ifnex/04_Laravel/app/Http/Controllers
Kazem Alghasi 8cf407553b feat(security): implement secure file storage and shipment access control
Introduce a 'secure' filesystem disk to prevent public access to sensitive
commitment form uploads. Files are now stored in a non-public directory
and served via a protected controller method that validates user ownership.

Additionally, implement shipment authorization policies to ensure users
can only access PDF documents (AWB, invoice, labels) belonging to their
own orders.

Other changes:
- Add production environment check for Zarinpal gateway configuration
  to prevent accidental use of sandbox credentials.
- Move discount code and commitment form routes under authentication
  middleware for improved security.
- Add `ShipmentPolicy` to handle resource authorization.
2026-10-01 03:34:28 +03:30
..
Api feat(security): implement secure file storage and shipment access control 2026-10-01 03:34:28 +03:30
Controller.php feat: Complete customer ordering system (Phase 3) 2026-08-10 06:09:56 +03:30
OrderController.php feat(order): implement order creation flow and pricing API 2026-08-04 07:59:23 +03:30
PricingPageController.php refactor(import): enhance shipping rates import and refine PDF layouts 2026-08-04 09:47:22 +03:30
ShipmentPdfController.php feat(security): implement secure file storage and shipment access control 2026-10-01 03:34:28 +03:30