Files
kaffeekasse-saas/index.php
T
clemens cb799c7c66 Deployment-Vorbereitung: Domain-Split und Legacy-/Debug-Seiten entfernt
- index.php zeigt bei abweichendem Host (APP_HOST-Env) die Landingpage
  statt des Dashboards, damit kaffeeliste.de und app.kaffeeliste.de aus
  demselben Webspace bedient werden koennen. Ohne gesetztes APP_HOST
  (lokale Entwicklung) unveraendertes Verhalten.
- landing.php verlinkt Login/Registrierung ueber APP_HOST fest auf die
  App-Domain, damit Besucher der Marketingdomain dort landen.
- functionsLDAP.php entfernt (nur ueber die tote IIS/AUTH_USER-Branch
  erreichbar, vollstaendig durch app/saas-auth.php ersetzt); zugehoerige
  tote AD/LDAP-Variablen aus config.php und der AUTH_USER-Zweig aus
  functions.php entfernt.
- mailausgebe.php, umfrage.php, umfrageergebnisse.php entfernt: aus der
  Navigation nicht erreichbare Debug-/Einzweck-Seiten ohne echte
  Berechtigungspruefung (mailausgebe.php dumpte alle Mitglieder-E-Mails,
  umfrageergebnisse.php hatte nur einen auskommentierten Basic-Auth-
  Block). scripts/http-smoke.php entsprechend bereinigt.
2026-07-17 11:37:41 +02:00

312 lines
10 KiB
PHP

<?php
require_once __DIR__ . "/app/bootstrap.php";
// Marketingdomain (z. B. kaffeeliste.de) zeigt die Landingpage statt des
// Dashboards; nur der Host aus APP_HOST bekommt die eigentliche App. Ohne
// gesetztes APP_HOST (lokale Entwicklung) verhaelt sich index.php wie
// bisher immer als Dashboard.
$appHost = app_primary_host();
$requestHost = strtolower(preg_replace('/:\d+$/', '', (string)($_SERVER['HTTP_HOST'] ?? '')));
if ($appHost !== null && $requestHost !== strtolower($appHost)) {
require __DIR__ . '/landing.php';
exit;
}
include "functions.php";
require_once __DIR__ . "/app/ledger.php";
app_require_csrf();
$pdo = app_db_pdo();
$saasUser = saas_current_user($pdo);
$tenantId = 0;
$hasAccess = false;
$emailNorm = strtolower(trim($mailadress));
if ($saasUser !== null) {
$tenantId = (int)$saasUser['tenant_id'];
$emailNorm = strtolower(trim((string)$saasUser['email_norm']));
$hasAccess = true;
}
if (!$hasAccess && checkKaffeelisteAccess($conn, $mailadress)) {
$tenant = ledger_fetch_default_tenant($pdo);
if ($tenant !== null) {
$tenantId = (int)$tenant['id'];
$hasAccess = true;
}
}
$participant = null;
if ($hasAccess && $emailNorm !== '') {
$summaries = ledger_fetch_participant_summaries($pdo, $tenantId, [
'email_norms' => [$emailNorm],
]);
$participant = $summaries[0] ?? null;
}
$settings = $hasAccess ? saas_fetch_tenant_settings($pdo, $tenantId) : null;
$entryMessage = null;
$entryError = null;
function dashboard_money(int $cents): string
{
return saas_format_money_cents($cents) . ' €';
}
function dashboard_date(string $value): string
{
try {
return (new DateTimeImmutable($value))->format('d.m.Y');
} catch (Throwable $e) {
return $value;
}
}
function dashboard_current_name(?array $saasUser, ?array $participant, mixed $conn, string $mailadress): string
{
$name = trim((string)($saasUser['display_name'] ?? ''));
if ($name !== '') {
return $name;
}
$name = trim((string)($participant['display_name'] ?? ''));
if ($name !== '') {
return $name;
}
return trim((string)getUserName($conn, $mailadress));
}
function dashboard_paypal_action(string $template, string $amount): string
{
return trim($template) . $amount;
}
/**
* @return array{ok: bool, message?: string, error?: string}
*/
function dashboard_record_legacy_self_entry(PDO $pdo, array $participant, array $settings, mixed $marksValue): array
{
$legacyMitarbeiterId = $participant['legacy_mitarbeiter_id'] !== null
? (int)$participant['legacy_mitarbeiter_id']
: 0;
if ($legacyMitarbeiterId <= 0) {
return ['ok' => false, 'error' => 'Für diesen Teilnehmer ist die eigene Stricherfassung noch nicht verfügbar.'];
}
if ((int)$settings['self_entry_enabled'] !== 1) {
return ['ok' => false, 'error' => 'Die eigene Stricherfassung ist aktuell deaktiviert.'];
}
$marks = filter_var($marksValue, FILTER_VALIDATE_INT);
if ($marks !== 1 && $marks !== 2) {
return ['ok' => false, 'error' => 'Bitte einen oder zwei Striche auswählen.'];
}
$unitPriceCents = (int)$settings['mark_price_cents'];
if ($unitPriceCents <= 0) {
return ['ok' => false, 'error' => 'Der Preis pro Strich ist nicht gültig konfiguriert.'];
}
$bookedAt = date('Y-m-d H:i:s');
$cost = (($marks * $unitPriceCents) / 100);
$unitPrice = ($unitPriceCents / 100);
try {
$pdo->beginTransaction();
$stmt = $pdo->prepare(
'INSERT INTO kl_Kaffeeverbrauch
(MitarbeiterID, AnzahlStriche, Kosten, KostenproStrich, Datum, Eintragsart)
VALUES (?, ?, ?, ?, ?, 2)'
);
$stmt->execute([$legacyMitarbeiterId, $marks, $cost, $unitPrice, $bookedAt]);
$legacyConsumptionId = (int)$pdo->lastInsertId();
if ($legacyConsumptionId <= 0) {
throw new RuntimeException('Legacy-Strich konnte nicht angelegt werden.');
}
ledger_mirror_legacy_consumption($pdo, (int)$participant['tenant_id'], $legacyConsumptionId);
$pdo->commit();
} catch (Throwable $e) {
if ($pdo->inTransaction()) {
$pdo->rollBack();
}
return ['ok' => false, 'error' => 'Die Stricheintragung konnte nicht gespeichert werden.'];
}
return ['ok' => true, 'message' => 'Stricheintragung wurde erfolgreich eingetragen.'];
}
function dashboard_render_payments(array $entries): void
{
echo "<h4>Letzte Einzahlungen</h4>";
echo "<table><tr><th style='width:120px'>Datum</th><th>Einzahlung</th></tr>";
if ($entries === []) {
echo "<tr><td colspan='2'>Keine Einzahlungen vorhanden.</td></tr>";
}
foreach ($entries as $entry) {
echo "<tr>";
echo "<td>" . saas_html(dashboard_date((string)$entry['booked_at'])) . "</td>";
echo "<td>" . saas_html(dashboard_money((int)$entry['amount_cents'])) . "</td>";
echo "</tr>";
}
echo "</table>";
}
function dashboard_render_consumption(array $entries): void
{
echo "<h4>Letzte Striche</h4>";
echo "<table><tr><th style='width:120px'>Datum</th><th>Striche</th><th>Kosten</th></tr>";
if ($entries === []) {
echo "<tr><td colspan='3'>Keine Striche vorhanden.</td></tr>";
}
foreach ($entries as $entry) {
echo "<tr>";
echo "<td>" . saas_html(dashboard_date((string)$entry['booked_at'])) . "</td>";
echo "<td>" . number_format((int)($entry['marks_count'] ?? 0), 0, ',', '.') . "</td>";
echo "<td>" . saas_html(dashboard_money(abs((int)$entry['amount_cents']))) . "</td>";
echo "</tr>";
}
echo "</table>";
}
if ($_SERVER["REQUEST_METHOD"] === "POST") {
if ($hasAccess && $participant !== null && $settings !== null) {
$result = dashboard_record_legacy_self_entry($pdo, $participant, $settings, $_POST["anzahlStriche"] ?? null);
if ($result['ok']) {
$entryMessage = $result['message'] ?? null;
$participant = ledger_fetch_participant_summary($pdo, $tenantId, (int)$participant['participant_id']);
} else {
$entryError = $result['error'] ?? 'Die Stricheintragung konnte nicht gespeichert werden.';
}
} else {
$entryError = 'Die Stricheintragung konnte nicht gespeichert werden.';
}
}
$paymentEntries = $participant !== null
? ledger_fetch_recent_entries($pdo, $tenantId, [
'participant_id' => $participant['participant_id'],
'type' => 'payment',
'limit' => 100,
])
: [];
$consumptionEntries = $participant !== null
? ledger_fetch_recent_entries($pdo, $tenantId, [
'participant_id' => $participant['participant_id'],
'type' => 'consumption',
'limit' => 100,
])
: [];
include "header.php";
include "headerline.php";
include "nav.php";
?>
<section id="banner">
<div class="content">
<?php
if ($hasAccess && $participant !== null && $settings !== null) {
$balanceCents = (int)$participant['balance_cents'];
$balance = dashboard_money($balanceCents);
$currentName = dashboard_current_name($saasUser, $participant, $conn, $mailadress);
$selfEntryEnabled = (int)$settings['self_entry_enabled'] === 1
&& $participant['legacy_mitarbeiter_id'] !== null;
$paypalEnabled = (int)$settings['paypal_enabled'] === 1
&& trim((string)$settings['paypal_url_template']) !== '';
?>
<h2>Kaffeeliste</h2>
<?php if ($currentName !== ''): ?>
Hallo <?php echo saas_html($currentName); ?>!<br><br>
<?php endif; ?>
<?php if ($entryMessage !== null): ?>
<div class="hint-box success"><p><b><?php echo saas_html($entryMessage); ?></b><br>Du kannst den Eintrag weiter unten kontrollieren.</p></div><br>
<?php endif; ?>
<?php if ($entryError !== null): ?>
<div class="hint-box error"><p><b><?php echo saas_html($entryError); ?></b></p></div><br>
<?php endif; ?>
<?php
if ($balanceCents > 0) {
echo "<p><b>Aktueller Stand: " . saas_html($balance) . " (Guthaben)</b></p>";
} elseif ($balanceCents < 0) {
echo "<p><b>Aktueller Stand: " . saas_html($balance) . " (Schulden)</b></p>";
} else {
echo "<p><b>Aktueller Stand: " . saas_html($balance) . "</b></p>";
}
?>
<h2>Jahresübersicht</h2>
Ausgabe im aktuellen Jahr: <?php echo saas_html(dashboard_money((int)$participant['year_costs_cents'])); ?><br>
Gesamtstriche im aktuellen Jahr: <?php echo number_format((int)$participant['year_marks'], 0, ',', '.'); ?><br>
<p>Gesamteinzahlung im aktuellen Jahr: <?php echo saas_html(dashboard_money((int)$participant['year_payments_cents'])); ?></p>
<?php if ($selfEntryEnabled): ?>
<h2>Eintrag in die Strichliste</h2>
<b>Hier kannst du einen oder zwei Striche für dich in der Kaffeeliste eintragen. <br>Dafür benötigst du keinen Eintrag auf der Liste durchführen.</b><br>
Aktueller Preis pro Strich: <?php echo saas_html(dashboard_money((int)$settings['mark_price_cents'])); ?><br><br>
<ul class="actions">
<li>
<form method="post" action="index.php">
<button type="submit">Einen Strich eintragen</button>
<input type="hidden" name="anzahlStriche" value="1">
<?php echo app_csrf_field(); ?>
</form>
</li>
<li>
<form method="post" action="index.php">
<button type="submit">Zwei Striche eintragen</button>
<input type="hidden" name="anzahlStriche" value="2">
<?php echo app_csrf_field(); ?>
</form>
</li>
</ul>
<?php endif; ?>
<?php if ($paypalEnabled): ?>
<h2>PayPal-Einzahlungen</h2>
<b>Bezahle immer über die Freunde-Funktion von PayPal. Ansonsten stellen wir 20% des Betrags als Gebühr in Rechnung.</b><br>
<br>
<?php
$paypalTemplate = trim((string)$settings['paypal_url_template']);
if ($balanceCents < 0) {
$debtCents = abs($balanceCents);
$debtAmount = dashboard_money($debtCents);
echo '<form action="' . saas_html(dashboard_paypal_action($paypalTemplate, saas_format_money_cents($debtCents))) . '" target="_blank"><button type="submit">' . saas_html($debtAmount) . ' bezahlen</button></form>';
}
?>
<ul class="actions">
<li><form action="<?php echo saas_html(dashboard_paypal_action($paypalTemplate, '5')); ?>" target="_blank"><button type="submit">5,00 € einzahlen</button></form></li>
<li><form action="<?php echo saas_html(dashboard_paypal_action($paypalTemplate, '10')); ?>" target="_blank"><button type="submit">10,00 € einzahlen</button></form></li>
<li><form action="<?php echo saas_html(dashboard_paypal_action($paypalTemplate, '15')); ?>" target="_blank"><button type="submit">15,00 € einzahlen</button></form></li>
</ul>
<?php endif; ?>
<br><br>
<?php
dashboard_render_payments($paymentEntries);
echo "<br>";
dashboard_render_consumption($consumptionEntries);
?>
<br><br>
<form action="namenanpassen.php" method="get">
<button type="submit">Namensanpassung</button>
</form>
<?php
} elseif ($hasAccess) {
echo "<h2>Kaffeeliste</h2>";
echo "<p>Für dein Konto wurde im aktuellen Mandanten kein Teilnehmer gefunden.</p>";
} else {
echo "<h2>Sie haben keinen Zugang zu dieser Webseite</h2>";
}
?>
</div>
</section>
<?php include "footer.php"; ?>