orders.php 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371
  1. <?php
  2. require_once __DIR__ . "/../config.php";
  3. require_once __DIR__ . "/../includes/functions.php";
  4. if (empty($_SESSION["admin_logged_in"])) {
  5. header("Location: login.php");
  6. exit();
  7. }
  8. expirePendingOrders();
  9. $pageTitle = "Bestellungen";
  10. $message = "";
  11. $messageType = "";
  12. if (
  13. $_SERVER["REQUEST_METHOD"] === "POST" &&
  14. isset($_POST["toggle_item_processed"])
  15. ) {
  16. // Validate CSRF token
  17. if (!validateCsrfToken($_POST["csrf_token"] ?? "")) {
  18. $message = "Ungültiges Token. Bitte versuchen Sie es erneut.";
  19. $messageType = "error";
  20. } else {
  21. $result = toggleOrderItemProcessed(
  22. $_POST["order_id"] ?? "",
  23. (int) ($_POST["item_index"] ?? -1),
  24. );
  25. $message = $result["success"]
  26. ? "Position wurde aktualisiert."
  27. : $result["message"];
  28. $messageType = $result["success"] ? "success" : "error";
  29. if ($result["success"]) {
  30. logAccess("Admin toggled order item", [
  31. "admin" => $_SESSION["admin_username"] ?? "unknown",
  32. "order_id" => $_POST["order_id"] ?? "",
  33. "item_index" => $_POST["item_index"] ?? -1,
  34. ]);
  35. }
  36. }
  37. }
  38. if ($_SERVER["REQUEST_METHOD"] === "POST" && isset($_POST["cancel_order"])) {
  39. // Validate CSRF token
  40. if (!validateCsrfToken($_POST["csrf_token"] ?? "")) {
  41. $message = "Ungültiges Token. Bitte versuchen Sie es erneut.";
  42. $messageType = "error";
  43. } else {
  44. $adminUsername = $_SESSION["admin_username"] ?? "";
  45. $result = cancelOrder(
  46. $_POST["order_id"] ?? "",
  47. $adminUsername,
  48. $_POST["cancellation_reason"] ?? "",
  49. );
  50. $message = $result["success"]
  51. ? "Bestellung wurde storniert."
  52. : $result["message"];
  53. $messageType = $result["success"] ? "success" : "error";
  54. if ($result["success"]) {
  55. logAccess("Admin cancelled order", [
  56. "admin" => $adminUsername,
  57. "order_id" => $_POST["order_id"] ?? "",
  58. ]);
  59. }
  60. }
  61. }
  62. $orders = getOrders();
  63. usort($orders, function ($left, $right) {
  64. return strcmp($right["created_at"], $left["created_at"]);
  65. });
  66. $filter = trim((string) ($_GET["filter"] ?? "all"));
  67. $searchOrderId = trim((string) ($_GET["order_id"] ?? ""));
  68. $selectedOrderId = trim((string) ($_GET["details"] ?? $searchOrderId));
  69. if ($searchOrderId !== "") {
  70. $orders = array_values(
  71. array_filter($orders, function ($order) use ($searchOrderId) {
  72. return stripos($order["id"], $searchOrderId) !== false;
  73. }),
  74. );
  75. }
  76. if ($filter !== "all") {
  77. $orders = array_values(
  78. array_filter($orders, function ($order) use ($filter) {
  79. switch ($filter) {
  80. case "unconfirmed":
  81. return $order["confirmation_status"] === "pending";
  82. case "expired":
  83. return $order["confirmation_status"] === "expired";
  84. case "open":
  85. return $order["confirmation_status"] !== "pending" &&
  86. $order["status"] === "open";
  87. case "partial":
  88. return $order["status"] === "partial";
  89. case "processed":
  90. return $order["status"] === "processed";
  91. case "cancelled":
  92. return $order["status"] === "cancelled";
  93. }
  94. return true;
  95. }),
  96. );
  97. }
  98. $selectedOrder =
  99. $selectedOrderId !== "" ? getOrderById($selectedOrderId) : null;
  100. $bodyClass = "admin-page";
  101. include __DIR__ . "/../includes/header.php";
  102. ?>
  103. <div class="admin-header">
  104. <h2>Bestellungen</h2>
  105. <div>
  106. <a href="index.php" class="btn btn-secondary">Zurück zum Dashboard</a>
  107. </div>
  108. </div>
  109. <?php if ($message !== ""): ?>
  110. <div class="alert alert-<?php echo escape($messageType); ?>">
  111. <?php echo escape($message); ?>
  112. </div>
  113. <?php endif; ?>
  114. <div class="panel">
  115. <form method="GET" class="admin-filter-form">
  116. <div class="admin-filter-field admin-filter-field-wide">
  117. <label for="order_id">Bestellnummer suchen</label>
  118. <input type="text" id="order_id" name="order_id" value="<?php echo escape(
  119. $searchOrderId,
  120. ); ?>" placeholder="z. B. FWFS-2026-001">
  121. </div>
  122. <div>
  123. <label for="filter">Filter</label>
  124. <select id="filter" name="filter">
  125. <option value="all" <?php echo $filter === "all"
  126. ? "selected"
  127. : ""; ?>>Alle</option>
  128. <option value="unconfirmed" <?php echo $filter === "unconfirmed"
  129. ? "selected"
  130. : ""; ?>>Unbestätigt</option>
  131. <option value="expired" <?php echo $filter === "expired"
  132. ? "selected"
  133. : ""; ?>>Bestätigung abgelaufen</option>
  134. <option value="open" <?php echo $filter === "open"
  135. ? "selected"
  136. : ""; ?>>Offen</option>
  137. <option value="partial" <?php echo $filter === "partial"
  138. ? "selected"
  139. : ""; ?>>Teilweise bearbeitet</option>
  140. <option value="processed" <?php echo $filter === "processed"
  141. ? "selected"
  142. : ""; ?>>Bearbeitet</option>
  143. <option value="cancelled" <?php echo $filter === "cancelled"
  144. ? "selected"
  145. : ""; ?>>Storniert</option>
  146. </select>
  147. </div>
  148. <div class="admin-filter-actions">
  149. <button type="submit" class="btn">Filtern</button>
  150. <a href="orders.php" class="btn btn-secondary">Zurücksetzen</a>
  151. </div>
  152. </form>
  153. </div>
  154. <?php if (empty($orders)): ?>
  155. <div class="alert alert-info">
  156. <p>Keine Bestellungen gefunden.</p>
  157. </div>
  158. <?php else: ?>
  159. <div class="table-responsive">
  160. <table class="responsive-table">
  161. <thead>
  162. <tr>
  163. <th>Bestellnummer</th>
  164. <th>Name</th>
  165. <th>Organisation</th>
  166. <th>Artikel</th>
  167. <th>Erstellt</th>
  168. <th>Status</th>
  169. <th>Aktionen</th>
  170. </tr>
  171. </thead>
  172. <tbody>
  173. <?php foreach ($orders as $order): ?>
  174. <tr>
  175. <td data-label="Bestellnummer"><strong><?php echo escape(
  176. $order["id"],
  177. ); ?></strong></td>
  178. <td data-label="Name"><?php echo escape(
  179. $order["customer_name"],
  180. ); ?></td>
  181. <td data-label="Organisation"><?php echo escape(
  182. $order["organization_label"],
  183. ); ?></td>
  184. <td data-label="Artikel"><?php echo count(
  185. $order["items"],
  186. ); ?></td>
  187. <td data-label="Erstellt"><?php echo escape(
  188. formatDate($order["created_at"]),
  189. ); ?></td>
  190. <td data-label="Status"><span class="status <?php echo escape(
  191. getOrderStatusClass($order),
  192. ); ?>"><?php echo escape(
  193. getOrderStatusLabel($order),
  194. ); ?></span></td>
  195. <td data-label="Aktionen">
  196. <a href="orders.php?details=<?php echo urlencode(
  197. $order["id"],
  198. ); ?>" class="btn btn-small">Details</a>
  199. </td>
  200. </tr>
  201. <?php endforeach; ?>
  202. </tbody>
  203. </table>
  204. </div>
  205. <?php endif; ?>
  206. <?php if ($selectedOrder !== null): ?>
  207. <div class="panel">
  208. <h3>Bestellung <?php echo escape($selectedOrder["id"]); ?></h3>
  209. <p><strong>Status:</strong> <span class="status <?php echo escape(
  210. getOrderStatusClass($selectedOrder),
  211. ); ?>"><?php echo escape(
  212. getOrderStatusLabel($selectedOrder),
  213. ); ?></span></p>
  214. <p><strong>Name:</strong> <?php echo escape(
  215. $selectedOrder["customer_name"],
  216. ); ?></p>
  217. <p><strong>E-Mail:</strong> <?php echo escape(
  218. $selectedOrder["customer_email"],
  219. ); ?></p>
  220. <p><strong>Organisation:</strong> <?php echo escape(
  221. $selectedOrder["organization_label"],
  222. ); ?></p>
  223. <p><strong>Erstellt:</strong> <?php echo escape(
  224. formatDate($selectedOrder["created_at"]),
  225. ); ?></p>
  226. <?php if ($selectedOrder["confirmed_at"] !== ""): ?>
  227. <p><strong>Bestätigt:</strong> <?php echo escape(
  228. formatDate($selectedOrder["confirmed_at"]),
  229. ); ?></p>
  230. <?php endif; ?>
  231. <?php if ($selectedOrder["confirmation_status"] === "pending"): ?>
  232. <p><strong>Bestätigung offen bis:</strong> <?php echo escape(
  233. formatDate($selectedOrder["confirmation_expires_at"]),
  234. ); ?></p>
  235. <?php endif; ?>
  236. <?php if ($selectedOrder["admin_notified_at"] !== ""): ?>
  237. <p><strong>Intern weitergeleitet:</strong> <?php echo escape(
  238. formatDate($selectedOrder["admin_notified_at"]),
  239. ); ?></p>
  240. <?php endif; ?>
  241. <p><strong>Kommentar:</strong><br><?php echo $selectedOrder[
  242. "comment"
  243. ] !== ""
  244. ? nl2br(escape($selectedOrder["comment"]))
  245. : "Kein Kommentar"; ?></p>
  246. <?php if ($selectedOrder["status"] === "cancelled"): ?>
  247. <div class="alert alert-warning">
  248. <p><strong>Storniert am:</strong> <?php echo escape(
  249. formatDate($selectedOrder["cancelled_at"]),
  250. ); ?></p>
  251. <p><strong>Storniert durch:</strong> <?php echo escape(
  252. $selectedOrder["cancelled_by"],
  253. ); ?></p>
  254. <p><strong>Stornogrund:</strong><br><?php echo $selectedOrder[
  255. "cancellation_reason"
  256. ] !== ""
  257. ? nl2br(escape($selectedOrder["cancellation_reason"]))
  258. : "Kein Grund angegeben"; ?></p>
  259. </div>
  260. <?php endif; ?>
  261. <h4>Positionen</h4>
  262. <div class="table-responsive">
  263. <table class="responsive-table table-compact">
  264. <thead>
  265. <tr>
  266. <th>Artikel</th>
  267. <th>Größe</th>
  268. <th>Lieferhinweis</th>
  269. <th>Bearbeitet</th>
  270. <th>Aktion</th>
  271. </tr>
  272. </thead>
  273. <tbody>
  274. <?php foreach (
  275. $selectedOrder["items"]
  276. as $index => $item
  277. ): ?>
  278. <tr>
  279. <td data-label="Artikel"><?php echo escape(
  280. $item["product_name"],
  281. ); ?></td>
  282. <td data-label="Größe"><?php echo $item["size"] !==
  283. ""
  284. ? escape($item["size"])
  285. : "-"; ?></td>
  286. <td data-label="Lieferhinweis"><?php echo $item[
  287. "availability_label"
  288. ] !== ""
  289. ? escape($item["availability_label"])
  290. : "-"; ?></td>
  291. <td data-label="Bearbeitet">
  292. <span class="status <?php echo !empty(
  293. $item["is_processed"]
  294. )
  295. ? "status-processed"
  296. : "status-open"; ?>">
  297. <?php echo !empty($item["is_processed"])
  298. ? "Ja"
  299. : "Nein"; ?>
  300. </span>
  301. </td>
  302. <td data-label="Aktionen">
  303. <?php if (
  304. $selectedOrder["status"] !== "cancelled" &&
  305. $selectedOrder["confirmation_status"] !==
  306. "pending" &&
  307. $selectedOrder["confirmation_status"] !==
  308. "expired"
  309. ): ?>
  310. <form method="POST">
  311. <?php echo csrfField(); ?>
  312. <input type="hidden" name="order_id" value="<?php echo escape(
  313. $selectedOrder["id"],
  314. ); ?>">
  315. <input type="hidden" name="item_index" value="<?php echo (int) $index; ?>">
  316. <button type="submit" name="toggle_item_processed" class="btn btn-small">
  317. <?php echo !empty(
  318. $item["is_processed"]
  319. )
  320. ? "Als offen markieren"
  321. : "Als bearbeitet markieren"; ?>
  322. </button>
  323. </form>
  324. <?php else: ?>
  325. -
  326. <?php endif; ?>
  327. </td>
  328. </tr>
  329. <?php endforeach; ?>
  330. </tbody>
  331. </table>
  332. </div>
  333. <?php if ($selectedOrder["status"] !== "cancelled"): ?>
  334. <h4>Bestellung stornieren</h4>
  335. <form method="POST" onsubmit="return confirm('Bestellung wirklich stornieren?');">
  336. <?php echo csrfField(); ?>
  337. <input type="hidden" name="order_id" value="<?php echo escape(
  338. $selectedOrder["id"],
  339. ); ?>">
  340. <div class="form-group">
  341. <label for="cancellation_reason">Stornogrund</label>
  342. <textarea id="cancellation_reason" name="cancellation_reason" rows="3" placeholder="Optionaler Grund"></textarea>
  343. </div>
  344. <button type="submit" name="cancel_order" class="btn">Bestellung stornieren</button>
  345. </form>
  346. <?php endif; ?>
  347. </div>
  348. <?php endif; ?>
  349. <?php include __DIR__ . "/../includes/footer.php"; ?>