Add guest user handling and product filtering in productsRoute

- Implement guest-specific product redactions (e.g., hide names, reset prices).
- Refactor `parseProduct` to include guest context for dynamic response handling.
- Add authentication checks and guest user handling for accurate permission validation.
- Update logging to include guest or user context in actions.
- Adjust product and addon parsing for consistent guest visibility.
This commit is contained in:
Jeppe Bundgaard
2025-11-26 13:29:53 +01:00
parent 7961217a91
commit 667947fcda
+52 -25
View File
@@ -94,7 +94,7 @@ class productsRoute
$products = (new products_o())->applyDepartmentPricing($products, $departmentId);
}
// Check if the customer is set
if ($customer) {
if ($customer !== null) {
// Apply the customers unique discounts
$products = (new products_o())->applyCustomerDiscounts($products, $customer);
}
@@ -128,9 +128,21 @@ class productsRoute
public function run(): void
{
$this->get('/products', function () {
function parseProduct($product): array
// Check if the user is logged in
global $response;
$permission_node = 'list_products';
$isGuest = true;
if ($this->isAuthenticated()) {
$isGuest = false;
$this->requirePermission($permission_node);
}
// Get the user object
$user = (new authentication())->get_user();
// Set the user id to 0 if guest
$responsibleUserId = $isGuest ? 0 : $user->id;
function parseProduct($product, $isGuest): array
{
return [
$tmpProduct = [
'id' => (int)$product['id'],
'name' => (string)$product['name'],
'description' => (string)$product['description'],
@@ -148,15 +160,30 @@ class productsRoute
'display_in_booking_form' => (bool)$product['display_in_booking_form'],
'order_priority' => (int)$product['order_priority'],
];
/** Apply guest filters and redactions, if any */
if ($isGuest) {
$tmpProductGuest = [
...$tmpProduct,
'name' => $tmpProduct['display_in_booking_form'] ? $tmpProduct['name'] : 'Login to view',
'description' => '',
'price' => 0,
'economic_product_id' => 0,
'apply_category_discount' => false,
'requires_note' => false,
'addons' => $tmpProduct['display_in_booking_form'] ?
array_map(function ($option) {
$option['price'] = 0;
$option['product']['price'] = 0;
return $option;
}, $tmpProduct['addons']) : []
];
}
return $isGuest ? $tmpProductGuest : $tmpProduct;
}
// Require the user to be logged in
global $response;
$this->requirePermission('list_products');
// Get the user object
$user = (new authentication())->get_user();
// Check if the request was successful
if ($user) {
if ($user || $isGuest) {
// Define the variables
$customer = self::getCustomerIfProvided(); // This is only used if the customer_id parameter is provided
$departmentId = self::getDepartmentIdIfProvided(); // This is only used if the department_id parameter is provided
@@ -186,8 +213,8 @@ class productsRoute
} else {
// Get all products
$products = (array)(new products_o())->listObjectsWithPaginationIfSet(
function ($product) {
return parseProduct($product);
function ($product) use ($isGuest) {
return parseProduct($product, $isGuest);
}
);
}
@@ -197,10 +224,10 @@ class productsRoute
// return parseProduct($product);
// }, self::parseProductsPrice($products, $customer, $departmentId))
//);
$result = array_map(function ($product) use ($customer, $departmentId) {
$productArray = parseProduct($product);
$result = array_map(function ($product) use ($customer, $departmentId, $isGuest) {
$productArray = parseProduct($product, $isGuest);
// Get the price of the product with the department pricing and customer discounts applied
$productArray = parseProduct(self::parseProductsPrice([$productArray], $customer, $departmentId)[0]);
$productArray = parseProduct(self::parseProductsPrice([$productArray], $customer, $departmentId)[0], $isGuest);
// Get the options for the product
$productArray['addons'] = self::parseOptionsPrice($productArray['addons'], $customer, $departmentId);
// Return the product with the updated price
@@ -212,11 +239,11 @@ class productsRoute
// Check if the id is set in the request (to get a specific product)
if (self::isParametersSet(['id'])) {
// Log the incident
(new logs_o())->add('products', 'global', 1, $user->id, 'LIST_PRODUCTS', 'Successfully listed product with id ' . $response->getRequestParameter('id'));
(new logs_o())->add('products', 'global', 1, $responsibleUserId, 'LIST_PRODUCTS', 'Successfully listed product with id ' . $response->getRequestParameter('id'));
// Return the product
$response->success(
parseProduct(
(new products_o())->select((int)self::getParameter('id'))->asArray()
(new products_o())->select((int)self::getParameter('id'))->asArray(), $isGuest
)
);
}
@@ -225,7 +252,7 @@ class productsRoute
// Check if the category is set
if (isset($data['category'])) {
// Log the incident
(new logs_o())->add('products', 'global', 1, $user->id, 'LIST_PRODUCTS', 'Successfully listed products in category ' . $data['category']);
(new logs_o())->add('products', 'global', 1, $responsibleUserId, 'LIST_PRODUCTS', 'Successfully listed products in category ' . $data['category']);
// Return the list of products
$products = (new products_o())->listObjectsByCategory($data['category']);
// Check if the department_id is set
@@ -234,13 +261,13 @@ class productsRoute
$products = (new products_o())->applyDepartmentPricing((array)$products, (int)$data['department_id']);
}
$response->success(
array_map(function ($product) {
return parseProduct($product);
array_map(function ($product) use ($isGuest) {
return parseProduct($product, $isGuest);
}, $products)
);
}
// Log the incident
(new logs_o())->add('products', 'global', 1, $user->id, 'LIST_PRODUCTS', 'Successfully listed products');
(new logs_o())->add('products', 'global', 1, $responsibleUserId, 'LIST_PRODUCTS', 'Successfully listed products');
// Check if the department_id is set
if (isset($data['department_id'])) {
// Get all product ids contained in a category attached to the department
@@ -252,20 +279,20 @@ class productsRoute
// Return the list of products
$response->success(
(new products_o())->applyDepartmentPricing((array)(new products_o())->listObjectsWithPaginationIfSet(
function ($product) use ($departmentSpecificProductIds) {
function ($product) use ($isGuest, $departmentSpecificProductIds) {
// Only include products that are in the department specific product ids
return parseProduct($product);
return parseProduct($product, $isGuest);
},
(new products_o())->forceRestrictFilters([
'id' => $departmentSpecificProductIds
'id' => $departmentSpecificProductIds,
])
), (int)$data['department_id'])
);
}
// Return the list of products
$response->success(
(new products_o())->listObjectsWithPaginationIfSet(function ($product) {
return parseProduct($product);
(new products_o())->listObjectsWithPaginationIfSet(function ($product) use ($isGuest) {
return parseProduct($product, $isGuest);
})
);
} else {