order.php 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425
  1. <?php
  2. require_once __DIR__ . "/../config.php";
  3. require_once __DIR__ . "/../includes/functions.php";
  4. if (empty($_SESSION['admin_logged_in'])) {
  5. header("Location: login.php");
  6. exit();
  7. }
  8. expirePendingOrders();
  9. $message = "";
  10. $messageType = "";
  11. if (
  12. $_SERVER['REQUEST_METHOD'] === "POST" &&
  13. isset($_POST['toggle_item_backorder'])
  14. ) {
  15. if (!validateCsrfToken($_POST['csrf_token'] ?? "")) {
  16. $message = "Ungültiges Token. Bitte versuchen Sie es erneut.";
  17. $messageType = "error";
  18. } else {
  19. $result = toggleOrderItemBackorder(
  20. $_POST['order_id'] ?? "",
  21. (int) ($_POST['item_index'] ?? -1),
  22. );
  23. $message = $result["success"]
  24. ? "Nachbestellstatus wurde aktualisiert."
  25. : $result["message"];
  26. $messageType = $result["success"] ? "success" : "error";
  27. if ($result["success"]) {
  28. logAccess("Admin toggled order item backorder", [
  29. "admin" => $_SESSION['admin_username'] ?? "unknown",
  30. "order_id" => $_POST['order_id'] ?? "",
  31. "item_index" => $_POST['item_index'] ?? -1,
  32. ]);
  33. }
  34. }
  35. }
  36. if (
  37. $_SERVER['REQUEST_METHOD'] === "POST" &&
  38. isset($_POST['toggle_item_processed'])
  39. ) {
  40. if (!validateCsrfToken($_POST['csrf_token'] ?? "")) {
  41. $message = "Ungültiges Token. Bitte versuchen Sie es erneut.";
  42. $messageType = "error";
  43. } else {
  44. $result = toggleOrderItemProcessed(
  45. $_POST['order_id'] ?? "",
  46. (int) ($_POST['item_index'] ?? -1),
  47. );
  48. $message = $result["success"]
  49. ? "Position wurde aktualisiert."
  50. : $result["message"];
  51. $messageType = $result["success"] ? "success" : "error";
  52. if ($result["success"]) {
  53. logAccess("Admin toggled order item", [
  54. "admin" => $_SESSION['admin_username'] ?? "unknown",
  55. "order_id" => $_POST['order_id'] ?? "",
  56. "item_index" => $_POST['item_index'] ?? -1,
  57. ]);
  58. }
  59. }
  60. }
  61. if ($_SERVER['REQUEST_METHOD'] === "POST" && isset($_POST['cancel_order'])) {
  62. if (!validateCsrfToken($_POST['csrf_token'] ?? "")) {
  63. $message = "Ungültiges Token. Bitte versuchen Sie es erneut.";
  64. $messageType = "error";
  65. } else {
  66. $adminUsername = $_SESSION['admin_username'] ?? "";
  67. $result = cancelOrder(
  68. $_POST['order_id'] ?? "",
  69. $adminUsername,
  70. $_POST['cancellation_reason'] ?? "",
  71. );
  72. $message = $result["success"]
  73. ? "Bestellung wurde storniert."
  74. : $result["message"];
  75. $messageType = $result["success"] ? "success" : "error";
  76. if ($result["success"]) {
  77. logAccess("Admin cancelled order", [
  78. "admin" => $adminUsername,
  79. "order_id" => $_POST['order_id'] ?? "",
  80. ]);
  81. }
  82. }
  83. }
  84. if ($_SERVER['REQUEST_METHOD'] === "POST" && isset($_POST['uncancel_order'])) {
  85. if (!validateCsrfToken($_POST['csrf_token'] ?? "")) {
  86. $message = "Ungültiges Token. Bitte versuchen Sie es erneut.";
  87. $messageType = "error";
  88. } else {
  89. $adminUsername = $_SESSION['admin_username'] ?? "";
  90. $result = uncancelOrder($_POST['order_id'] ?? "");
  91. $message = $result["success"]
  92. ? "Stornierung wurde aufgehoben."
  93. : $result["message"];
  94. $messageType = $result["success"] ? "success" : "error";
  95. if ($result["success"]) {
  96. logAccess("Admin uncancelled order", [
  97. "admin" => $adminUsername,
  98. "order_id" => $_POST['order_id'] ?? "",
  99. ]);
  100. }
  101. }
  102. }
  103. $orderId = trim((string) ($_GET['id'] ?? $_POST['order_id'] ?? ""));
  104. $order = $orderId !== "" ? getOrderById($orderId) : null;
  105. $pageTitle =
  106. $order !== null
  107. ? "Bestellung " . $order["id"]
  108. : ($orderId !== ""
  109. ? "Bestellung nicht gefunden"
  110. : "Bestellung");
  111. $bodyClass = "admin-page";
  112. include __DIR__ . "/../includes/header.php";
  113. ?>
  114. <div class="admin-header">
  115. <h2><?php echo $order !== null
  116. ? "Bestellung " . escape($order["id"])
  117. : "Bestellung"; ?></h2>
  118. <div class="admin-dashboard-actions">
  119. <?php if ($order !== null): ?>
  120. <a
  121. href="order-pdf.php?id=<?php echo urlencode($order["id"]); ?>"
  122. class="btn btn-secondary"
  123. target="_blank"
  124. rel="noopener noreferrer"
  125. >Bestellung drucken</a>
  126. <?php endif; ?>
  127. <a href="index.php" class="btn btn-secondary">Zurück zum Dashboard</a>
  128. <a href="orders.php" class="btn">Zurück zur Bestellliste</a>
  129. </div>
  130. </div>
  131. <?php if ($message !== ""): ?>
  132. <div class="alert alert-<?php echo escape($messageType); ?>">
  133. <?php echo escape($message); ?>
  134. </div>
  135. <?php endif; ?>
  136. <?php if ($order === null): ?>
  137. <div class="alert alert-info">
  138. <p><?php echo $orderId !== ""
  139. ? "Die Bestellung wurde nicht gefunden."
  140. : "Keine Bestellnummer angegeben."; ?></p>
  141. </div>
  142. <?php else: ?>
  143. <div class="panel">
  144. <p><strong>Status:</strong> <span class="status <?php echo escape(
  145. getOrderStatusClass($order),
  146. ); ?>"><?php echo escape(
  147. getOrderStatusLabel($order),
  148. ); ?></span>
  149. <?php if (orderHasBackorder($order)): ?>
  150. <span class="status status-backorder">Nachbestellung</span>
  151. <?php endif; ?>
  152. </p>
  153. <p><strong>Name:</strong> <?php echo escape(
  154. $order["customer_name"],
  155. ); ?></p>
  156. <p><strong>E-Mail:</strong> <?php echo escape(
  157. $order["customer_email"],
  158. ); ?></p>
  159. <p><strong>Organisation:</strong> <?php echo escape(
  160. $order["organization_label"],
  161. ); ?></p>
  162. <p><strong>Erstellt:</strong> <?php echo escape(
  163. formatDate($order["created_at"]),
  164. ); ?></p>
  165. <?php if ($order["confirmed_at"] !== ""): ?>
  166. <p><strong>Bestätigt:</strong> <?php echo escape(
  167. formatDate($order["confirmed_at"]),
  168. ); ?></p>
  169. <?php endif; ?>
  170. <?php if ($order["confirmation_status"] === "pending"): ?>
  171. <p><strong>Bestätigung offen bis:</strong> <?php echo escape(
  172. formatDate($order["confirmation_expires_at"]),
  173. ); ?></p>
  174. <?php endif; ?>
  175. <?php if ($order["admin_notified_at"] !== ""): ?>
  176. <p><strong>Intern weitergeleitet:</strong> <?php echo escape(
  177. formatDate($order["admin_notified_at"]),
  178. ); ?></p>
  179. <?php endif; ?>
  180. <p><strong>Kommentar:</strong><br><?php echo $order[
  181. "comment"
  182. ] !== ""
  183. ? nl2br(escape($order["comment"]))
  184. : "Kein Kommentar"; ?></p>
  185. <?php if ($order["status"] === "cancelled"): ?>
  186. <div class="alert alert-warning">
  187. <p><strong>Storniert am:</strong> <?php echo escape(
  188. formatDate($order["cancelled_at"]),
  189. ); ?></p>
  190. <p><strong>Storniert durch:</strong> <?php echo escape(
  191. $order["cancelled_by"],
  192. ); ?></p>
  193. <p><strong>Stornogrund:</strong><br><?php echo $order[
  194. "cancellation_reason"
  195. ] !== ""
  196. ? nl2br(escape($order["cancellation_reason"]))
  197. : "Kein Grund angegeben"; ?></p>
  198. </div>
  199. <form
  200. method="POST"
  201. class="inline-form"
  202. onsubmit="return confirm('Stornierung wirklich aufheben? Die Bestellung kann danach wieder bearbeitet werden.');"
  203. >
  204. <?php echo csrfField(); ?>
  205. <input type="hidden" name="order_id" value="<?php echo escape(
  206. $order["id"],
  207. ); ?>">
  208. <button type="submit" name="uncancel_order" class="btn btn-small">
  209. Stornierung aufheben
  210. </button>
  211. </form>
  212. <?php endif; ?>
  213. <h4>Positionen</h4>
  214. <div class="table-responsive">
  215. <table class="responsive-table table-compact">
  216. <thead>
  217. <tr>
  218. <th>Artikel</th>
  219. <th>Größe</th>
  220. <th>Lieferhinweis</th>
  221. <th>Bearbeitet</th>
  222. <th>Nachbestellung</th>
  223. <th>Aktion</th>
  224. </tr>
  225. </thead>
  226. <tbody>
  227. <?php foreach ($order["items"] as $index => $item): ?>
  228. <tr>
  229. <td data-label="Artikel"><?php echo escape(
  230. $item["product_name"],
  231. ); ?></td>
  232. <td data-label="Größe"><?php echo $item["size"] !==
  233. ""
  234. ? escape($item["size"])
  235. : "-"; ?></td>
  236. <td data-label="Lieferhinweis"><?php echo $item[
  237. "availability_label"
  238. ] !== ""
  239. ? escape($item["availability_label"])
  240. : "-"; ?></td>
  241. <td data-label="Bearbeitet">
  242. <span class="status <?php echo !empty(
  243. $item["is_processed"]
  244. )
  245. ? "status-processed"
  246. : "status-open"; ?>">
  247. <?php echo !empty($item["is_processed"])
  248. ? "Ja"
  249. : "Nein"; ?>
  250. </span>
  251. </td>
  252. <td data-label="Nachbestellung">
  253. <?php
  254. $backorderStatus = (string) ($item["backorder_status"] ?? "");
  255. if ($backorderStatus !== ""): ?>
  256. <span class="status <?php echo escape(
  257. getBackorderStatusClass($backorderStatus),
  258. ); ?>"><?php echo escape(
  259. getBackorderStatusLabel($backorderStatus),
  260. ); ?></span>
  261. <?php else: ?>
  262. -
  263. <?php endif; ?>
  264. </td>
  265. <td data-label="Aktionen">
  266. <?php if (
  267. $order["status"] !== "cancelled" &&
  268. $order["confirmation_status"] !==
  269. "pending" &&
  270. $order["confirmation_status"] !==
  271. "expired"
  272. ): ?>
  273. <form method="POST" class="inline-form">
  274. <?php echo csrfField(); ?>
  275. <input type="hidden" name="order_id" value="<?php echo escape(
  276. $order["id"],
  277. ); ?>">
  278. <input type="hidden" name="item_index" value="<?php echo (int) $index; ?>">
  279. <button type="submit" name="toggle_item_processed" class="btn btn-small">
  280. <?php echo !empty(
  281. $item["is_processed"]
  282. )
  283. ? "Als offen markieren"
  284. : "Als bearbeitet markieren"; ?>
  285. </button>
  286. </form>
  287. <?php
  288. $canToggleBackorder =
  289. $backorderStatus === "to_be_backordered" ||
  290. ($backorderStatus === "" &&
  291. empty($item["is_processed"]));
  292. if ($canToggleBackorder): ?>
  293. <form method="POST" class="inline-form">
  294. <?php echo csrfField(); ?>
  295. <input type="hidden" name="order_id" value="<?php echo escape(
  296. $order["id"],
  297. ); ?>">
  298. <input type="hidden" name="item_index" value="<?php echo (int) $index; ?>">
  299. <button type="submit" name="toggle_item_backorder" class="btn btn-small btn-secondary">
  300. <?php echo $backorderStatus === "to_be_backordered"
  301. ? "Nachbestellung aufheben"
  302. : "Als Nachbestellung markieren"; ?>
  303. </button>
  304. </form>
  305. <?php endif; ?>
  306. <?php else: ?>
  307. -
  308. <?php endif; ?>
  309. </td>
  310. </tr>
  311. <?php endforeach; ?>
  312. </tbody>
  313. </table>
  314. </div>
  315. <?php if (
  316. $order["status"] !== "cancelled" &&
  317. $order["status"] !== "processed"
  318. ): ?>
  319. <button
  320. type="button"
  321. class="btn btn-secondary btn-small"
  322. id="cancel-order-open"
  323. >
  324. Bestellung stornieren
  325. </button>
  326. <div
  327. id="cancel-order-modal"
  328. class="modal"
  329. role="dialog"
  330. aria-labelledby="cancel-order-title"
  331. aria-hidden="true"
  332. >
  333. <div class="modal-content modal-content-compact">
  334. <button
  335. type="button"
  336. class="modal-close btn btn-secondary btn-small"
  337. id="cancel-order-close"
  338. aria-label="Schließen"
  339. >
  340. &times;
  341. </button>
  342. <h4 id="cancel-order-title">Bestellung stornieren</h4>
  343. <form method="POST" id="cancel-order-form">
  344. <?php echo csrfField(); ?>
  345. <input type="hidden" name="order_id" value="<?php echo escape(
  346. $order["id"],
  347. ); ?>">
  348. <div class="form-group">
  349. <label for="cancellation_reason">Stornogrund</label>
  350. <textarea
  351. id="cancellation_reason"
  352. name="cancellation_reason"
  353. rows="3"
  354. placeholder="Optionaler Grund"
  355. ></textarea>
  356. </div>
  357. <button type="submit" name="cancel_order" class="btn">
  358. Stornierung bestätigen
  359. </button>
  360. </form>
  361. </div>
  362. </div>
  363. <script>
  364. (function () {
  365. const modal = document.getElementById("cancel-order-modal");
  366. const openBtn = document.getElementById("cancel-order-open");
  367. const closeBtn = document.getElementById("cancel-order-close");
  368. if (!modal || !openBtn || !closeBtn) {
  369. return;
  370. }
  371. function openModal() {
  372. modal.classList.add("is-open");
  373. modal.setAttribute("aria-hidden", "false");
  374. const reason = document.getElementById("cancellation_reason");
  375. if (reason) {
  376. reason.focus();
  377. }
  378. }
  379. function closeModal() {
  380. modal.classList.remove("is-open");
  381. modal.setAttribute("aria-hidden", "true");
  382. }
  383. openBtn.addEventListener("click", openModal);
  384. closeBtn.addEventListener("click", closeModal);
  385. modal.addEventListener("click", function (event) {
  386. if (event.target === modal) {
  387. closeModal();
  388. }
  389. });
  390. document.addEventListener("keydown", function (event) {
  391. if (event.key === "Escape" && modal.classList.contains("is-open")) {
  392. closeModal();
  393. }
  394. });
  395. })();
  396. </script>
  397. <?php endif; ?>
  398. </div>
  399. <?php endif; ?>
  400. <?php include __DIR__ . "/../includes/footer.php"; ?>