This update introduces explicit permission definitions for various route handlers across multiple routes. These changes enhance clarity and allow for more granular control over route access based on defined permissions. The updates ensure better manageability and scalability of endpoint permissions.
130 lines
5.8 KiB
PHP
130 lines
5.8 KiB
PHP
<?php
|
|
|
|
namespace routes;
|
|
|
|
use classes\authentication;
|
|
use objects\logs_o;
|
|
use objects\users_o;
|
|
use traits\route_t;
|
|
|
|
class customerAttributes
|
|
{
|
|
use route_t;
|
|
|
|
public function run(): void
|
|
{
|
|
$this->get('/customer/attributes', function () {
|
|
// Require the user to be logged in
|
|
global $response;
|
|
$this->requirePermission('list_customer_attributes');
|
|
// Get the user object
|
|
$user = (new authentication())->get_user();
|
|
// Check if the request was successful
|
|
if ($user) {
|
|
// Get the query parameters from the URL
|
|
$data = $_GET;
|
|
// Check if the required fields are set
|
|
if (!isset($data['customer_number']) && !isset($data['user_id'])) {
|
|
$response->error('User ID or Customer Number is required', 400);
|
|
}
|
|
// Validate that the number is a number
|
|
if (isset($data['customer_number']) && !is_numeric($data['customer_number'])) {
|
|
$response->error('Customer Number must be a number', 400);
|
|
}
|
|
// Check if the user exists
|
|
if (!(new users_o())->automaticGetTargetUserFromRequest()->exists()) {
|
|
$response->error('Customer not found', 400);
|
|
}
|
|
// Log the incident
|
|
(new logs_o())->add('customer_attributes', 'global', 1, $user->id, 'LIST_CUSTOMER_ATTRIBUTES', 'Successfully listed customer attributes');
|
|
// Return the list of customer notes
|
|
$response->success(
|
|
(new users_o())->automaticGetTargetUserFromRequest()->getUserAttributes()
|
|
);
|
|
} else {
|
|
// Log the incident
|
|
(new logs_o())->add('customer_attributes', 'global', 1, 0, 'LIST_CUSTOMER_ATTRIBUTES', 'No user found, or invalid session');
|
|
// Return an error
|
|
$response->error('Invalid session', 400);
|
|
}
|
|
},
|
|
[
|
|
'list_customer_attributes' => 'List all customer attributes'
|
|
]
|
|
);
|
|
|
|
$this->post('/customer/attributes', function () {
|
|
// Require the user to be logged in
|
|
global $response;
|
|
$this->requirePermission('add_customer_attribute');
|
|
// Get the user object
|
|
$user = (new authentication())->get_user();
|
|
// Check if the request was successful
|
|
if ($user) {
|
|
// Get the post data
|
|
$data = json_decode(file_get_contents('php://input'), true);
|
|
// Check if the required fields are set
|
|
if (!isset($data['user_id']) && !isset($data['customer_number'])) {
|
|
$response->error('User ID or Customer Number is required', 400);
|
|
}
|
|
if (!isset($data['attribute'])) {
|
|
$response->error('Attribute is required', 400);
|
|
}
|
|
// Add the note to the customer
|
|
(new users_o())->automaticGetTargetUserFromRequest()->addAttribute((string)$data['attribute']);
|
|
// Log the incident
|
|
(new logs_o())->add('customer_attributes', 'global', 1, $user->id, 'ADD_CUSTOMER_ATTRIBUTE', 'Successfully added a customer attribute');
|
|
// Return a success message
|
|
$response->success(['message' => 'Customer attribute added']);
|
|
} else {
|
|
// Log the incident
|
|
(new logs_o())->add('customer_attributes', 'global', 1, 0, 'ADD_CUSTOMER_ATTRIBUTE', 'No user found, or invalid session');
|
|
// Return an error
|
|
$response->error('Invalid session', 400);
|
|
}
|
|
},
|
|
[
|
|
'add_customer_attribute' => 'Add a customer attribute'
|
|
]
|
|
);
|
|
|
|
$this->delete('/customer/attributes', function () {
|
|
// Require the user to be logged in
|
|
global $response;
|
|
$this->requirePermission('delete_customer_attribute');
|
|
// Get the user object
|
|
$user = (new authentication())->get_user();
|
|
// Check if the request was successful
|
|
if ($user) {
|
|
// Get the query parameters from the URL
|
|
$data = $_GET;
|
|
// Check if the required fields are set
|
|
if (!isset($data['user_id']) && !isset($data['customer_number'])) {
|
|
$response->error('User ID or Customer Number is required', 400);
|
|
}
|
|
if (!isset($data['attribute'])) {
|
|
$response->error('Attribute is required', 400);
|
|
}
|
|
// Check if the user exists
|
|
if (!(new users_o())->automaticGetTargetUserFromRequest()->exists()) {
|
|
$response->error('Customer not found', 400);
|
|
}
|
|
// Add the note to the customer
|
|
(new users_o())->automaticGetTargetUserFromRequest()->deleteAttribute($data['attribute']);
|
|
// Log the incident
|
|
(new logs_o())->add('customer_attributes', 'global', 1, $user->id, 'DELETE_CUSTOMER_ATTRIBUTE', 'Successfully deleted a customer attribute');
|
|
// Return a success message
|
|
$response->success(['message' => 'Customer attribute deleted']);
|
|
} else {
|
|
// Log the incident
|
|
(new logs_o())->add('customer_attributes', 'global', 1, 0, 'DELETE_CUSTOMER_ATTRIBUTE', 'No user found, or invalid session');
|
|
// Return an error
|
|
$response->error('Invalid session', 400);
|
|
}
|
|
},
|
|
[
|
|
'delete_customer_attribute' => 'Delete a customer attribute'
|
|
]
|
|
);
|
|
}
|
|
} |