orders.php 18 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434
  1. <?php
  2. require_once __DIR__ . "/../config.php";
  3. require_once __DIR__ . "/../includes/functions.php";
  4. if (empty($_SESSION['admin_logged_in'])) {
  5. header("Location: login.php");
  6. exit();
  7. }
  8. expirePendingOrders();
  9. $pageTitle = "Bestellungen";
  10. $message = "";
  11. $messageType = "";
  12. if (
  13. $_SERVER['REQUEST_METHOD'] === "POST" &&
  14. isset($_POST['toggle_item_backorder'])
  15. ) {
  16. if (!validateCsrfToken($_POST['csrf_token'] ?? "")) {
  17. $message = "Ungültiges Token. Bitte versuchen Sie es erneut.";
  18. $messageType = "error";
  19. } else {
  20. $result = toggleOrderItemBackorder(
  21. $_POST['order_id'] ?? "",
  22. (int) ($_POST['item_index'] ?? -1),
  23. );
  24. $message = $result["success"]
  25. ? "Nachbestellstatus wurde aktualisiert."
  26. : $result["message"];
  27. $messageType = $result["success"] ? "success" : "error";
  28. if ($result["success"]) {
  29. logAccess("Admin toggled order item backorder", [
  30. "admin" => $_SESSION['admin_username'] ?? "unknown",
  31. "order_id" => $_POST['order_id'] ?? "",
  32. "item_index" => $_POST['item_index'] ?? -1,
  33. ]);
  34. }
  35. }
  36. }
  37. if (
  38. $_SERVER['REQUEST_METHOD'] === "POST" &&
  39. isset($_POST['toggle_item_processed'])
  40. ) {
  41. // Validate CSRF token
  42. if (!validateCsrfToken($_POST['csrf_token'] ?? "")) {
  43. $message = "Ungültiges Token. Bitte versuchen Sie es erneut.";
  44. $messageType = "error";
  45. } else {
  46. $result = toggleOrderItemProcessed(
  47. $_POST['order_id'] ?? "",
  48. (int) ($_POST['item_index'] ?? -1),
  49. );
  50. $message = $result["success"]
  51. ? "Position wurde aktualisiert."
  52. : $result["message"];
  53. $messageType = $result["success"] ? "success" : "error";
  54. if ($result["success"]) {
  55. logAccess("Admin toggled order item", [
  56. "admin" => $_SESSION['admin_username'] ?? "unknown",
  57. "order_id" => $_POST['order_id'] ?? "",
  58. "item_index" => $_POST['item_index'] ?? -1,
  59. ]);
  60. }
  61. }
  62. }
  63. if ($_SERVER['REQUEST_METHOD'] === "POST" && isset($_POST['cancel_order'])) {
  64. // Validate CSRF token
  65. if (!validateCsrfToken($_POST['csrf_token'] ?? "")) {
  66. $message = "Ungültiges Token. Bitte versuchen Sie es erneut.";
  67. $messageType = "error";
  68. } else {
  69. $adminUsername = $_SESSION['admin_username'] ?? "";
  70. $result = cancelOrder(
  71. $_POST['order_id'] ?? "",
  72. $adminUsername,
  73. $_POST['cancellation_reason'] ?? "",
  74. );
  75. $message = $result["success"]
  76. ? "Bestellung wurde storniert."
  77. : $result["message"];
  78. $messageType = $result["success"] ? "success" : "error";
  79. if ($result["success"]) {
  80. logAccess("Admin cancelled order", [
  81. "admin" => $adminUsername,
  82. "order_id" => $_POST['order_id'] ?? "",
  83. ]);
  84. }
  85. }
  86. }
  87. $orders = getOrders();
  88. usort($orders, function ($left, $right) {
  89. return strcmp($right["created_at"], $left["created_at"]);
  90. });
  91. $filter = trim((string) ($_GET['filter'] ?? "all"));
  92. $searchOrderId = trim((string) ($_GET['order_id'] ?? ""));
  93. $selectedOrderId = trim((string) ($_GET['details'] ?? $searchOrderId));
  94. if ($searchOrderId !== "") {
  95. $orders = array_values(
  96. array_filter($orders, function ($order) use ($searchOrderId) {
  97. return stripos($order["id"], $searchOrderId) !== false;
  98. }),
  99. );
  100. }
  101. if ($filter !== "all") {
  102. $orders = array_values(
  103. array_filter($orders, function ($order) use ($filter) {
  104. switch ($filter) {
  105. case "unconfirmed":
  106. return $order["confirmation_status"] === "pending";
  107. case "expired":
  108. return $order["confirmation_status"] === "expired";
  109. case "open":
  110. return $order["confirmation_status"] !== "pending" &&
  111. $order["status"] === "open";
  112. case "partial":
  113. return $order["status"] === "partial";
  114. case "processed":
  115. return $order["status"] === "processed";
  116. case "cancelled":
  117. return $order["status"] === "cancelled";
  118. }
  119. return true;
  120. }),
  121. );
  122. }
  123. $selectedOrder =
  124. $selectedOrderId !== "" ? getOrderById($selectedOrderId) : null;
  125. $bodyClass = "admin-page";
  126. include __DIR__ . "/../includes/header.php";
  127. ?>
  128. <div class="admin-header">
  129. <h2>Bestellungen</h2>
  130. <div>
  131. <a href="index.php" class="btn btn-secondary">Zurück zum Dashboard</a>
  132. </div>
  133. </div>
  134. <?php if ($message !== ""): ?>
  135. <div class="alert alert-<?php echo escape($messageType); ?>">
  136. <?php echo escape($message); ?>
  137. </div>
  138. <?php endif; ?>
  139. <div class="panel">
  140. <form method="GET" class="admin-filter-form">
  141. <div class="admin-filter-field admin-filter-field-wide">
  142. <label for="order_id">Bestellnummer suchen</label>
  143. <input type="text" id="order_id" name="order_id" value="<?php echo escape(
  144. $searchOrderId,
  145. ); ?>" placeholder="z. B. FWFS-2026-001">
  146. </div>
  147. <div>
  148. <label for="filter">Filter</label>
  149. <select id="filter" name="filter">
  150. <option value="all" <?php echo $filter === "all"
  151. ? "selected"
  152. : ""; ?>>Alle</option>
  153. <option value="unconfirmed" <?php echo $filter === "unconfirmed"
  154. ? "selected"
  155. : ""; ?>>Unbestätigt</option>
  156. <option value="expired" <?php echo $filter === "expired"
  157. ? "selected"
  158. : ""; ?>>Bestätigung abgelaufen</option>
  159. <option value="open" <?php echo $filter === "open"
  160. ? "selected"
  161. : ""; ?>>Offen</option>
  162. <option value="partial" <?php echo $filter === "partial"
  163. ? "selected"
  164. : ""; ?>>Teilweise bearbeitet</option>
  165. <option value="processed" <?php echo $filter === "processed"
  166. ? "selected"
  167. : ""; ?>>Bearbeitet</option>
  168. <option value="cancelled" <?php echo $filter === "cancelled"
  169. ? "selected"
  170. : ""; ?>>Storniert</option>
  171. </select>
  172. </div>
  173. <div class="admin-filter-actions">
  174. <button type="submit" class="btn">Filtern</button>
  175. <a href="orders.php" class="btn btn-secondary">Zurücksetzen</a>
  176. </div>
  177. </form>
  178. </div>
  179. <?php if (empty($orders)): ?>
  180. <div class="alert alert-info">
  181. <p>Keine Bestellungen gefunden.</p>
  182. </div>
  183. <?php else: ?>
  184. <div class="table-responsive">
  185. <table class="responsive-table">
  186. <thead>
  187. <tr>
  188. <th>Bestellnummer</th>
  189. <th>Name</th>
  190. <th>Organisation</th>
  191. <th>Artikel</th>
  192. <th>Erstellt</th>
  193. <th>Status</th>
  194. <th>Aktionen</th>
  195. </tr>
  196. </thead>
  197. <tbody>
  198. <?php foreach ($orders as $order): ?>
  199. <tr>
  200. <td data-label="Bestellnummer"><strong><?php echo escape(
  201. $order["id"],
  202. ); ?></strong></td>
  203. <td data-label="Name"><?php echo escape(
  204. $order["customer_name"],
  205. ); ?></td>
  206. <td data-label="Organisation"><?php echo escape(
  207. $order["organization_label"],
  208. ); ?></td>
  209. <td data-label="Artikel"><?php echo count(
  210. $order["items"],
  211. ); ?></td>
  212. <td data-label="Erstellt"><?php echo escape(
  213. formatDate($order["created_at"]),
  214. ); ?></td>
  215. <td data-label="Status"><span class="status <?php echo escape(
  216. getOrderStatusClass($order),
  217. ); ?>"><?php echo escape(
  218. getOrderStatusLabel($order),
  219. ); ?></span></td>
  220. <td data-label="Aktionen">
  221. <a href="orders.php?details=<?php echo urlencode(
  222. $order["id"],
  223. ); ?>" class="btn btn-small">Details</a>
  224. </td>
  225. </tr>
  226. <?php endforeach; ?>
  227. </tbody>
  228. </table>
  229. </div>
  230. <?php endif; ?>
  231. <?php if ($selectedOrder !== null): ?>
  232. <div class="panel">
  233. <h3>Bestellung <?php echo escape($selectedOrder["id"]); ?></h3>
  234. <p><strong>Status:</strong> <span class="status <?php echo escape(
  235. getOrderStatusClass($selectedOrder),
  236. ); ?>"><?php echo escape(
  237. getOrderStatusLabel($selectedOrder),
  238. ); ?></span>
  239. <?php if (orderHasBackorder($selectedOrder)): ?>
  240. <span class="status status-backorder">Nachbestellung</span>
  241. <?php endif; ?>
  242. </p>
  243. <p><strong>Name:</strong> <?php echo escape(
  244. $selectedOrder["customer_name"],
  245. ); ?></p>
  246. <p><strong>E-Mail:</strong> <?php echo escape(
  247. $selectedOrder["customer_email"],
  248. ); ?></p>
  249. <p><strong>Organisation:</strong> <?php echo escape(
  250. $selectedOrder["organization_label"],
  251. ); ?></p>
  252. <p><strong>Erstellt:</strong> <?php echo escape(
  253. formatDate($selectedOrder["created_at"]),
  254. ); ?></p>
  255. <?php if ($selectedOrder["confirmed_at"] !== ""): ?>
  256. <p><strong>Bestätigt:</strong> <?php echo escape(
  257. formatDate($selectedOrder["confirmed_at"]),
  258. ); ?></p>
  259. <?php endif; ?>
  260. <?php if ($selectedOrder["confirmation_status"] === "pending"): ?>
  261. <p><strong>Bestätigung offen bis:</strong> <?php echo escape(
  262. formatDate($selectedOrder["confirmation_expires_at"]),
  263. ); ?></p>
  264. <?php endif; ?>
  265. <?php if ($selectedOrder["admin_notified_at"] !== ""): ?>
  266. <p><strong>Intern weitergeleitet:</strong> <?php echo escape(
  267. formatDate($selectedOrder["admin_notified_at"]),
  268. ); ?></p>
  269. <?php endif; ?>
  270. <p><strong>Kommentar:</strong><br><?php echo $selectedOrder[
  271. "comment"
  272. ] !== ""
  273. ? nl2br(escape($selectedOrder["comment"]))
  274. : "Kein Kommentar"; ?></p>
  275. <?php if ($selectedOrder["status"] === "cancelled"): ?>
  276. <div class="alert alert-warning">
  277. <p><strong>Storniert am:</strong> <?php echo escape(
  278. formatDate($selectedOrder["cancelled_at"]),
  279. ); ?></p>
  280. <p><strong>Storniert durch:</strong> <?php echo escape(
  281. $selectedOrder["cancelled_by"],
  282. ); ?></p>
  283. <p><strong>Stornogrund:</strong><br><?php echo $selectedOrder[
  284. "cancellation_reason"
  285. ] !== ""
  286. ? nl2br(escape($selectedOrder["cancellation_reason"]))
  287. : "Kein Grund angegeben"; ?></p>
  288. </div>
  289. <?php endif; ?>
  290. <h4>Positionen</h4>
  291. <div class="table-responsive">
  292. <table class="responsive-table table-compact">
  293. <thead>
  294. <tr>
  295. <th>Artikel</th>
  296. <th>Größe</th>
  297. <th>Lieferhinweis</th>
  298. <th>Bearbeitet</th>
  299. <th>Nachbestellung</th>
  300. <th>Aktion</th>
  301. </tr>
  302. </thead>
  303. <tbody>
  304. <?php foreach (
  305. $selectedOrder["items"]
  306. as $index => $item
  307. ): ?>
  308. <tr>
  309. <td data-label="Artikel"><?php echo escape(
  310. $item["product_name"],
  311. ); ?></td>
  312. <td data-label="Größe"><?php echo $item["size"] !==
  313. ""
  314. ? escape($item["size"])
  315. : "-"; ?></td>
  316. <td data-label="Lieferhinweis"><?php echo $item[
  317. "availability_label"
  318. ] !== ""
  319. ? escape($item["availability_label"])
  320. : "-"; ?></td>
  321. <td data-label="Bearbeitet">
  322. <span class="status <?php echo !empty(
  323. $item["is_processed"]
  324. )
  325. ? "status-processed"
  326. : "status-open"; ?>">
  327. <?php echo !empty($item["is_processed"])
  328. ? "Ja"
  329. : "Nein"; ?>
  330. </span>
  331. </td>
  332. <td data-label="Nachbestellung">
  333. <?php
  334. $backorderStatus = (string) ($item["backorder_status"] ?? "");
  335. if ($backorderStatus !== ""): ?>
  336. <span class="status <?php echo escape(
  337. getBackorderStatusClass($backorderStatus),
  338. ); ?>"><?php echo escape(
  339. getBackorderStatusLabel($backorderStatus),
  340. ); ?></span>
  341. <?php else: ?>
  342. -
  343. <?php endif; ?>
  344. </td>
  345. <td data-label="Aktionen">
  346. <?php if (
  347. $selectedOrder["status"] !== "cancelled" &&
  348. $selectedOrder["confirmation_status"] !==
  349. "pending" &&
  350. $selectedOrder["confirmation_status"] !==
  351. "expired"
  352. ): ?>
  353. <form method="POST" class="inline-form">
  354. <?php echo csrfField(); ?>
  355. <input type="hidden" name="order_id" value="<?php echo escape(
  356. $selectedOrder["id"],
  357. ); ?>">
  358. <input type="hidden" name="item_index" value="<?php echo (int) $index; ?>">
  359. <button type="submit" name="toggle_item_processed" class="btn btn-small">
  360. <?php echo !empty(
  361. $item["is_processed"]
  362. )
  363. ? "Als offen markieren"
  364. : "Als bearbeitet markieren"; ?>
  365. </button>
  366. </form>
  367. <?php
  368. $canToggleBackorder =
  369. $backorderStatus === "" ||
  370. $backorderStatus === "to_be_backordered";
  371. if ($canToggleBackorder): ?>
  372. <form method="POST" class="inline-form">
  373. <?php echo csrfField(); ?>
  374. <input type="hidden" name="order_id" value="<?php echo escape(
  375. $selectedOrder["id"],
  376. ); ?>">
  377. <input type="hidden" name="item_index" value="<?php echo (int) $index; ?>">
  378. <button type="submit" name="toggle_item_backorder" class="btn btn-small btn-secondary">
  379. <?php echo $backorderStatus === "to_be_backordered"
  380. ? "Nachbestellung aufheben"
  381. : "Als Nachbestellung markieren"; ?>
  382. </button>
  383. </form>
  384. <?php endif; ?>
  385. <?php else: ?>
  386. -
  387. <?php endif; ?>
  388. </td>
  389. </tr>
  390. <?php endforeach; ?>
  391. </tbody>
  392. </table>
  393. </div>
  394. <?php if ($selectedOrder["status"] !== "cancelled"): ?>
  395. <h4>Bestellung stornieren</h4>
  396. <form method="POST" onsubmit="return confirm('Bestellung wirklich stornieren?');">
  397. <?php echo csrfField(); ?>
  398. <input type="hidden" name="order_id" value="<?php echo escape(
  399. $selectedOrder["id"],
  400. ); ?>">
  401. <div class="form-group">
  402. <label for="cancellation_reason">Stornogrund</label>
  403. <textarea id="cancellation_reason" name="cancellation_reason" rows="3" placeholder="Optionaler Grund"></textarea>
  404. </div>
  405. <button type="submit" name="cancel_order" class="btn">Bestellung stornieren</button>
  406. </form>
  407. <?php endif; ?>
  408. </div>
  409. <?php endif; ?>
  410. <?php include __DIR__ . "/../includes/footer.php"; ?>