Commit Graph

4 Commits

Author SHA1 Message Date
Kazem Alghasi
0209b6b32e feat(commitment-forms): implement end-to-end management and secure file access
Integrate a complete workflow for commitment forms including secure template downloads, customer uploads via WordPress AJAX, and administrative verification with automated notifications.

- Implement `downloadTemplate` and `downloadSigned` logic in `CommitmentFormController` to replace public symlinks with ownership-verified routes.
- Add `CommitmentFormVerifiedNotification` and `CommitmentFormRejectedNotification` to alert customers of status changes.
- Enhance WordPress bridge with AJAX-driven form listing, status badges, and upload capabilities.
- Update Filament `CommitmentFormsRelationManager` to provide better visibility into form directions and descriptions while restricting status edits to specific actions.
- Refactor Laravel 11 bootstrap configuration to handle guest redirection for API and web routes correctly.
- Add administrative controllers for secure file access within the admin panel.
2026-10-03 05:58:59 +03:30
Kazem Alghasi
8cf407553b feat(security): implement secure file storage and shipment access control
Introduce a 'secure' filesystem disk to prevent public access to sensitive
commitment form uploads. Files are now stored in a non-public directory
and served via a protected controller method that validates user ownership.

Additionally, implement shipment authorization policies to ensure users
can only access PDF documents (AWB, invoice, labels) belonging to their
own orders.

Other changes:
- Add production environment check for Zarinpal gateway configuration
  to prevent accidental use of sandbox credentials.
- Move discount code and commitment form routes under authentication
  middleware for improved security.
- Add `ShipmentPolicy` to handle resource authorization.
2026-10-01 03:34:28 +03:30
Kazem Alghasi
7a8ff49baa feat(api): implement shipment commitment forms and document downloads
Introduce a complete workflow for managing shipment-related documents
and mandatory commitment forms between the Laravel backend and
WordPress frontend.

- Laravel:
  - Add `ShipmentCommitmentForm` model and migration to track signed
    forms per shipment.
  - Implement `CommitmentFormController` to handle fetching available
    forms and uploading signed documents.
  - Add PDF download endpoints for AWB, labels, and invoices via
    `ShipmentPdfController`.
  - Extend `User` model with notification management methods.
  - Add `FinanceOverviewWidget` for Filament dashboard.

- WordPress:
  - Implement AJAX handlers in `user-bridge.php` for PDF downloads and
    commitment form management.
  - Update `shortcodes.php` to display document download grid and
    dynamic commitment form upload interface in order details.
  - Add styling for document buttons and form status indicators in
    `ifnex-orders.css`.
2026-09-09 13:08:22 +03:30
Kazem Alghasi
02c29db696 feat(core): implement order approval flow, credit system, and import invoicing
Introduce a comprehensive set of commercial features including a multi-step
order approval workflow, customer credit management, and specialized
import service invoicing.

Key changes:
- Implement `pending_approval` and `approved` shipment statuses to allow
  staff verification before customer payment.
- Add a credit system to `User` model with `credit_limit` and `credit_used`
  to manage customer balances and debts.
- Develop a new `importInvoice` PDF generation service following the
  "Sheet ENG Invoice" specification for import services.
- Add Filament resources for managing Audit Logs, Commitment Forms,
  Customer Credits, and Shipment Checklists.
- Implement staff-specific APIs for order approval/rejection and
  customer financial status monitoring.
- Integrate Kavenegar SMS service for mobile verification and notifications.
- Add bulk tracking import functionality via CSV/Excel.
- Update WordPress bridge assets (CSS/JS) to support the new multi-step
  order form UI and updated redirection logic.
- Update deployment configurations and documentation to reflect new
  production domains and feature sets.
2026-09-03 06:04:20 +03:30