Integrate a complete workflow for commitment forms including secure template downloads, customer uploads via WordPress AJAX, and administrative verification with automated notifications. - Implement `downloadTemplate` and `downloadSigned` logic in `CommitmentFormController` to replace public symlinks with ownership-verified routes. - Add `CommitmentFormVerifiedNotification` and `CommitmentFormRejectedNotification` to alert customers of status changes. - Enhance WordPress bridge with AJAX-driven form listing, status badges, and upload capabilities. - Update Filament `CommitmentFormsRelationManager` to provide better visibility into form directions and descriptions while restricting status edits to specific actions. - Refactor Laravel 11 bootstrap configuration to handle guest redirection for API and web routes correctly. - Add administrative controllers for secure file access within the admin panel.
70 lines
2.5 KiB
PHP
70 lines
2.5 KiB
PHP
<?php
|
|
|
|
namespace App\Http\Controllers\Admin;
|
|
|
|
use App\Http\Controllers\Controller;
|
|
use App\Models\CommitmentForm;
|
|
use App\Models\Shipment;
|
|
use App\Models\ShipmentCommitmentForm;
|
|
use Illuminate\Support\Facades\Storage;
|
|
|
|
/**
|
|
* دانلود امن فایلهای تعهدنامه برای پنل ادمین (Filament).
|
|
*
|
|
* فایلهای قالب روی دیسک public و فایلهای امضاشده روی دیسک secure ذخیره میشوند؛
|
|
* دیسک secure هیچ URL عمومی ندارد و فایل فقط از طریق این روت (با مجوز پنل) استریم میشود.
|
|
*/
|
|
class CommitmentFileController extends Controller
|
|
{
|
|
/**
|
|
* دانلود قالب خام تعهدنامه برای یک سفارش.
|
|
* GET /admin/shipments/{shipment}/commitment-forms/{form}/template
|
|
*/
|
|
public function template(Shipment $shipment, CommitmentForm $form)
|
|
{
|
|
$this->authorizePanel();
|
|
|
|
if (!$form->file_path || !Storage::disk('public')->exists($form->file_path)) {
|
|
abort(404, 'فایل قالب یافت نشد.');
|
|
}
|
|
|
|
$ext = pathinfo($form->file_path, PATHINFO_EXTENSION);
|
|
|
|
return Storage::disk('public')->download(
|
|
$form->file_path,
|
|
'template-' . $form->id . '-' . $shipment->awb_no . '.' . $ext
|
|
);
|
|
}
|
|
|
|
/**
|
|
* دانلود فایل امضاشدهای که مشتری آپلود کرده است.
|
|
* GET /admin/shipments/{shipment}/commitment-forms/{record}/signed
|
|
*/
|
|
public function signed(Shipment $shipment, ShipmentCommitmentForm $record)
|
|
{
|
|
$this->authorizePanel();
|
|
|
|
if ($record->shipment_id !== $shipment->id) {
|
|
abort(404);
|
|
}
|
|
|
|
if (!$record->uploaded_file_path || !Storage::disk('secure')->exists($record->uploaded_file_path)) {
|
|
abort(404, 'فایل امضاشده یافت نشد.');
|
|
}
|
|
|
|
return Storage::disk('secure')->download(
|
|
$record->uploaded_file_path,
|
|
'commitment-' . $record->commitment_form_id . '-' . $shipment->awb_no . '.' . $record->uploaded_file_type
|
|
);
|
|
}
|
|
|
|
/**
|
|
* فقط کاربران پنل ادمین (super_admin/admin/staff) مجاز به دانلود هستند.
|
|
* همان منطق User::canAccessPanel — بدون نیاز به نمونه پنل (بیرون از کانتکست Filament)
|
|
*/
|
|
private function authorizePanel(): void
|
|
{
|
|
abort_unless(auth()->user()?->hasAnyRole(['super_admin', 'admin', 'staff']), 403);
|
|
}
|
|
}
|