ifnex/04_Laravel/app/Http/Controllers/Api/CommitmentFormController.php
Kazem Alghasi 8cf407553b feat(security): implement secure file storage and shipment access control
Introduce a 'secure' filesystem disk to prevent public access to sensitive
commitment form uploads. Files are now stored in a non-public directory
and served via a protected controller method that validates user ownership.

Additionally, implement shipment authorization policies to ensure users
can only access PDF documents (AWB, invoice, labels) belonging to their
own orders.

Other changes:
- Add production environment check for Zarinpal gateway configuration
  to prevent accidental use of sandbox credentials.
- Move discount code and commitment form routes under authentication
  middleware for improved security.
- Add `ShipmentPolicy` to handle resource authorization.
2026-10-01 03:34:28 +03:30

220 lines
7.8 KiB
PHP

<?php
namespace App\Http\Controllers\Api;
use App\Http\Controllers\Controller;
use App\Models\CommitmentForm;
use App\Models\Shipment;
use App\Models\ShipmentCommitmentForm;
use Illuminate\Http\JsonResponse;
use Illuminate\Http\Request;
use Illuminate\Support\Facades\Storage;
class CommitmentFormController extends Controller
{
/**
* دریافت لیست فایل‌های تعهدنامه فعال
* GET /api/v1/commitment-forms
*/
public function index(): JsonResponse
{
$forms = CommitmentForm::query()
->where('is_active', true)
->orderBy('sort_order')
->orderBy('created_at', 'desc')
->get()
->map(fn ($form) => [
'id' => $form->id,
'title' => $form->title,
'description' => $form->description,
'file_url' => $form->file_url,
'file_type' => strtoupper(pathinfo($form->file_path, PATHINFO_EXTENSION)),
'direction' => $form->direction,
]);
return response()->json([
'success' => true,
'data' => $forms,
]);
}
/**
* دریافت تعهدنامه‌ها بر اساس جهت ارسال
* GET /api/v1/commitment-forms/{direction}
*/
public function byDirection(string $direction): JsonResponse
{
$forms = CommitmentForm::query()
->where('is_active', true)
->where(function ($query) use ($direction) {
$query->where('direction', 'both')
->orWhere('direction', $direction);
})
->orderBy('sort_order')
->orderBy('created_at', 'desc')
->get()
->map(fn ($form) => [
'id' => $form->id,
'title' => $form->title,
'description' => $form->description,
'file_url' => $form->file_url,
'file_type' => strtoupper(pathinfo($form->file_path, PATHINFO_EXTENSION)),
'direction' => $form->direction,
]);
return response()->json([
'success' => true,
'data' => $forms,
]);
}
/**
* دریافت لیست تعهدنامه‌های مربوط به سفارش خاص
* GET /api/v1/customer/orders/{shipment}/commitment-forms
*/
public function shipmentForms(Shipment $shipment): JsonResponse
{
$user = auth()->user();
// بررسی مالکیت
if ($shipment->user_id !== $user->id) {
return response()->json([
'success' => false,
'message' => 'شما به این سفارش دسترسی ندارید.',
], 403);
}
$forms = CommitmentForm::query()
->where('is_active', true)
->where(function ($query) use ($shipment) {
$query->where('direction', 'both')
->orWhere('direction', $shipment->direction);
})
->orderBy('sort_order')
->orderBy('created_at', 'desc')
->get()
->map(function ($form) use ($shipment) {
$upload = ShipmentCommitmentForm::where('shipment_id', $shipment->id)
->where('commitment_form_id', $form->id)
->first();
return [
'id' => $form->id,
'title' => $form->title,
'description' => $form->description,
'file_url' => $form->file_url,
'file_type' => strtoupper(pathinfo($form->file_path, PATHINFO_EXTENSION)),
'direction' => $form->direction,
'upload_status' => $upload ? $upload->status : 'pending',
'uploaded_file_url' => $upload && $upload->uploaded_file_path
? route('customer.commitment-forms.download', ['shipment' => $shipment->id, 'form' => $form->id])
: null,
'uploaded_at' => $upload ? $upload->created_at : null,
'notes' => $upload ? $upload->notes : null,
];
});
return response()->json([
'success' => true,
'data' => $forms,
]);
}
/**
* آپلود فرم تعهدنامه امضاشده
* POST /api/v1/customer/orders/{shipment}/commitment-forms/{form}/upload
*/
public function uploadSigned(Request $request, Shipment $shipment, CommitmentForm $form): JsonResponse
{
$user = auth()->user();
// بررسی مالکیت
if ($shipment->user_id !== $user->id) {
return response()->json([
'success' => false,
'message' => 'شما به این سفارش دسترسی ندارید.',
], 403);
}
$request->validate([
'file' => 'required|file|mimes:pdf,jpg,jpeg,png|max:5120', // حداکثر 5MB
'notes' => 'nullable|string|max:1000',
]);
try {
$file = $request->file('file');
// 🛡️ ذخیره در دیسک امن (غیرعمومی) — فقط از طریق route محافظت‌شده قابل دانلود
$path = $file->store("commitment-forms/{$shipment->id}", 'secure');
$upload = ShipmentCommitmentForm::updateOrCreate(
[
'shipment_id' => $shipment->id,
'commitment_form_id' => $form->id,
],
[
'uploaded_file_path' => $path,
'uploaded_file_type' => $file->getClientOriginalExtension(),
'uploaded_file_size' => $file->getSize(),
'status' => 'uploaded',
'notes' => $request->input('notes'),
'uploaded_by' => $user->id,
]
);
return response()->json([
'success' => true,
'message' => 'فایل با موفقیت آپلود شد.',
'data' => [
'id' => $upload->id,
'file_url' => route('customer.commitment-forms.download', [
'shipment' => $shipment->id,
'form' => $form->id,
]),
'file_type' => $upload->uploaded_file_type,
'status' => $upload->status,
'uploaded_at' => $upload->created_at,
],
]);
} catch (\Exception $e) {
return response()->json([
'success' => false,
'message' => 'خطا در آپلود فایل: ' . $e->getMessage(),
], 500);
}
}
/**
* دانلود فرم تعهدنامه امزاشده (محافظت‌شده با بررسی مالکیت).
* GET /api/v1/customer/orders/{shipment}/commitment-forms/{form}/download
*/
public function downloadSigned(Shipment $shipment, CommitmentForm $form)
{
$user = auth()->user();
if ($shipment->user_id !== $user->id) {
return response()->json([
'success' => false,
'message' => 'شما به این سفارش دسترسی ندارید.',
], 403);
}
$upload = ShipmentCommitmentForm::where('shipment_id', $shipment->id)
->where('commitment_form_id', $form->id)
->firstOrFail();
if (!$upload->uploaded_file_path) {
return response()->json([
'success' => false,
'message' => 'فایلی برای این تعهدنامه آپلود نشده است.',
], 404);
}
return Storage::disk('secure')->download(
$upload->uploaded_file_path,
'commitment-' . $form->id . '-' . $shipment->awb_no . '.' . $upload->uploaded_file_type
);
}
}
}