Introduce a 'secure' filesystem disk to prevent public access to sensitive commitment form uploads. Files are now stored in a non-public directory and served via a protected controller method that validates user ownership. Additionally, implement shipment authorization policies to ensure users can only access PDF documents (AWB, invoice, labels) belonging to their own orders. Other changes: - Add production environment check for Zarinpal gateway configuration to prevent accidental use of sandbox credentials. - Move discount code and commitment form routes under authentication middleware for improved security. - Add `ShipmentPolicy` to handle resource authorization. |
||
|---|---|---|
| .. | ||
| Customer | ||
| AuthController.php | ||
| BridgeAuthController.php | ||
| CommitmentFormController.php | ||
| CustomerFinancialController.php | ||
| DiscountCodeController.php | ||
| MobileVerificationController.php | ||
| MockGatewayController.php | ||
| PaymentController.php | ||
| PricingController.php | ||
| StaffOrderController.php | ||
| TrackController.php | ||
| WalletController.php | ||