← All changes
|
app/Http/Requests/FrontendRequests/CouponRequest.php
+22
-4
1.3.21
→
1.7.1
View file →
| @@ -1,8 +1,9 @@ | ||
| 1 | 1 | <?php |
| 2 | 2 | |
| 3 | 3 | namespace FluentCart\App\Http\Requests\FrontendRequests; |
| 4 | 4 | |
| 5 | +use FluentCart\App\Helpers\CartHelper; | |
| 5 | 6 | use FluentCart\Framework\Foundation\RequestGuard; |
| 6 | 7 | |
| 7 | 8 | class CouponRequest extends RequestGuard |
| 8 | 9 | { |
| @@ -21,9 +22,9 @@ | ||
| 21 | 22 | "order_items.*.order_id" => 'numeric|min:1', |
| 22 | 23 | "order_items.*.post_id" => 'numeric|min:1', |
| 23 | 24 | "order_items.*.variation_id" => 'numeric|min:1', |
| 24 | 25 | "order_items.*.type" => 'nullable|sanitizeText|maxLength:100', |
| 25 | - "order_items.*.quantity" => 'numeric|min:1', | |
| 26 | + "order_items.*.quantity" => 'numeric|min:1|max:' . CartHelper::maxQuantity(), | |
| 26 | 27 | "order_items.*.title" => 'nullable|sanitizeText|maxLength:100', |
| 27 | 28 | "order_items.*.price" => 'numeric', |
| 28 | 29 | "order_items.*.unit_price" => 'numeric', |
| 29 | 30 | "order_items.*.item_cost" => 'numeric', |
| @@ -28,14 +29,21 @@ | ||
| 28 | 29 | "order_items.*.unit_price" => 'numeric', |
| 29 | 30 | "order_items.*.item_cost" => 'numeric', |
| 30 | 31 | "order_items.*.item_total" => 'numeric', |
| 31 | 32 | "order_items.*.tax_amount" => 'numeric', |
| 33 | + // nullable: the admin UI serializes variation line items with subtotal null | |
| 34 | + // (cartService.js computes unit_price*quantity - cost, and productService.js | |
| 35 | + // never sets `cost` on variation rows, so NaN JSON-encodes as null). The bare | |
| 36 | + // numeric rule 422'd every coupon apply on such orders. CouponServiceAdmin | |
| 37 | + // falls back to unit_price*quantity for non-numeric subtotals, keeping the | |
| 38 | + // min/max purchase-amount enforcement this field was whitelisted for. | |
| 39 | + "order_items.*.subtotal" => 'nullable|numeric', | |
| 32 | 40 | "order_items.*.discount_total" => 'numeric', |
| 33 | 41 | "order_items.*.total" => 'numeric', |
| 34 | 42 | "order_items.*.line_total" => 'numeric', |
| 35 | 43 | "order_items.*.cart_index" => 'nullable|numeric', |
| 36 | 44 | "order_items.*.rate" => 'nullable|numeric', |
| 37 | - "order_items.*.line_meta" => 'nullable|sanitizeTextArea', | |
| 45 | + "order_items.*.line_meta" => 'nullable', | |
| 38 | 46 | "order_items.*.other_info" => 'nullable|array', |
| 39 | 47 | 'applied_coupons' => 'nullable|array', |
| 40 | 48 | |
| 41 | 49 | 'customer_email' => 'nullable|sanitizeText|email', |
| @@ -74,15 +82,25 @@ | ||
| 74 | 82 | "order_items.*.unit_price" => 'floatval', |
| 75 | 83 | "order_items.*.item_cost" => 'floatval', |
| 76 | 84 | "order_items.*.item_total" => 'floatval', |
| 77 | 85 | "order_items.*.tax_amount" => 'floatval', |
| 86 | + // floatval(null) would coerce to 0.0 and silently zero the items total the | |
| 87 | + // min/max purchase gates sum — keep null as null so the service layer can | |
| 88 | + // recompute it from unit_price * quantity instead. | |
| 89 | + "order_items.*.subtotal" => function ($value) { | |
| 90 | + return is_numeric($value) ? floatval($value) : null; | |
| 91 | + }, | |
| 78 | 92 | "order_items.*.discount_total" => 'floatval', |
| 79 | 93 | "order_items.*.total" => 'floatval', |
| 80 | 94 | "order_items.*.line_total" => 'floatval', |
| 81 | 95 | "order_items.*.cart_index" => 'intval', |
| 82 | 96 | "order_items.*.rate" => 'floatval', |
| 83 | - "order_items.*.line_meta" => 'sanitize_text_field', | |
| 84 | - "order_items.*.other_info" => 'sanitize_text_field', | |
| 97 | + "order_items.*.line_meta" => function ($value) { | |
| 98 | + return is_array($value) ? $value : sanitize_text_field((string) $value); | |
| 99 | + }, | |
| 100 | + "order_items.*.other_info" => function ($value) { | |
| 101 | + return is_array($value) ? $value : sanitize_text_field((string) $value); | |
| 102 | + }, | |
| 85 | 103 | 'applied_coupons.*' => 'intval', |
| 86 | 104 | |
| 87 | 105 | 'customer_email' => function ($value) { |
| 88 | 106 | if(empty($value)) { |