orders.php 22 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542
  1. <?php
  2. require_once __DIR__ . "/../config.php";
  3. require_once __DIR__ . "/../includes/functions.php";
  4. if (empty($_SESSION['admin_logged_in'])) {
  5. header("Location: login.php");
  6. exit();
  7. }
  8. expirePendingOrders();
  9. $pageTitle = "Bestellungen";
  10. $message = "";
  11. $messageType = "";
  12. if (
  13. $_SERVER['REQUEST_METHOD'] === "POST" &&
  14. isset($_POST['toggle_item_backorder'])
  15. ) {
  16. if (!validateCsrfToken($_POST['csrf_token'] ?? "")) {
  17. $message = "Ungültiges Token. Bitte versuchen Sie es erneut.";
  18. $messageType = "error";
  19. } else {
  20. $result = toggleOrderItemBackorder(
  21. $_POST['order_id'] ?? "",
  22. (int) ($_POST['item_index'] ?? -1),
  23. );
  24. $message = $result["success"]
  25. ? "Nachbestellstatus wurde aktualisiert."
  26. : $result["message"];
  27. $messageType = $result["success"] ? "success" : "error";
  28. if ($result["success"]) {
  29. logAccess("Admin toggled order item backorder", [
  30. "admin" => $_SESSION['admin_username'] ?? "unknown",
  31. "order_id" => $_POST['order_id'] ?? "",
  32. "item_index" => $_POST['item_index'] ?? -1,
  33. ]);
  34. }
  35. }
  36. }
  37. if (
  38. $_SERVER['REQUEST_METHOD'] === "POST" &&
  39. isset($_POST['toggle_item_processed'])
  40. ) {
  41. // Validate CSRF token
  42. if (!validateCsrfToken($_POST['csrf_token'] ?? "")) {
  43. $message = "Ungültiges Token. Bitte versuchen Sie es erneut.";
  44. $messageType = "error";
  45. } else {
  46. $result = toggleOrderItemProcessed(
  47. $_POST['order_id'] ?? "",
  48. (int) ($_POST['item_index'] ?? -1),
  49. );
  50. $message = $result["success"]
  51. ? "Position wurde aktualisiert."
  52. : $result["message"];
  53. $messageType = $result["success"] ? "success" : "error";
  54. if ($result["success"]) {
  55. logAccess("Admin toggled order item", [
  56. "admin" => $_SESSION['admin_username'] ?? "unknown",
  57. "order_id" => $_POST['order_id'] ?? "",
  58. "item_index" => $_POST['item_index'] ?? -1,
  59. ]);
  60. }
  61. }
  62. }
  63. if ($_SERVER['REQUEST_METHOD'] === "POST" && isset($_POST['cancel_order'])) {
  64. // Validate CSRF token
  65. if (!validateCsrfToken($_POST['csrf_token'] ?? "")) {
  66. $message = "Ungültiges Token. Bitte versuchen Sie es erneut.";
  67. $messageType = "error";
  68. } else {
  69. $adminUsername = $_SESSION['admin_username'] ?? "";
  70. $result = cancelOrder(
  71. $_POST['order_id'] ?? "",
  72. $adminUsername,
  73. $_POST['cancellation_reason'] ?? "",
  74. );
  75. $message = $result["success"]
  76. ? "Bestellung wurde storniert."
  77. : $result["message"];
  78. $messageType = $result["success"] ? "success" : "error";
  79. if ($result["success"]) {
  80. logAccess("Admin cancelled order", [
  81. "admin" => $adminUsername,
  82. "order_id" => $_POST['order_id'] ?? "",
  83. ]);
  84. }
  85. }
  86. }
  87. if ($_SERVER['REQUEST_METHOD'] === "POST" && isset($_POST['uncancel_order'])) {
  88. if (!validateCsrfToken($_POST['csrf_token'] ?? "")) {
  89. $message = "Ungültiges Token. Bitte versuchen Sie es erneut.";
  90. $messageType = "error";
  91. } else {
  92. $adminUsername = $_SESSION['admin_username'] ?? "";
  93. $result = uncancelOrder($_POST['order_id'] ?? "");
  94. $message = $result["success"]
  95. ? "Stornierung wurde aufgehoben."
  96. : $result["message"];
  97. $messageType = $result["success"] ? "success" : "error";
  98. if ($result["success"]) {
  99. logAccess("Admin uncancelled order", [
  100. "admin" => $adminUsername,
  101. "order_id" => $_POST['order_id'] ?? "",
  102. ]);
  103. }
  104. }
  105. }
  106. $orders = getOrders();
  107. usort($orders, function ($left, $right) {
  108. return strcmp($right["created_at"], $left["created_at"]);
  109. });
  110. $filter = trim((string) ($_GET['filter'] ?? "all"));
  111. $searchOrderId = trim((string) ($_GET['order_id'] ?? ""));
  112. $selectedOrderId = trim((string) ($_GET['details'] ?? $searchOrderId));
  113. if ($searchOrderId !== "") {
  114. $orders = array_values(
  115. array_filter($orders, function ($order) use ($searchOrderId) {
  116. return stripos($order["id"], $searchOrderId) !== false;
  117. }),
  118. );
  119. }
  120. if ($filter !== "all") {
  121. $orders = array_values(
  122. array_filter($orders, function ($order) use ($filter) {
  123. switch ($filter) {
  124. case "unconfirmed":
  125. return $order["confirmation_status"] === "pending";
  126. case "expired":
  127. return $order["confirmation_status"] === "expired";
  128. case "open":
  129. return $order["confirmation_status"] !== "pending" &&
  130. $order["status"] === "open";
  131. case "partial":
  132. return $order["status"] === "partial";
  133. case "processed":
  134. return $order["status"] === "processed";
  135. case "cancelled":
  136. return $order["status"] === "cancelled";
  137. }
  138. return true;
  139. }),
  140. );
  141. }
  142. $selectedOrder =
  143. $selectedOrderId !== "" ? getOrderById($selectedOrderId) : null;
  144. $bodyClass = "admin-page";
  145. include __DIR__ . "/../includes/header.php";
  146. ?>
  147. <div class="admin-header">
  148. <h2>Bestellungen</h2>
  149. <div>
  150. <a href="index.php" class="btn btn-secondary">Zurück zum Dashboard</a>
  151. </div>
  152. </div>
  153. <?php if ($message !== ""): ?>
  154. <div class="alert alert-<?php echo escape($messageType); ?>">
  155. <?php echo escape($message); ?>
  156. </div>
  157. <?php endif; ?>
  158. <div class="panel">
  159. <form method="GET" class="admin-filter-form">
  160. <div class="admin-filter-field admin-filter-field-wide">
  161. <label for="order_id">Bestellnummer suchen</label>
  162. <input type="text" id="order_id" name="order_id" value="<?php echo escape(
  163. $searchOrderId,
  164. ); ?>" placeholder="z. B. FWFS-2026-001">
  165. </div>
  166. <div>
  167. <label for="filter">Filter</label>
  168. <select id="filter" name="filter">
  169. <option value="all" <?php echo $filter === "all"
  170. ? "selected"
  171. : ""; ?>>Alle</option>
  172. <option value="unconfirmed" <?php echo $filter === "unconfirmed"
  173. ? "selected"
  174. : ""; ?>>Unbestätigt</option>
  175. <option value="expired" <?php echo $filter === "expired"
  176. ? "selected"
  177. : ""; ?>>Bestätigung abgelaufen</option>
  178. <option value="open" <?php echo $filter === "open"
  179. ? "selected"
  180. : ""; ?>>Offen</option>
  181. <option value="partial" <?php echo $filter === "partial"
  182. ? "selected"
  183. : ""; ?>>Teilweise bearbeitet</option>
  184. <option value="processed" <?php echo $filter === "processed"
  185. ? "selected"
  186. : ""; ?>>Bearbeitet</option>
  187. <option value="cancelled" <?php echo $filter === "cancelled"
  188. ? "selected"
  189. : ""; ?>>Storniert</option>
  190. </select>
  191. </div>
  192. <div class="admin-filter-actions">
  193. <button type="submit" class="btn">Filtern</button>
  194. <a href="orders.php" class="btn btn-secondary">Zurücksetzen</a>
  195. </div>
  196. </form>
  197. </div>
  198. <?php if (empty($orders)): ?>
  199. <div class="alert alert-info">
  200. <p>Keine Bestellungen gefunden.</p>
  201. </div>
  202. <?php else: ?>
  203. <div class="table-responsive">
  204. <table class="responsive-table">
  205. <thead>
  206. <tr>
  207. <th>Bestellnummer</th>
  208. <th>Name</th>
  209. <th>Organisation</th>
  210. <th>Artikel</th>
  211. <th>Erstellt</th>
  212. <th>Status</th>
  213. <th>Aktionen</th>
  214. </tr>
  215. </thead>
  216. <tbody>
  217. <?php foreach ($orders as $order): ?>
  218. <tr>
  219. <td data-label="Bestellnummer"><strong><?php echo escape(
  220. $order["id"],
  221. ); ?></strong></td>
  222. <td data-label="Name"><?php echo escape(
  223. $order["customer_name"],
  224. ); ?></td>
  225. <td data-label="Organisation"><?php echo escape(
  226. $order["organization_label"],
  227. ); ?></td>
  228. <td data-label="Artikel"><?php echo count(
  229. $order["items"],
  230. ); ?></td>
  231. <td data-label="Erstellt"><?php echo escape(
  232. formatDate($order["created_at"]),
  233. ); ?></td>
  234. <td data-label="Status"><span class="status <?php echo escape(
  235. getOrderStatusClass($order),
  236. ); ?>"><?php echo escape(
  237. getOrderStatusLabel($order),
  238. ); ?></span></td>
  239. <td data-label="Aktionen">
  240. <a href="orders.php?details=<?php echo urlencode(
  241. $order["id"],
  242. ); ?>" class="btn btn-small">Details</a>
  243. </td>
  244. </tr>
  245. <?php endforeach; ?>
  246. </tbody>
  247. </table>
  248. </div>
  249. <?php endif; ?>
  250. <?php if ($selectedOrder !== null): ?>
  251. <div class="panel">
  252. <h3>Bestellung <?php echo escape($selectedOrder["id"]); ?></h3>
  253. <p><strong>Status:</strong> <span class="status <?php echo escape(
  254. getOrderStatusClass($selectedOrder),
  255. ); ?>"><?php echo escape(
  256. getOrderStatusLabel($selectedOrder),
  257. ); ?></span>
  258. <?php if (orderHasBackorder($selectedOrder)): ?>
  259. <span class="status status-backorder">Nachbestellung</span>
  260. <?php endif; ?>
  261. </p>
  262. <p><strong>Name:</strong> <?php echo escape(
  263. $selectedOrder["customer_name"],
  264. ); ?></p>
  265. <p><strong>E-Mail:</strong> <?php echo escape(
  266. $selectedOrder["customer_email"],
  267. ); ?></p>
  268. <p><strong>Organisation:</strong> <?php echo escape(
  269. $selectedOrder["organization_label"],
  270. ); ?></p>
  271. <p><strong>Erstellt:</strong> <?php echo escape(
  272. formatDate($selectedOrder["created_at"]),
  273. ); ?></p>
  274. <?php if ($selectedOrder["confirmed_at"] !== ""): ?>
  275. <p><strong>Bestätigt:</strong> <?php echo escape(
  276. formatDate($selectedOrder["confirmed_at"]),
  277. ); ?></p>
  278. <?php endif; ?>
  279. <?php if ($selectedOrder["confirmation_status"] === "pending"): ?>
  280. <p><strong>Bestätigung offen bis:</strong> <?php echo escape(
  281. formatDate($selectedOrder["confirmation_expires_at"]),
  282. ); ?></p>
  283. <?php endif; ?>
  284. <?php if ($selectedOrder["admin_notified_at"] !== ""): ?>
  285. <p><strong>Intern weitergeleitet:</strong> <?php echo escape(
  286. formatDate($selectedOrder["admin_notified_at"]),
  287. ); ?></p>
  288. <?php endif; ?>
  289. <p><strong>Kommentar:</strong><br><?php echo $selectedOrder[
  290. "comment"
  291. ] !== ""
  292. ? nl2br(escape($selectedOrder["comment"]))
  293. : "Kein Kommentar"; ?></p>
  294. <?php if ($selectedOrder["status"] === "cancelled"): ?>
  295. <div class="alert alert-warning">
  296. <p><strong>Storniert am:</strong> <?php echo escape(
  297. formatDate($selectedOrder["cancelled_at"]),
  298. ); ?></p>
  299. <p><strong>Storniert durch:</strong> <?php echo escape(
  300. $selectedOrder["cancelled_by"],
  301. ); ?></p>
  302. <p><strong>Stornogrund:</strong><br><?php echo $selectedOrder[
  303. "cancellation_reason"
  304. ] !== ""
  305. ? nl2br(escape($selectedOrder["cancellation_reason"]))
  306. : "Kein Grund angegeben"; ?></p>
  307. </div>
  308. <form
  309. method="POST"
  310. class="inline-form"
  311. onsubmit="return confirm('Stornierung wirklich aufheben? Die Bestellung kann danach wieder bearbeitet werden.');"
  312. >
  313. <?php echo csrfField(); ?>
  314. <input type="hidden" name="order_id" value="<?php echo escape(
  315. $selectedOrder["id"],
  316. ); ?>">
  317. <button type="submit" name="uncancel_order" class="btn btn-small">
  318. Stornierung aufheben
  319. </button>
  320. </form>
  321. <?php endif; ?>
  322. <h4>Positionen</h4>
  323. <div class="table-responsive">
  324. <table class="responsive-table table-compact">
  325. <thead>
  326. <tr>
  327. <th>Artikel</th>
  328. <th>Größe</th>
  329. <th>Lieferhinweis</th>
  330. <th>Bearbeitet</th>
  331. <th>Nachbestellung</th>
  332. <th>Aktion</th>
  333. </tr>
  334. </thead>
  335. <tbody>
  336. <?php foreach (
  337. $selectedOrder["items"]
  338. as $index => $item
  339. ): ?>
  340. <tr>
  341. <td data-label="Artikel"><?php echo escape(
  342. $item["product_name"],
  343. ); ?></td>
  344. <td data-label="Größe"><?php echo $item["size"] !==
  345. ""
  346. ? escape($item["size"])
  347. : "-"; ?></td>
  348. <td data-label="Lieferhinweis"><?php echo $item[
  349. "availability_label"
  350. ] !== ""
  351. ? escape($item["availability_label"])
  352. : "-"; ?></td>
  353. <td data-label="Bearbeitet">
  354. <span class="status <?php echo !empty(
  355. $item["is_processed"]
  356. )
  357. ? "status-processed"
  358. : "status-open"; ?>">
  359. <?php echo !empty($item["is_processed"])
  360. ? "Ja"
  361. : "Nein"; ?>
  362. </span>
  363. </td>
  364. <td data-label="Nachbestellung">
  365. <?php
  366. $backorderStatus = (string) ($item["backorder_status"] ?? "");
  367. if ($backorderStatus !== ""): ?>
  368. <span class="status <?php echo escape(
  369. getBackorderStatusClass($backorderStatus),
  370. ); ?>"><?php echo escape(
  371. getBackorderStatusLabel($backorderStatus),
  372. ); ?></span>
  373. <?php else: ?>
  374. -
  375. <?php endif; ?>
  376. </td>
  377. <td data-label="Aktionen">
  378. <?php if (
  379. $selectedOrder["status"] !== "cancelled" &&
  380. $selectedOrder["confirmation_status"] !==
  381. "pending" &&
  382. $selectedOrder["confirmation_status"] !==
  383. "expired"
  384. ): ?>
  385. <form method="POST" class="inline-form">
  386. <?php echo csrfField(); ?>
  387. <input type="hidden" name="order_id" value="<?php echo escape(
  388. $selectedOrder["id"],
  389. ); ?>">
  390. <input type="hidden" name="item_index" value="<?php echo (int) $index; ?>">
  391. <button type="submit" name="toggle_item_processed" class="btn btn-small">
  392. <?php echo !empty(
  393. $item["is_processed"]
  394. )
  395. ? "Als offen markieren"
  396. : "Als bearbeitet markieren"; ?>
  397. </button>
  398. </form>
  399. <?php
  400. $canToggleBackorder =
  401. $backorderStatus === "to_be_backordered" ||
  402. ($backorderStatus === "" &&
  403. empty($item["is_processed"]));
  404. if ($canToggleBackorder): ?>
  405. <form method="POST" class="inline-form">
  406. <?php echo csrfField(); ?>
  407. <input type="hidden" name="order_id" value="<?php echo escape(
  408. $selectedOrder["id"],
  409. ); ?>">
  410. <input type="hidden" name="item_index" value="<?php echo (int) $index; ?>">
  411. <button type="submit" name="toggle_item_backorder" class="btn btn-small btn-secondary">
  412. <?php echo $backorderStatus === "to_be_backordered"
  413. ? "Nachbestellung aufheben"
  414. : "Als Nachbestellung markieren"; ?>
  415. </button>
  416. </form>
  417. <?php endif; ?>
  418. <?php else: ?>
  419. -
  420. <?php endif; ?>
  421. </td>
  422. </tr>
  423. <?php endforeach; ?>
  424. </tbody>
  425. </table>
  426. </div>
  427. <?php if (
  428. $selectedOrder["status"] !== "cancelled" &&
  429. $selectedOrder["status"] !== "processed"
  430. ): ?>
  431. <button
  432. type="button"
  433. class="btn btn-secondary btn-small"
  434. id="cancel-order-open"
  435. >
  436. Bestellung stornieren
  437. </button>
  438. <div
  439. id="cancel-order-modal"
  440. class="modal"
  441. role="dialog"
  442. aria-labelledby="cancel-order-title"
  443. aria-hidden="true"
  444. >
  445. <div class="modal-content modal-content-compact">
  446. <button
  447. type="button"
  448. class="modal-close btn btn-secondary btn-small"
  449. id="cancel-order-close"
  450. aria-label="Schließen"
  451. >
  452. &times;
  453. </button>
  454. <h4 id="cancel-order-title">Bestellung stornieren</h4>
  455. <form method="POST" id="cancel-order-form">
  456. <?php echo csrfField(); ?>
  457. <input type="hidden" name="order_id" value="<?php echo escape(
  458. $selectedOrder["id"],
  459. ); ?>">
  460. <div class="form-group">
  461. <label for="cancellation_reason">Stornogrund</label>
  462. <textarea
  463. id="cancellation_reason"
  464. name="cancellation_reason"
  465. rows="3"
  466. placeholder="Optionaler Grund"
  467. ></textarea>
  468. </div>
  469. <button type="submit" name="cancel_order" class="btn">
  470. Stornierung bestätigen
  471. </button>
  472. </form>
  473. </div>
  474. </div>
  475. <script>
  476. (function () {
  477. const modal = document.getElementById("cancel-order-modal");
  478. const openBtn = document.getElementById("cancel-order-open");
  479. const closeBtn = document.getElementById("cancel-order-close");
  480. if (!modal || !openBtn || !closeBtn) {
  481. return;
  482. }
  483. function openModal() {
  484. modal.classList.add("is-open");
  485. modal.setAttribute("aria-hidden", "false");
  486. const reason = document.getElementById("cancellation_reason");
  487. if (reason) {
  488. reason.focus();
  489. }
  490. }
  491. function closeModal() {
  492. modal.classList.remove("is-open");
  493. modal.setAttribute("aria-hidden", "true");
  494. }
  495. openBtn.addEventListener("click", openModal);
  496. closeBtn.addEventListener("click", closeModal);
  497. modal.addEventListener("click", function (event) {
  498. if (event.target === modal) {
  499. closeModal();
  500. }
  501. });
  502. document.addEventListener("keydown", function (event) {
  503. if (event.key === "Escape" && modal.classList.contains("is-open")) {
  504. closeModal();
  505. }
  506. });
  507. })();
  508. </script>
  509. <?php endif; ?>
  510. </div>
  511. <?php endif; ?>
  512. <?php include __DIR__ . "/../includes/footer.php"; ?>