← All changes
|
app/Http/Controllers/FrontendControllers/ProductReviewFrontendController.php
+11
-6
1.7.0
→
1.7.1
View file →
| @@ -78,19 +78,24 @@ | ||
| 78 | 78 | 'page' => max(1, intval($request->get('page', 1))), |
| 79 | 79 | 'sort_by' => $data['sort_by'] ?? 'created_at', |
| 80 | 80 | 'sort_order' => $data['sort_order'] ?? 'DESC', |
| 81 | 81 | 'per_page' => $perPage, |
| 82 | - // The list's floor, read out of the composition this request names | |
| 83 | - // rather than off the query string. It is the editor's setting, | |
| 84 | - // not the reader's: taken from the request, anyone could ask for | |
| 85 | - // the one-star reviews a shop had chosen not to publish here. | |
| 82 | + // A signed per-instance floor takes precedence over the legacy | |
| 83 | + // composition default. Neither changes public-review permissions. | |
| 86 | 84 | 'min_rating' => ProductReviewListBlockEditor::minRatingOfComposition( |
| 87 | - $request->get('client_id', '') | |
| 85 | + $request->get('client_id', ''), | |
| 86 | + (int) $postId, | |
| 87 | + (string) $request->get('rating_token', '') | |
| 88 | 88 | ), |
| 89 | 89 | ]; |
| 90 | 90 | |
| 91 | + // ratings=5,4 from the star chips; the single rating param still works. | |
| 92 | + $ratings = ProductReviewService::ratingList($request->get('ratings', '')); | |
| 91 | 93 | $rating = !empty($data['rating']) ? (int) $data['rating'] : null; |
| 92 | - if ($rating && $rating >= 1 && $rating <= 5) { | |
| 94 | + | |
| 95 | + if ($ratings) { | |
| 96 | + $params['ratings'] = $ratings; | |
| 97 | + } elseif ($rating && $rating >= 1 && $rating <= 5) { | |
| 93 | 98 | $params['rating'] = $rating; |
| 94 | 99 | } |
| 95 | 100 | |
| 96 | 101 | if (!empty($data['has_media'])) { |