| @@ -1,9 +1,12 @@ | ||
| 1 | 1 | <?php |
| 2 | 2 | |
| 3 | 3 | namespace FluentCart\App\Http\Requests; |
| 4 | 4 | |
| 5 | +use FluentCart\App\Helpers\CartHelper; | |
| 6 | +use FluentCart\App\Helpers\Helper; | |
| 5 | 7 | use FluentCart\Framework\Foundation\RequestGuard; |
| 8 | +use FluentCart\Framework\Support\Arr; | |
| 6 | 9 | |
| 7 | 10 | class OrderRequest extends RequestGuard |
| 8 | 11 | { |
| 9 | 12 | |
| @@ -25,9 +28,13 @@ | ||
| 25 | 28 | 'discount_tax' => 'numeric', |
| 26 | 29 | 'manual_discount_total' => 'numeric', |
| 27 | 30 | 'coupon_discount_total' => 'numeric', |
| 28 | 31 | 'shipping_tax' => 'numeric', |
| 29 | - 'shipping_total' => 'numeric', | |
| 32 | + // min/max close the silent-corruption window: 1e19 passes `numeric` | |
| 33 | + // but wraps to a negative BIGINT through a float-to-int cast, and a | |
| 34 | + // negative shipping charge has no meaning. The bound matches the | |
| 35 | + // Helper::roundCent() guard (float's exact-integer range). | |
| 36 | + 'shipping_total' => 'numeric|min:0|max:9000000000000000', | |
| 30 | 37 | 'tax_total' => 'numeric', |
| 31 | 38 | 'total_amount' => 'numeric', |
| 32 | 39 | 'rate' => 'numeric', |
| 33 | 40 | 'note' => 'nullable|sanitizeTextArea|maxLength:5000', |
| @@ -45,9 +52,9 @@ | ||
| 45 | 52 | "order_items.*.variation_id" => 'numeric|min:1', |
| 46 | 53 | "order_items.*.object_id" => 'numeric|min:1', |
| 47 | 54 | "order_items.*.fulfillment_type" => 'nullable|sanitizeText', |
| 48 | 55 | "order_items.*.payment_type" => 'nullable|sanitizeText|maxLength:100', |
| 49 | - "order_items.*.quantity" => 'numeric|min:1', | |
| 56 | + "order_items.*.quantity" => 'numeric|min:1|max:' . CartHelper::maxQuantity(), | |
| 50 | 57 | "order_items.*.post_title" => 'nullable|sanitizeText|maxLength:255', |
| 51 | 58 | "order_items.*.title" => 'nullable|sanitizeText|maxLength:255', |
| 52 | 59 | "order_items.*.price" => 'numeric', |
| 53 | 60 | "order_items.*.unit_price" => 'numeric', |
| @@ -73,30 +80,65 @@ | ||
| 73 | 80 | "shipping.*.type" => 'nullable|sanitizeText|maxLength:100', |
| 74 | 81 | "shipping.*.rate_name" => 'nullable|sanitizeText|maxLength:100', |
| 75 | 82 | "shipping.*.custom_price" => 'nullable|numeric', |
| 76 | 83 | |
| 77 | - 'deletedItems' => 'nullable|array', | |
| 84 | + 'deletedItems' => 'nullable|array', | |
| 85 | + 'tax_behavior' => 'nullable|numeric|min:0', | |
| 86 | + 'tax_lines' => 'nullable|array', | |
| 87 | + 'tax_lines.*.rate_id' => 'nullable|numeric|min:0', | |
| 88 | + 'tax_lines.*.tax_amount' => 'nullable|numeric|min:0', | |
| 89 | + 'tax_lines.*.label' => 'nullable|sanitizeText', | |
| 90 | + 'tax_lines.*.is_compound'=> 'nullable', | |
| 78 | 91 | |
| 79 | - 'applied_coupon' => 'nullable|array', | |
| 80 | - "applied_coupon.*.id" => 'nullable|numeric|min:1', | |
| 81 | - "applied_coupon.*.order_id" => 'nullable|numeric|min:1', | |
| 82 | - "applied_coupon.*.coupon_id" => 'required|numeric|min:1', | |
| 83 | - //"applied_coupon.*.title" => 'required|string|max:100', | |
| 84 | - "applied_coupon.*.code" => 'required|sanitizeText|maxLength:100', | |
| 85 | - //"applied_coupon.*.status" => 'required|string|max:100', | |
| 86 | - //"applied_coupon.*.type" => 'required|string|max:100', | |
| 87 | - "applied_coupon.*.amount" => 'nullable|numeric', | |
| 88 | - "applied_coupon.*.discounted_amount" => 'required|numeric', | |
| 89 | - "applied_coupon.*.discount" => 'nullable|numeric', | |
| 90 | - "applied_coupon.*.stackable" => 'required|numeric', | |
| 91 | - "applied_coupon.*.priority" => 'nullable|numeric', | |
| 92 | - "applied_coupon.*.max_uses" => 'nullable|numeric', | |
| 93 | - "applied_coupon.*.use_count" => 'nullable|numeric', | |
| 94 | - "applied_coupon.*.max_per_customer" => 'nullable|numeric|min:1', | |
| 95 | - "applied_coupon.*.min_purchase_amount" => 'nullable|numeric', | |
| 96 | - "applied_coupon.*.max_discount_amount" => 'nullable|numeric', | |
| 97 | - "applied_coupon.*.notes" => 'nullable|sanitizeTextArea|maxLength:100', | |
| 98 | - 'trigger' => 'nullable|string', | |
| 92 | + // `applied_coupon` is the admin order screen handing back, untouched, what | |
| 93 | + // POST coupons/apply returned: a map KEYED BY COUPON CODE whose rows are | |
| 94 | + // CouponServiceAdmin discount data (see ensureCouponExistInDiscountData()), | |
| 95 | + // NOT fct_applied_coupons rows. AdminOrderProcessor::insertAppliedCoupons() | |
| 96 | + // reads the code keys plus `id` and `discount` and builds its insert rows | |
| 97 | + // from the Coupon model, so those two are the whole load-bearing contract; | |
| 98 | + // everything else in the map is display metadata. | |
| 99 | + // | |
| 100 | + // The previous rules described fct_applied_coupons columns (coupon_id, code, | |
| 101 | + // discounted_amount, stackable) that no caller has ever sent. They were inert | |
| 102 | + // while the validator skipped absent wildcard children, and became a hard | |
| 103 | + // 422 on every coupon order once it started materializing them. | |
| 104 | + // | |
| 105 | + // The per-row closure is the backstop, not decoration: whether the wildcard | |
| 106 | + // rules below can fire at all depends on the validator materializing absent | |
| 107 | + // children, so on its own `applied_coupon.*.id => required` is silently | |
| 108 | + // unenforced on older framework builds. insertAppliedCoupons() subscripts | |
| 109 | + // ['id'] unguarded, so an entry without one writes a null coupon_id. | |
| 110 | + 'applied_coupon' => ['nullable', 'array', function ($attribute, $value) { | |
| 111 | + if (!is_array($value)) { | |
| 112 | + return null; // the `array` rule already reports this | |
| 113 | + } | |
| 114 | + | |
| 115 | + foreach ($value as $code => $row) { | |
| 116 | + $couponId = is_array($row) ? Arr::get($row, 'id') : null; | |
| 117 | + | |
| 118 | + if (!is_numeric($couponId) || (int) $couponId < 1) { | |
| 119 | + return sprintf( | |
| 120 | + /* translators: %1$s: the coupon code the admin applied to the order. */ | |
| 121 | + __('The applied coupon "%1$s" is missing its coupon id.', 'fluent-cart'), | |
| 122 | + sanitize_text_field((string) $code) | |
| 123 | + ); | |
| 124 | + } | |
| 125 | + } | |
| 126 | + | |
| 127 | + return null; | |
| 128 | + }], | |
| 129 | + "applied_coupon.*.id" => 'required|numeric|min:1', | |
| 130 | + // Bounded for the same reason as shipping_total above: sanitize() routes this | |
| 131 | + // through Helper::roundCent(), which throws outside float's exact-integer | |
| 132 | + // range, and a negative coupon discount has no meaning. | |
| 133 | + "applied_coupon.*.discount" => 'required|numeric|min:0|max:9000000000000000', | |
| 134 | + "applied_coupon.*.title" => 'nullable|sanitizeText|maxLength:192', | |
| 135 | + "applied_coupon.*.type" => 'nullable|sanitizeText|maxLength:100', | |
| 136 | + "applied_coupon.*.amount" => 'nullable|numeric', | |
| 137 | + "applied_coupon.*.actual_amount" => 'nullable|numeric', | |
| 138 | + "applied_coupon.*.unit_amount" => 'nullable|numeric', | |
| 139 | + "applied_coupon.*.actual_quantity" => 'nullable|numeric', | |
| 140 | + 'trigger' => 'nullable|string', | |
| 99 | 141 | ]; |
| 100 | 142 | } |
| 101 | 143 | |
| 102 | 144 | |
| @@ -132,13 +174,24 @@ | ||
| 132 | 174 | 'discount_tax' => 'floatval', |
| 133 | 175 | 'manual_discount_total' => 'floatval', |
| 134 | 176 | 'coupon_discount_total' => 'floatval', |
| 135 | 177 | 'shipping_tax' => 'floatval', |
| 136 | - 'shipping_total' => 'floatval', | |
| 178 | + // Cents column: normalize at the boundary so every consumer of this request | |
| 179 | + // receives a whole-cent int. floatval alone let a client-computed 19.99 * 100 | |
| 180 | + // arrive as 1998.9999999999998, which any later int cast would truncate. | |
| 181 | + // | |
| 182 | + // Wrapped in a closure, NOT passed as [Helper::class, 'roundCent']: an array | |
| 183 | + // value in this map is a LIST of callbacks, iterated one by one | |
| 184 | + // (vendor/wpfluent/framework/src/WPFluent/Support/Sanitizer.php:456-464), so the | |
| 185 | + // array-callable form would try to call Helper() as a function. | |
| 186 | + 'shipping_total' => function ($value) { | |
| 187 | + return Helper::roundCent($value); | |
| 188 | + }, | |
| 137 | 189 | 'tax_total' => 'floatval', |
| 190 | + 'tax_behavior' => 'intval', | |
| 138 | 191 | 'total_amount' => 'floatval', |
| 139 | 192 | 'rate' => 'sanitize_text_field', |
| 140 | - 'note' => 'sanitize_text_field', | |
| 193 | + 'note' => 'sanitize_textarea_field', | |
| 141 | 194 | 'uuid' => 'sanitize_text_field', |
| 142 | 195 | 'ip_address' => 'sanitize_text_field', |
| 143 | 196 | 'billing_address_id' => 'intval', |
| 144 | 197 | 'shipping_address_id' => 'intval', |
| @@ -164,9 +217,11 @@ | ||
| 164 | 217 | "order_items.*.total" => 'floatval', |
| 165 | 218 | "order_items.*.line_total" => 'floatval', |
| 166 | 219 | "order_items.*.cart_index" => 'intval', |
| 167 | 220 | "order_items.*.rate" => 'floatval', |
| 168 | - "order_items.*.line_meta" => 'sanitize_text_field', | |
| 221 | + "order_items.*.line_meta" => function ($value) { | |
| 222 | + return is_array($value) ? $value : []; | |
| 223 | + }, | |
| 169 | 224 | "order_items.*.other_info" => function ($value) { |
| 170 | 225 | return is_array($value) ? $value : []; |
| 171 | 226 | }, |
| 172 | 227 | |
| @@ -182,28 +237,33 @@ | ||
| 182 | 237 | |
| 183 | 238 | "deletedItems" => function ($value) { |
| 184 | 239 | return is_array($value) ? $value : []; |
| 185 | 240 | }, |
| 241 | + "tax_lines" => function ($value) { | |
| 242 | + return is_array($value) ? $value : []; | |
| 243 | + }, | |
| 244 | + "tax_lines.*.rate_id" => 'intval', | |
| 245 | + "tax_lines.*.tax_amount" => 'intval', | |
| 246 | + "tax_lines.*.label" => 'sanitize_text_field', | |
| 247 | + "tax_lines.*.is_compound"=> function ($value) { | |
| 248 | + return (bool) $value; | |
| 249 | + }, | |
| 186 | 250 | |
| 187 | - "applied_coupon.*.id" => 'intval', | |
| 188 | - "applied_coupon.*.order_id" => 'intval', | |
| 189 | - "applied_coupon.*.coupon_id" => 'intval', | |
| 190 | - "applied_coupon.*.title" => 'sanitize_text_field', | |
| 191 | - "applied_coupon.*.discount" => 'intval', | |
| 192 | - "applied_coupon.*.code" => 'sanitize_text_field', | |
| 193 | - "applied_coupon.*.status" => 'sanitize_text_field', | |
| 194 | - "applied_coupon.*.type" => 'sanitize_text_field', | |
| 195 | - "applied_coupon.*.amount" => 'intval', | |
| 196 | - "applied_coupon.*.discounted_amount" => 'intval', | |
| 197 | - "applied_coupon.*.stackable" => 'intval', | |
| 198 | - "applied_coupon.*.priority" => 'intval', | |
| 199 | - "applied_coupon.*.max_uses" => 'intval', | |
| 200 | - "applied_coupon.*.use_count" => 'intval', | |
| 201 | - "applied_coupon.*.max_per_customer" => 'intval', | |
| 202 | - "applied_coupon.*.min_purchase_amount" => 'intval', | |
| 203 | - "applied_coupon.*.max_discount_amount" => 'intval', | |
| 204 | - "applied_coupon.*.notes" => 'sanitize_text_field', | |
| 205 | - 'trigger' => 'sanitize_text_field', | |
| 251 | + // Mirrors rules(): the coupons/apply discount-data shape, keyed by coupon code. | |
| 252 | + "applied_coupon.*.id" => 'intval', | |
| 253 | + // Already cents (CouponServiceAdmin rounds the distributed discount to two | |
| 254 | + // decimals in cents) — normalize the float artifact without scaling. A bare | |
| 255 | + // intval() here truncates, so a 9.99 discount would persist a cent short. | |
| 256 | + "applied_coupon.*.discount" => function ($value) { | |
| 257 | + return Helper::roundCent($value); | |
| 258 | + }, | |
| 259 | + "applied_coupon.*.title" => 'sanitize_text_field', | |
| 260 | + "applied_coupon.*.type" => 'sanitize_text_field', | |
| 261 | + "applied_coupon.*.amount" => 'intval', | |
| 262 | + "applied_coupon.*.actual_amount" => 'floatval', | |
| 263 | + "applied_coupon.*.unit_amount" => 'intval', | |
| 264 | + "applied_coupon.*.actual_quantity" => 'intval', | |
| 265 | + 'trigger' => 'sanitize_text_field', | |
| 206 | 266 | ]; |
| 207 | 267 | |
| 208 | 268 | } |
| 209 | 269 | } |