ifnex/04_Laravel/app/Http/Controllers/Admin/CommitmentFileController.php
Kazem Alghasi 0209b6b32e feat(commitment-forms): implement end-to-end management and secure file access
Integrate a complete workflow for commitment forms including secure template downloads, customer uploads via WordPress AJAX, and administrative verification with automated notifications.

- Implement `downloadTemplate` and `downloadSigned` logic in `CommitmentFormController` to replace public symlinks with ownership-verified routes.
- Add `CommitmentFormVerifiedNotification` and `CommitmentFormRejectedNotification` to alert customers of status changes.
- Enhance WordPress bridge with AJAX-driven form listing, status badges, and upload capabilities.
- Update Filament `CommitmentFormsRelationManager` to provide better visibility into form directions and descriptions while restricting status edits to specific actions.
- Refactor Laravel 11 bootstrap configuration to handle guest redirection for API and web routes correctly.
- Add administrative controllers for secure file access within the admin panel.
2026-10-03 05:58:59 +03:30

70 lines
2.5 KiB
PHP

<?php
namespace App\Http\Controllers\Admin;
use App\Http\Controllers\Controller;
use App\Models\CommitmentForm;
use App\Models\Shipment;
use App\Models\ShipmentCommitmentForm;
use Illuminate\Support\Facades\Storage;
/**
* دانلود امن فایل‌های تعهدنامه برای پنل ادمین (Filament).
*
* فایل‌های قالب روی دیسک public و فایل‌های امضاشده روی دیسک secure ذخیره می‌شوند؛
* دیسک secure هیچ URL عمومی ندارد و فایل فقط از طریق این روت (با مجوز پنل) استریم می‌شود.
*/
class CommitmentFileController extends Controller
{
/**
* دانلود قالب خام تعهدنامه برای یک سفارش.
* GET /admin/shipments/{shipment}/commitment-forms/{form}/template
*/
public function template(Shipment $shipment, CommitmentForm $form)
{
$this->authorizePanel();
if (!$form->file_path || !Storage::disk('public')->exists($form->file_path)) {
abort(404, 'فایل قالب یافت نشد.');
}
$ext = pathinfo($form->file_path, PATHINFO_EXTENSION);
return Storage::disk('public')->download(
$form->file_path,
'template-' . $form->id . '-' . $shipment->awb_no . '.' . $ext
);
}
/**
* دانلود فایل امضاشده‌ای که مشتری آپلود کرده است.
* GET /admin/shipments/{shipment}/commitment-forms/{record}/signed
*/
public function signed(Shipment $shipment, ShipmentCommitmentForm $record)
{
$this->authorizePanel();
if ($record->shipment_id !== $shipment->id) {
abort(404);
}
if (!$record->uploaded_file_path || !Storage::disk('secure')->exists($record->uploaded_file_path)) {
abort(404, 'فایل امضاشده یافت نشد.');
}
return Storage::disk('secure')->download(
$record->uploaded_file_path,
'commitment-' . $record->commitment_form_id . '-' . $shipment->awb_no . '.' . $record->uploaded_file_type
);
}
/**
* فقط کاربران پنل ادمین (super_admin/admin/staff) مجاز به دانلود هستند.
* همان منطق User::canAccessPanel — بدون نیاز به نمونه پنل (بیرون از کانتکست Filament)
*/
private function authorizePanel(): void
{
abort_unless(auth()->user()?->hasAnyRole(['super_admin', 'admin', 'staff']), 403);
}
}