ($applySearchFilter) { | |
| 37 | 38 | $query->where($applySearchFilter); |
| 38 | 39 | }]) |
| 39 | 40 | ->where('status', '!=', 'expired'); |
| 40 | 41 | |
| @@ -60,23 +61,29 @@ | ||
| 60 | 61 | foreach ($calendars as $calendar) { |
| 61 | 62 | $calendar->author_profile = $calendar->getAuthorProfile(); |
| 62 | 63 | $calendar->public_url = $calendar->getLandingPageUrl(); |
| 63 | 64 | $calendar->event_order = $calendar->getMeta('event_order'); |
| 64 | - foreach ($calendar->slots as $key => $slot) { | |
| 65 | - if (!$hasPermission && !CalendarEventService::isSharedCalendarEvent($slot)) { | |
| 66 | - unset($calendar->slots[$key]); | |
| 67 | - } | |
| 65 | + | |
| 66 | + if (!$hasPermission) { | |
| 67 | + $calendar->setRelation('slots', $calendar->slots->filter(function ($slot) { | |
| 68 | + return CalendarEventService::isSharedCalendarEvent($slot); | |
| 69 | + })->values()); | |
| 70 | + } | |
| 71 | + | |
| 72 | + foreach ($calendar->slots as $slot) { | |
| 73 | + $slot->setRelation('calendar', $calendar); | |
| 68 | 74 | $slot->shortcode = '[fluent_booking id="' . $slot->id . '"]'; |
| 69 | 75 | $slot->public_url = $slot->getPublicUrl(); |
| 70 | 76 | $slot->duration = $slot->getDefaultDuration(); |
| 71 | - $slot->price_total = $slot->getPricingTotal(); | |
| 77 | + $slot->price_total = $slot->getEventPrice(); | |
| 72 | 78 | $slot->location_fields = $slot->getLocationFields(); |
| 73 | 79 | $slot->author_profiles = $slot->isMultiHostEvent() ? $slot->getAuthorProfiles() : []; |
| 74 | 80 | do_action_ref_array('fluent_booking/calendar_slot', [&$slot]); |
| 81 | + $slot->unsetRelation('calendar'); | |
| 75 | 82 | } |
| 76 | 83 | |
| 77 | 84 | if(empty($calendar->author_profile['ID'])) { |
| 78 | - $calendar->generic_error = '<p style="color: red; margin:0;">Connected Host user is missing</p>'; | |
| 85 | + $calendar->generic_error = '<p style="color: var(--fcal-danger-fg); margin:0;">Connected Host user is missing</p>'; | |
| 79 | 86 | } |
| 80 | 87 | |
| 81 | 88 | do_action_ref_array('fluent_booking/calendar', [&$calendar, 'lists']); |
| 82 | 89 | } |
| @@ -106,12 +113,59 @@ | ||
| 106 | 113 | ], 422); |
| 107 | 114 | } |
| 108 | 115 | |
| 109 | 116 | return [ |
| 110 | - 'status' => true | |
| 117 | + 'status' => true, | |
| 118 | + 'message' => __('The provided slug is available', 'fluent-booking') | |
| 111 | 119 | ]; |
| 112 | 120 | } |
| 113 | 121 | |
| 122 | + public function getNewEventLocationFields(Request $request) | |
| 123 | + { | |
| 124 | + $eventType = SanitizeService::checkCollection( | |
| 125 | + sanitize_text_field($request->get('event_type', 'single')), | |
| 126 | + CalendarSlot::getEventTypes(), | |
| 127 | + 'single' | |
| 128 | + ); | |
| 129 | + | |
| 130 | + // Resolve the organizer the same way createCalendar() does, so the | |
| 131 | + // connection checks run against the host the event will be saved under. | |
| 132 | + $canAssignOthers = PermissionManager::canManageOtherHosts(); | |
| 133 | + | |
| 134 | + $userId = get_current_user_id(); | |
| 135 | + $requestedUserId = (int) $request->get('user_id'); | |
| 136 | + if ($requestedUserId && $canAssignOthers) { | |
| 137 | + $userId = $requestedUserId; | |
| 138 | + } | |
| 139 | + | |
| 140 | + $calendarEvent = new CalendarSlot(); | |
| 141 | + $calendarEvent->event_type = $eventType; | |
| 142 | + | |
| 143 | + if ($calendarEvent->isMultiHostEvent()) { | |
| 144 | + $teamMembers = array_values(array_unique(array_filter( | |
| 145 | + array_map('intval', (array) $request->get('team_members', [])) | |
| 146 | + ))); | |
| 147 | + | |
| 148 | + if (!PermissionManager::canAssignHosts($teamMembers, [$userId])) { | |
| 149 | + return $this->sendError([ | |
| 150 | + 'message' => __('You are not allowed to create a calendar for another user', 'fluent-booking') | |
| 151 | + ], 403); | |
| 152 | + } | |
| 153 | + | |
| 154 | + if ($teamMembers && !in_array($userId, $teamMembers, true)) { | |
| 155 | + $userId = reset($teamMembers); | |
| 156 | + } | |
| 157 | + | |
| 158 | + $calendarEvent->settings = ['team_members' => $teamMembers]; | |
| 159 | + } | |
| 160 | + | |
| 161 | + $calendarEvent->user_id = $userId; | |
| 162 | + | |
| 163 | + return [ | |
| 164 | + 'location_fields' => $calendarEvent->getLocationFields() | |
| 165 | + ]; | |
| 166 | + } | |
| 167 | + | |
| 114 | 168 | public function createCalendar(Request $request) |
| 115 | 169 | { |
| 116 | 170 | $data = $request->get('calendar'); |
| 117 | 171 | |
| @@ -147,9 +201,9 @@ | ||
| 147 | 201 | $this->validate($data, $validationConfig['rules'], $validationConfig['messages']); |
| 148 | 202 | |
| 149 | 203 | do_action('fluent_booking/before_create_calendar', $data, $this); |
| 150 | 204 | |
| 151 | - if (!empty($data['user_id']) && PermissionManager::userCan('invite_team_members')) { | |
| 205 | + if (!empty($data['user_id']) && PermissionManager::canManageOtherHosts()) { | |
| 152 | 206 | $user = get_user_by('ID', $data['user_id']); |
| 153 | 207 | } else { |
| 154 | 208 | $user = get_user_by('ID', get_current_user_id()); |
| 155 | 209 | } |
| @@ -159,15 +213,25 @@ | ||
| 159 | 213 | 'message' => __('User not found', 'fluent-booking') |
| 160 | 214 | ], 422); |
| 161 | 215 | } |
| 162 | 216 | |
| 163 | - $type = sanitize_text_field(Arr::get($data, 'type', 'simple')); | |
| 217 | + $onboardinFeatures = $request->get('features'); | |
| 218 | + if (!empty($onboardinFeatures)) { | |
| 219 | + $installableAddons = SanitizeService::sanitizeAddons($onboardinFeatures); | |
| 220 | + OnboardingService::installAddons($installableAddons); | |
| 221 | + } | |
| 164 | 222 | |
| 223 | + $type = SanitizeService::checkCollection( | |
| 224 | + sanitize_text_field(Arr::get($data, 'type', 'simple')), | |
| 225 | + ['simple', 'team', 'event'], | |
| 226 | + 'simple' | |
| 227 | + ); | |
| 228 | + | |
| 165 | 229 | $isHostCalendar = $type == 'simple' ? true : false; |
| 166 | 230 | |
| 167 | 231 | if ($isHostCalendar && Calendar::where('user_id', $user->ID)->where('type', 'simple')->first()) { |
| 168 | 232 | return $this->sendError([ |
| 169 | - 'message' => __('The user already have a calendar. Please delete it first to create a new one', 'fluent-booking') | |
| 233 | + 'message' => __('The user already has a calendar. Please delete it first to create a new one', 'fluent-booking') | |
| 170 | 234 | ], 422); |
| 171 | 235 | } |
| 172 | 236 | |
| 173 | 237 | if ($isHostCalendar) { |
| @@ -183,10 +247,30 @@ | ||
| 183 | 247 | |
| 184 | 248 | if (!$isHostCalendar) { |
| 185 | 249 | $title = sanitize_text_field(Arr::get($data, 'title', '')); |
| 186 | 250 | $data['slug'] = sanitize_title($title, '', 'display'); |
| 187 | - $teamMembers = array_map('intval', Arr::get($slot, 'settings.team_members', [])); | |
| 188 | - if (!in_array($user->ID, $teamMembers)) { | |
| 251 | + $teamMembers = array_values(array_filter( | |
| 252 | + array_map('intval', (array) Arr::get($slot, 'settings.team_members', [])) | |
| 253 | + )); | |
| 254 | + | |
| 255 | + cache_users($teamMembers); | |
| 256 | + | |
| 257 | + foreach ($teamMembers as $memberId) { | |
| 258 | + if (!get_user_by('ID', $memberId)) { | |
| 259 | + return $this->sendError([ | |
| 260 | + 'message' => __('Invalid Team Member', 'fluent-booking') | |
| 261 | + ], 422); | |
| 262 | + } | |
| 263 | + } | |
| 264 | + | |
| 265 | + // Gated even when the creator is listed too, not only when they are absent. | |
| 266 | + if (!PermissionManager::canAssignHosts($teamMembers, [$user->ID])) { | |
| 267 | + return $this->sendError([ | |
| 268 | + 'message' => __('You are not allowed to create a calendar for another user', 'fluent-booking') | |
| 269 | + ], 403); | |
| 270 | + } | |
| 271 | + | |
| 272 | + if (!in_array($user->ID, $teamMembers, true)) { | |
| 189 | 273 | $user = get_user_by('ID', reset($teamMembers)); |
| 190 | 274 | if (!$user) { |
| 191 | 275 | return $this->sendError([ |
| 192 | 276 | 'message' => __('Invalid Team Member', 'fluent-booking') |
| @@ -245,9 +329,9 @@ | ||
| 245 | 329 | 'description' => wp_kses_post(Arr::get($slot, 'description')), |
| 246 | 330 | 'settings' => [ |
| 247 | 331 | 'team_members' => !$isHostCalendar ? $teamMembers : [], |
| 248 | 332 | 'schedule_type' => sanitize_text_field($slot['schedule_type']), |
| 249 | - 'weekly_schedules' => SanitizeService::weeklySchedules($slot['weekly_schedules'], $calendar->author_timezone, 'UTC') | |
| 333 | + 'weekly_schedules' => SanitizeService::weeklySchedules($slot['weekly_schedules'], $calendar->author_timezone, 'UTC', true) | |
| 250 | 334 | ], |
| 251 | 335 | 'status' => SanitizeService::checkCollection($slot['status'], ['active', 'draft']), |
| 252 | 336 | 'color_schema' => sanitize_text_field(Arr::get($slot, 'color_schema', '#0099ff')), |
| 253 | 337 | 'event_type' => sanitize_text_field(Arr::get($slot, 'event_type')), |
| @@ -281,9 +365,28 @@ | ||
| 281 | 365 | $query->where('status', '!=', 'expired'); |
| 282 | 366 | }])->findOrFail($calendarId); |
| 283 | 367 | |
| 284 | 368 | $calendar->author_profile = $calendar->getAuthorProfile(); |
| 369 | + $calendar->event_order = $calendar->getMeta('event_order'); | |
| 285 | 370 | |
| 371 | + if (!PermissionManager::hasAllCalendarAccess(true)) { | |
| 372 | + $calendar->setRelation('slots', $calendar->slots->filter(function ($slot) { | |
| 373 | + return CalendarEventService::isSharedCalendarEvent($slot); | |
| 374 | + })->values()); | |
| 375 | + } | |
| 376 | + | |
| 377 | + foreach ($calendar->slots as $slot) { | |
| 378 | + $slot->setRelation('calendar', $calendar); | |
| 379 | + $slot->shortcode = '[fluent_booking id="' . $slot->id . '"]'; | |
| 380 | + $slot->public_url = $slot->getPublicUrl(); | |
| 381 | + $slot->duration = $slot->getDefaultDuration(); | |
| 382 | + $slot->price_total = $slot->getEventPrice(); | |
| 383 | + $slot->location_fields = $slot->getLocationFields(); | |
| 384 | + $slot->author_profiles = $slot->isMultiHostEvent() ? $slot->getAuthorProfiles() : []; | |
| 385 | + do_action_ref_array('fluent_booking/calendar_slot', [&$slot]); | |
| 386 | + $slot->unsetRelation('calendar'); | |
| 387 | + } | |
| 388 | + | |
| 286 | 389 | $data = [ |
| 287 | 390 | 'calendar' => $calendar |
| 288 | 391 | ]; |
| 289 | 392 | |
| @@ -290,8 +393,12 @@ | ||
| 290 | 393 | if (in_array('settings_menu', $request->get('with', []))) { |
| 291 | 394 | $data['settings_menu'] = AdminMenuHandler::getCalendarSettingsMenuItems($calendar); |
| 292 | 395 | } |
| 293 | 396 | |
| 397 | + if (in_array('public_url', $request->get('with', []))) { | |
| 398 | + $data['public_url'] = $calendar->getLandingPageUrl(); | |
| 399 | + } | |
| 400 | + | |
| 294 | 401 | return $data; |
| 295 | 402 | } |
| 296 | 403 | |
| 297 | 404 | public function getSharingSettings(Request $request, $calendarId) |
| @@ -298,10 +405,11 @@ | ||
| 298 | 405 | { |
| 299 | 406 | $calendar = Calendar::findOrFail($calendarId); |
| 300 | 407 | |
| 301 | 408 | return [ |
| 302 | - 'settings' => LandingPageHelper::getSettings($calendar), | |
| 303 | - 'share_url' => $calendar->getLandingPageUrl(true) | |
| 409 | + 'settings' => LandingPageHelper::getSettings($calendar), | |
| 410 | + 'share_url' => $calendar->getLandingPageUrl(true), | |
| 411 | + 'public_url' => $this->getSharePublicUrl($calendar, intval($request->get('event_id'))) | |
| 304 | 412 | ]; |
| 305 | 413 | } |
| 306 | 414 | |
| 307 | 415 | public function saveSharingSettings(Request $request, $calendarId) |
| @@ -337,12 +445,27 @@ | ||
| 337 | 445 | $sharingSettings = $request->get('landing_page_settings', []); |
| 338 | 446 | LandingPageHelper::updateSettings($calendar, $sharingSettings); |
| 339 | 447 | |
| 340 | 448 | return [ |
| 341 | - 'message' => __('Landing Page settings has been updated', 'fluent-booking') | |
| 449 | + 'message' => __('Landing Page settings has been updated', 'fluent-booking'), | |
| 450 | + 'public_url' => $this->getSharePublicUrl($calendar, intval($request->get('event_id'))) | |
| 342 | 451 | ]; |
| 343 | 452 | } |
| 344 | 453 | |
| 454 | + private function getSharePublicUrl($calendar, $eventId) | |
| 455 | + { | |
| 456 | + if ($eventId) { | |
| 457 | + $event = CalendarSlot::where('calendar_id', $calendar->id) | |
| 458 | + ->where('id', $eventId) | |
| 459 | + ->first(); | |
| 460 | + if ($event) { | |
| 461 | + return $event->getPublicUrl(); | |
| 462 | + } | |
| 463 | + } | |
| 464 | + | |
| 465 | + return $calendar->getLandingPageUrl(); | |
| 466 | + } | |
| 467 | + | |
| 345 | 468 | public function updateCalendar(Request $request, $calendarId) |
| 346 | 469 | { |
| 347 | 470 | $data = $request->all(); |
| 348 | 471 | |
| @@ -471,12 +594,32 @@ | ||
| 471 | 594 | ], $slot); |
| 472 | 595 | |
| 473 | 596 | $this->validate($slot, $validationConfig['rules'], $validationConfig['messages']); |
| 474 | 597 | |
| 598 | + $teamMembers = array_values(array_unique(array_filter( | |
| 599 | + array_map('intval', (array) Arr::get($slot, 'settings.team_members', [])) | |
| 600 | + ))); | |
| 601 | + | |
| 602 | + cache_users($teamMembers); | |
| 603 | + | |
| 604 | + foreach ($teamMembers as $memberId) { | |
| 605 | + if (!get_user_by('ID', $memberId)) { | |
| 606 | + return $this->sendError([ | |
| 607 | + 'message' => __('Invalid Team Member', 'fluent-booking') | |
| 608 | + ], 422); | |
| 609 | + } | |
| 610 | + } | |
| 611 | + | |
| 612 | + if ($teamMembers && !PermissionManager::canAssignHosts($teamMembers, $calendar->getMemberIds())) { | |
| 613 | + return $this->sendError([ | |
| 614 | + 'message' => __('You are not allowed to create a calendar for another user', 'fluent-booking') | |
| 615 | + ], 403); | |
| 616 | + } | |
| 617 | + | |
| 475 | 618 | $availability = AvailabilityService::getDefaultSchedule($calendar->user_id); |
| 476 | 619 | |
| 477 | 620 | $slotData = [ |
| 478 | - 'title' => $slot['title'], | |
| 621 | + 'title' => sanitize_text_field($slot['title']), | |
| 479 | 622 | 'slug' => Helper::generateSlotSlug($slot['duration'] . 'min', $calendar), |
| 480 | 623 | 'calendar_id' => $calendar->id, |
| 481 | 624 | 'user_id' => $calendar->user_id, |
| 482 | 625 | 'duration' => (int)$slot['duration'], |
| @@ -482,10 +625,10 @@ | ||
| 482 | 625 | 'duration' => (int)$slot['duration'], |
| 483 | 626 | 'description' => wp_kses_post(Arr::get($slot, 'description')), |
| 484 | 627 | 'settings' => [ |
| 485 | 628 | 'schedule_type' => sanitize_text_field($slot['settings']['schedule_type']), |
| 486 | - 'weekly_schedules' => SanitizeService::weeklySchedules($slot['settings']['weekly_schedules'], $calendar->author_timezone, 'UTC'), | |
| 487 | - 'date_overrides' => SanitizeService::slotDateOverrides(Arr::get($slot['settings'], 'date_overrides', []), $calendar->author_timezone, 'UTC'), | |
| 629 | + 'weekly_schedules' => SanitizeService::weeklySchedules($slot['settings']['weekly_schedules'], $calendar->author_timezone, 'UTC', true), | |
| 630 | + 'date_overrides' => SanitizeService::slotDateOverrides(Arr::get($slot['settings'], 'date_overrides', []), $calendar->author_timezone, 'UTC', null, true), | |
| 488 | 631 | 'range_type' => sanitize_text_field(Arr::get($slot['settings'], 'range_type')), |
| 489 | 632 | 'range_days' => (int)(Arr::get($slot['settings'], 'range_days', 60)) ?: 60, |
| 490 | 633 | 'range_date_between' => SanitizeService::rangeDateBetween(Arr::get($slot['settings'], 'range_date_between', ['', ''])), |
| 491 | 634 | 'schedule_conditions' => SanitizeService::scheduleConditions(Arr::get($slot['settings'], 'schedule_conditions', [])), |
| @@ -491,13 +634,13 @@ | ||
| 491 | 634 | 'schedule_conditions' => SanitizeService::scheduleConditions(Arr::get($slot['settings'], 'schedule_conditions', [])), |
| 492 | 635 | 'buffer_time_before' => sanitize_text_field(Arr::get($slot['settings'], 'buffer_time_before', '0')), |
| 493 | 636 | 'buffer_time_after' => sanitize_text_field(Arr::get($slot['settings'], 'buffer_time_after', '0')), |
| 494 | 637 | 'slot_interval' => sanitize_text_field(Arr::get($slot['settings'], 'slot_interval', '')), |
| 495 | - 'team_members' => array_map('intval', Arr::get($slot['settings'], 'team_members', [])) | |
| 638 | + 'team_members' => $teamMembers | |
| 496 | 639 | ], |
| 497 | 640 | 'status' => SanitizeService::checkCollection($slot['status'], ['active', 'draft'], 'active'), |
| 498 | 641 | 'color_schema' => sanitize_text_field(Arr::get($slot, 'color_schema', '#0099ff')), |
| 499 | - 'event_type' => sanitize_text_field(Arr::get($slot, 'event_type')), | |
| 642 | + 'event_type' => SanitizeService::checkCollection(sanitize_text_field(Arr::get($slot, 'event_type')), CalendarSlot::getEventTypes(), 'single'), | |
| 500 | 643 | 'availability_type' => 'existing_schedule', |
| 501 | 644 | 'availability_id' => $availability ? $availability->id : null, |
| 502 | 645 | 'location_type' => sanitize_text_field(Arr::get($slot, 'location_type')), |
| 503 | 646 | 'location_settings' => SanitizeService::locationSettings(Arr::get($slot, 'location_settings', [])), |
| @@ -604,10 +747,10 @@ | ||
| 604 | 747 | $event = CalendarSlot::where('calendar_id', $calendarId)->findOrFail($eventId); |
| 605 | 748 | |
| 606 | 749 | $eventSettings = [ |
| 607 | 750 | 'schedule_type' => sanitize_text_field(Arr::get($data, 'schedule_type')), |
| 608 | - 'weekly_schedules' => SanitizeService::weeklySchedules(Arr::get($data, 'weekly_schedules'), $event->calendar->author_timezone, 'UTC'), | |
| 609 | - 'date_overrides' => SanitizeService::slotDateOverrides(Arr::get($data, 'date_overrides', []), $event->calendar->author_timezone, 'UTC'), | |
| 751 | + 'weekly_schedules' => SanitizeService::weeklySchedules(Arr::get($data, 'weekly_schedules'), $event->calendar->author_timezone, 'UTC', true), | |
| 752 | + 'date_overrides' => SanitizeService::slotDateOverrides(Arr::get($data, 'date_overrides', []), $event->calendar->author_timezone, 'UTC', null, true), | |
| 610 | 753 | 'range_type' => sanitize_text_field(Arr::get($data, 'range_type')), |
| 611 | 754 | 'range_days' => (int)(Arr::get($data, 'range_days', 60)) ?: 60, |
| 612 | 755 | 'range_date_between' => SanitizeService::rangeDateBetween(Arr::get($data, 'range_date_between', ['', ''])), |
| 613 | 756 | 'common_schedule' => Arr::isTrue($data, 'common_schedule', false) |
| @@ -612,19 +755,69 @@ | ||
| 612 | 755 | 'range_date_between' => SanitizeService::rangeDateBetween(Arr::get($data, 'range_date_between', ['', ''])), |
| 613 | 756 | 'common_schedule' => Arr::isTrue($data, 'common_schedule', false) |
| 614 | 757 | ]; |
| 615 | 758 | |
| 759 | + $hostsSchedules = []; | |
| 760 | + | |
| 616 | 761 | if ($event->isTeamEvent()) { |
| 617 | - $eventSettings['hosts_schedules'] = array_map('intval', array_combine( | |
| 762 | + $hostsSchedules = array_map('intval', array_combine( | |
| 618 | 763 | array_map('intval', array_keys(Arr::get($data, 'hosts_schedules', []))), |
| 619 | 764 | array_map('intval', Arr::get($data, 'hosts_schedules', [])) |
| 620 | 765 | )); |
| 621 | 766 | } |
| 622 | 767 | |
| 768 | + $availabilityId = (int)Arr::get($data, 'availability_id'); | |
| 769 | + $availabilityType = SanitizeService::checkCollection(Arr::get($data, 'availability_type'), ['existing_schedule', 'custom']); | |
| 770 | + | |
| 771 | + $submittedIds = array_values(array_filter(array_unique(array_merge( | |
| 772 | + [$availabilityType === 'existing_schedule' ? $availabilityId : 0], | |
| 773 | + array_values($hostsSchedules) | |
| 774 | + )))); | |
| 775 | + | |
| 776 | + $usableIds = []; | |
| 777 | + $scheduleOwners = []; | |
| 778 | + | |
| 779 | + if ($submittedIds) { | |
| 780 | + $usableIds = array_map('intval', AvailabilityService::usableAvailabilityQuery() | |
| 781 | + ->whereIn('id', $submittedIds)->pluck('id')->toArray()); | |
| 782 | + | |
| 783 | + $scheduleOwners = array_map('intval', Availability::whereIn('id', $submittedIds) | |
| 784 | + ->pluck('object_id', 'id')->toArray()); | |
| 785 | + } | |
| 786 | + | |
| 787 | + foreach ($hostsSchedules as $hostId => $scheduleId) { | |
| 788 | + if (($scheduleOwners[$scheduleId] ?? 0) === (int)$hostId) { | |
| 789 | + continue; | |
| 790 | + } | |
| 791 | + | |
| 792 | + if (!in_array($scheduleId, $usableIds, true)) { | |
| 793 | + return $this->sendError([ | |
| 794 | + 'message' => __('You are not allowed to use the selected schedule', 'fluent-booking') | |
| 795 | + ], 403); | |
| 796 | + } | |
| 797 | + } | |
| 798 | + | |
| 799 | + if ($hostsSchedules) { | |
| 800 | + $eventSettings['hosts_schedules'] = $hostsSchedules; | |
| 801 | + } | |
| 802 | + | |
| 803 | + $eventHostIds = array_map('intval', array_merge( | |
| 804 | + $event->getHostIds(), | |
| 805 | + [$event->user_id, $event->calendar->user_id] | |
| 806 | + )); | |
| 807 | + | |
| 808 | + if ($availabilityType === 'existing_schedule' && $availabilityId | |
| 809 | + && !in_array($availabilityId, $usableIds, true) | |
| 810 | + && !in_array($scheduleOwners[$availabilityId] ?? 0, $eventHostIds, true)) { | |
| 811 | + return $this->sendError([ | |
| 812 | + 'message' => __('You are not allowed to use the selected schedule', 'fluent-booking') | |
| 813 | + ], 403); | |
| 814 | + } | |
| 815 | + | |
| 623 | 816 | $event->settings = $eventSettings; |
| 624 | 817 | |
| 625 | - $event->availability_id = (int)Arr::get($data, 'availability_id'); | |
| 626 | - $event->availability_type = SanitizeService::checkCollection(Arr::get($data, 'availability_type'), ['existing_schedule', 'custom']); | |
| 818 | + $event->availability_id = $availabilityId; | |
| 819 | + $event->availability_type = $availabilityType; | |
| 627 | 820 | |
| 628 | 821 | $event->save(); |
| 629 | 822 | |
| 630 | 823 | return [ |
| @@ -686,12 +879,28 @@ | ||
| 686 | 879 | public function cloneCalendarEvent(Request $request, $calendarId, $eventId) |
| 687 | 880 | { |
| 688 | 881 | $newCalendarId = intval($request->get('new_calendar_id')) ?: $calendarId; |
| 689 | 882 | |
| 883 | + if (!PermissionManager::canWriteCalendar($newCalendarId)) { | |
| 884 | + return $this->sendError([ | |
| 885 | + 'message' => __('You do not have permission to write to the destination calendar.', 'fluent-booking') | |
| 886 | + ], 403); | |
| 887 | + } | |
| 888 | + | |
| 690 | 889 | $calendar = Calendar::findOrFail($newCalendarId); |
| 691 | 890 | |
| 692 | 891 | $originalEvent = CalendarSlot::with('event_metas')->where('calendar_id', $calendarId)->findOrFail($eventId); |
| 693 | 892 | |
| 893 | + $teamMembers = Arr::get($originalEvent->settings, 'team_members', []); | |
| 894 | + | |
| 895 | + // Cloning into another calendar carries the source hosts along with it. | |
| 896 | + if ($teamMembers && $calendar->id != $calendarId | |
| 897 | + && !PermissionManager::canAssignHosts($teamMembers, $calendar->getMemberIds())) { | |
| 898 | + return $this->sendError([ | |
| 899 | + 'message' => __('You are not allowed to create a calendar for another user', 'fluent-booking') | |
| 900 | + ], 403); | |
| 901 | + } | |
| 902 | + | |
| 694 | 903 | $clonedEvent = $originalEvent->replicate(); |
| 695 | 904 | |
| 696 | 905 | $clonedEvent->hash = null; |
| 697 | 906 | |
| @@ -740,8 +949,14 @@ | ||
| 740 | 949 | $calendarEvent = CalendarSlot::where('calendar_id', $calendarId)->findOrFail($eventId); |
| 741 | 950 | |
| 742 | 951 | $fromEventId = intval($request->get('from_event_id')); |
| 743 | 952 | |
| 953 | + if (!$fromEventId || !PermissionManager::canUpdateCalendarEvent($fromEventId)) { | |
| 954 | + return $this->sendError([ | |
| 955 | + 'message' => __('You do not have permission to clone from the selected event.', 'fluent-booking') | |
| 956 | + ], 403); | |
| 957 | + } | |
| 958 | + | |
| 744 | 959 | $fromCalendarEvent = CalendarSlot::findOrFail($fromEventId); |
| 745 | 960 | |
| 746 | 961 | $notification = $fromCalendarEvent->getNotifications(true); |
| 747 | 962 | |
| @@ -827,60 +1042,39 @@ | ||
| 827 | 1042 | $calendarEvent = CalendarSlot::where('calendar_id', $calendarId)->findOrFail($eventId); |
| 828 | 1043 | |
| 829 | 1044 | $bookingFields = $request->get('booking_fields'); |
| 830 | 1045 | |
| 831 | - $optionRequiredFields = ['dropdown', 'radio', 'checkbox-group', 'multi-select']; | |
| 1046 | + $formattedFields = BookingFieldService::sanitizeBookingFields($bookingFields, $calendarEvent); | |
| 832 | 1047 | |
| 833 | - $formattedFields = []; | |
| 1048 | + $calendarEvent->setBookingFields($formattedFields); | |
| 834 | 1049 | |
| 835 | - $textFields = ['type', 'name', 'label', 'placeholder', 'limit', 'help_text', 'date_format', 'min_date', 'max_date']; | |
| 836 | - $booleanFields = ['enabled', 'required', 'system_defined', 'disable_alter', 'is_sms_number']; | |
| 1050 | + return [ | |
| 1051 | + 'message' => __('Fields has been updated', 'fluent-booking') | |
| 1052 | + ]; | |
| 1053 | + } | |
| 837 | 1054 | |
| 838 | - foreach ($bookingFields as $value) { | |
| 839 | - if (empty($value['name'])) { | |
| 840 | - $value['name'] = BookingFieldService::generateFieldName($calendarEvent, $value['label']); | |
| 841 | - } else { | |
| 842 | - $value['name'] = BookingFieldService::maybeGenerateFieldName($calendarEvent, $value); | |
| 843 | - } | |
| 1055 | + public function getEventPaymentSettings($calendarId, $eventId) | |
| 1056 | + { | |
| 1057 | + $calendarEvent = CalendarSlot::where('calendar_id', $calendarId)->findOrFail($eventId); | |
| 844 | 1058 | |
| 845 | - $textValues = array_map('sanitize_text_field', Arr::only($value, $textFields)); | |
| 1059 | + $config = [ | |
| 1060 | + 'native_enabled' => Helper::isPaymentEnabled(), | |
| 1061 | + 'stripe_configured' => Helper::isPaymentConfigured('stripe'), | |
| 1062 | + 'paypal_configured' => Helper::isPaymentConfigured('paypal'), | |
| 1063 | + 'offline_configured' => Helper::isPaymentConfigured('offline'), | |
| 1064 | + 'native_config_link' => Helper::getAppBaseUrl('settings/payment-methods/stripe'), | |
| 1065 | + 'woo_config_link' => Helper::getAppBaseUrl('settings/configure-integrations/global-modules'), | |
| 1066 | + 'has_cart' => defined('FLUENTCART_VERSION'), | |
| 1067 | + 'has_woo' => defined('WC_PLUGIN_FILE'), | |
| 1068 | + 'woo_enabled' => defined('WC_PLUGIN_FILE') && Helper::isModuleEnabled('woo') | |
| 1069 | + ]; | |
| 846 | 1070 | |
| 847 | - $booleanValues = array_map(function ($valueItem) { | |
| 848 | - return $valueItem === true || $valueItem === 'true' || $valueItem == 1; | |
| 849 | - }, Arr::only($value, $booleanFields)); | |
| 1071 | + $data = apply_filters('fluent_booking/payment/get_payment_settings', [ | |
| 1072 | + 'settings' => $calendarEvent->getPaymentSettings(), | |
| 1073 | + 'config' => $config | |
| 1074 | + ], $calendarEvent); | |
| 850 | 1075 | |
| 851 | - $formattedField = array_merge($textValues, $booleanValues); | |
| 852 | - | |
| 853 | - $formattedField['index'] = (int)Arr::get($value, 'index'); | |
| 854 | - if (in_array(Arr::get($value, 'type'), $optionRequiredFields)) { | |
| 855 | - $sanitizedOptions = array_map('sanitize_text_field', Arr::get($value, 'options')); | |
| 856 | - $formattedField['options'] = $sanitizedOptions; | |
| 857 | - } | |
| 858 | - if ($value['type'] == 'payment' && $calendarEvent->type === 'paid') { | |
| 859 | - $formattedField['payment_items'] = Arr::get($value, 'payment_items'); | |
| 860 | - $formattedField['currency_sign'] = CurrenciesHelper::getGlobalCurrencySign(); | |
| 861 | - } | |
| 862 | - if ($value['type'] == 'file') { | |
| 863 | - $formattedField['max_file_allow'] = intval(Arr::get($value, 'max_file_allow')); | |
| 864 | - $formattedField['allow_file_types'] = array_map('sanitize_text_field', Arr::get($value, 'allow_file_types')); | |
| 865 | - $formattedField['file_size_value'] = intval(Arr::get($value, 'file_size_value')); | |
| 866 | - $formattedField['file_size_unit'] = SanitizeService::checkCollection(Arr::get($value, 'file_size_unit'), ['kb','mb']); | |
| 867 | - } | |
| 868 | - if ($value['type'] == 'hidden') { | |
| 869 | - $formattedField['default_value'] = sanitize_text_field(Arr::get($value, 'default_value')); | |
| 870 | - } | |
| 871 | - if ($value['type'] == 'terms-and-conditions') { | |
| 872 | - $formattedField['terms_and_conditions'] = wp_kses_post(Arr::get($value, 'terms_and_conditions')); | |
| 873 | - } | |
| 874 | - | |
| 875 | - $formattedFields[] = $formattedField; | |
| 876 | - } | |
| 877 | - | |
| 878 | - $calendarEvent->setBookingFields($formattedFields); | |
| 879 | - | |
| 880 | - return [ | |
| 881 | - 'message' => __('Fields has been updated', 'fluent-booking') | |
| 882 | - ]; | |
| 1076 | + return $data; | |
| 883 | 1077 | } |
| 884 | 1078 | |
| 885 | 1079 | public function deleteCalendarEvent(Request $request, $calendarId, $calendarEventId) |
| 886 | 1080 | { |