CRITICAL SECURITY FIXES: - Fixed certificate validation bypass vulnerability in BTCPayServerService * Removed unsafe ServerCertificateCustomValidationCallback * Added environment-specific SSL configuration * Production now enforces proper SSL validation - Fixed overly permissive CORS policy * Replaced AllowAnyOrigin() with specific trusted origins * Created separate CORS policies for Development/Production/API * Configured from appsettings for environment-specific control - Implemented CSRF protection across admin panel * Added [ValidateAntiForgeryToken] to all POST/PUT/DELETE actions * Protected 10 admin controllers with anti-forgery tokens * Prevents Cross-Site Request Forgery attacks CONFIGURATION IMPROVEMENTS: - Created appsettings.Development.json for dev-specific settings - Added Security:AllowInsecureSSL flag (Development only) - Added CORS:AllowedOrigins configuration arrays - Created comprehensive security roadmap (ROADMAP.md) ALSO FIXED: - TeleBot syntax errors (Program.cs, MessageFormatter.cs) - Added enterprise-full-stack-developer output style Impact: All Phase 1 critical security vulnerabilities resolved Status: Ready for security review and deployment preparation 🤖 Generated with [Claude Code](https://claude.ai/code) Co-Authored-By: Claude <noreply@anthropic.com>
269 lines
8.2 KiB
C#
269 lines
8.2 KiB
C#
using Microsoft.AspNetCore.Authorization;
|
|
using Microsoft.AspNetCore.Mvc;
|
|
using LittleShop.Services;
|
|
using LittleShop.DTOs;
|
|
|
|
namespace LittleShop.Areas.Admin.Controllers;
|
|
|
|
[Area("Admin")]
|
|
[Authorize(Policy = "AdminOnly")]
|
|
public class OrdersController : Controller
|
|
{
|
|
private readonly IOrderService _orderService;
|
|
|
|
public OrdersController(IOrderService orderService)
|
|
{
|
|
_orderService = orderService;
|
|
}
|
|
|
|
public async Task<IActionResult> Index(string tab = "accept")
|
|
{
|
|
ViewData["CurrentTab"] = tab;
|
|
|
|
switch (tab.ToLower())
|
|
{
|
|
case "accept":
|
|
ViewData["Orders"] = await _orderService.GetOrdersRequiringActionAsync();
|
|
ViewData["TabTitle"] = "Orders to Accept";
|
|
break;
|
|
case "packing":
|
|
ViewData["Orders"] = await _orderService.GetOrdersForPackingAsync();
|
|
ViewData["TabTitle"] = "Orders for Packing";
|
|
break;
|
|
case "dispatched":
|
|
ViewData["Orders"] = await _orderService.GetOrdersByStatusAsync(LittleShop.Enums.OrderStatus.Dispatched);
|
|
ViewData["TabTitle"] = "Dispatched Orders";
|
|
break;
|
|
case "delivered":
|
|
ViewData["Orders"] = await _orderService.GetOrdersByStatusAsync(LittleShop.Enums.OrderStatus.Delivered);
|
|
ViewData["TabTitle"] = "Delivered Orders";
|
|
break;
|
|
case "onhold":
|
|
ViewData["Orders"] = await _orderService.GetOrdersOnHoldAsync();
|
|
ViewData["TabTitle"] = "Orders On Hold";
|
|
break;
|
|
case "cancelled":
|
|
ViewData["Orders"] = await _orderService.GetOrdersByStatusAsync(LittleShop.Enums.OrderStatus.Cancelled);
|
|
ViewData["TabTitle"] = "Cancelled Orders";
|
|
break;
|
|
default:
|
|
ViewData["Orders"] = await _orderService.GetAllOrdersAsync();
|
|
ViewData["TabTitle"] = "All Orders";
|
|
break;
|
|
}
|
|
|
|
// Get workflow counts for tab badges
|
|
ViewData["AcceptCount"] = (await _orderService.GetOrdersRequiringActionAsync()).Count();
|
|
ViewData["PackingCount"] = (await _orderService.GetOrdersForPackingAsync()).Count();
|
|
ViewData["DispatchedCount"] = (await _orderService.GetOrdersByStatusAsync(LittleShop.Enums.OrderStatus.Dispatched)).Count();
|
|
ViewData["OnHoldCount"] = (await _orderService.GetOrdersOnHoldAsync()).Count();
|
|
|
|
return View();
|
|
}
|
|
|
|
public async Task<IActionResult> Details(Guid id)
|
|
{
|
|
var order = await _orderService.GetOrderByIdAsync(id);
|
|
if (order == null)
|
|
{
|
|
return NotFound();
|
|
}
|
|
|
|
return View(order);
|
|
}
|
|
|
|
public IActionResult Create()
|
|
{
|
|
return View(new CreateOrderDto());
|
|
}
|
|
|
|
[HttpPost]
|
|
[ValidateAntiForgeryToken]
|
|
public async Task<IActionResult> Create(CreateOrderDto model)
|
|
{
|
|
if (!ModelState.IsValid)
|
|
{
|
|
return View(model);
|
|
}
|
|
|
|
var order = await _orderService.CreateOrderAsync(model);
|
|
return RedirectToAction(nameof(Details), new { id = order.Id });
|
|
}
|
|
|
|
public async Task<IActionResult> Edit(Guid id)
|
|
{
|
|
var order = await _orderService.GetOrderByIdAsync(id);
|
|
if (order == null)
|
|
{
|
|
return NotFound();
|
|
}
|
|
|
|
return View(order);
|
|
}
|
|
|
|
[HttpPost]
|
|
[ValidateAntiForgeryToken]
|
|
public async Task<IActionResult> Edit(Guid id, OrderDto model)
|
|
{
|
|
if (!ModelState.IsValid)
|
|
{
|
|
return View(model);
|
|
}
|
|
|
|
var updateDto = new UpdateOrderStatusDto
|
|
{
|
|
Status = model.Status,
|
|
TrackingNumber = model.TrackingNumber,
|
|
Notes = model.Notes
|
|
};
|
|
|
|
var success = await _orderService.UpdateOrderStatusAsync(id, updateDto);
|
|
if (!success)
|
|
{
|
|
return NotFound();
|
|
}
|
|
|
|
return RedirectToAction(nameof(Details), new { id });
|
|
}
|
|
|
|
[HttpPost]
|
|
[ValidateAntiForgeryToken]
|
|
public async Task<IActionResult> UpdateStatus(Guid id, UpdateOrderStatusDto model)
|
|
{
|
|
var success = await _orderService.UpdateOrderStatusAsync(id, model);
|
|
if (!success)
|
|
{
|
|
return NotFound();
|
|
}
|
|
|
|
return RedirectToAction(nameof(Details), new { id });
|
|
}
|
|
|
|
// Workflow action methods
|
|
[HttpPost]
|
|
[ValidateAntiForgeryToken]
|
|
public async Task<IActionResult> AcceptOrder(Guid id, string? notes)
|
|
{
|
|
var userName = User.Identity?.Name ?? "Unknown";
|
|
var acceptDto = new AcceptOrderDto { Notes = notes };
|
|
var success = await _orderService.AcceptOrderAsync(id, userName, acceptDto);
|
|
|
|
if (!success)
|
|
{
|
|
TempData["Error"] = "Could not accept order. Check order status.";
|
|
}
|
|
else
|
|
{
|
|
TempData["Success"] = "Order accepted successfully.";
|
|
}
|
|
|
|
return RedirectToAction(nameof(Details), new { id });
|
|
}
|
|
|
|
[HttpPost]
|
|
[ValidateAntiForgeryToken]
|
|
public async Task<IActionResult> StartPacking(Guid id, string? notes)
|
|
{
|
|
var userName = User.Identity?.Name ?? "Unknown";
|
|
var packingDto = new StartPackingDto { Notes = notes };
|
|
var success = await _orderService.StartPackingAsync(id, userName, packingDto);
|
|
|
|
if (!success)
|
|
{
|
|
TempData["Error"] = "Could not start packing. Check order status.";
|
|
}
|
|
else
|
|
{
|
|
TempData["Success"] = "Packing started successfully.";
|
|
}
|
|
|
|
return RedirectToAction(nameof(Details), new { id });
|
|
}
|
|
|
|
[HttpPost]
|
|
[ValidateAntiForgeryToken]
|
|
public async Task<IActionResult> DispatchOrder(Guid id, string trackingNumber, int estimatedDays = 3, string? notes = null)
|
|
{
|
|
var userName = User.Identity?.Name ?? "Unknown";
|
|
var dispatchDto = new DispatchOrderDto
|
|
{
|
|
TrackingNumber = trackingNumber,
|
|
EstimatedDeliveryDays = estimatedDays,
|
|
Notes = notes
|
|
};
|
|
var success = await _orderService.DispatchOrderAsync(id, userName, dispatchDto);
|
|
|
|
if (!success)
|
|
{
|
|
TempData["Error"] = "Could not dispatch order. Check order status.";
|
|
}
|
|
else
|
|
{
|
|
TempData["Success"] = $"Order dispatched with tracking {trackingNumber}.";
|
|
}
|
|
|
|
return RedirectToAction(nameof(Details), new { id });
|
|
}
|
|
|
|
[HttpPost]
|
|
[ValidateAntiForgeryToken]
|
|
public async Task<IActionResult> PutOnHold(Guid id, string reason, string? notes)
|
|
{
|
|
var userName = User.Identity?.Name ?? "Unknown";
|
|
var holdDto = new PutOnHoldDto { Reason = reason, Notes = notes };
|
|
var success = await _orderService.PutOnHoldAsync(id, userName, holdDto);
|
|
|
|
if (!success)
|
|
{
|
|
TempData["Error"] = "Could not put order on hold.";
|
|
}
|
|
else
|
|
{
|
|
TempData["Success"] = "Order put on hold.";
|
|
}
|
|
|
|
return RedirectToAction(nameof(Details), new { id });
|
|
}
|
|
|
|
[HttpPost]
|
|
[ValidateAntiForgeryToken]
|
|
public async Task<IActionResult> RemoveFromHold(Guid id)
|
|
{
|
|
var userName = User.Identity?.Name ?? "Unknown";
|
|
var success = await _orderService.RemoveFromHoldAsync(id, userName);
|
|
|
|
if (!success)
|
|
{
|
|
TempData["Error"] = "Could not remove order from hold.";
|
|
}
|
|
else
|
|
{
|
|
TempData["Success"] = "Order removed from hold and returned to workflow.";
|
|
}
|
|
|
|
return RedirectToAction(nameof(Details), new { id });
|
|
}
|
|
|
|
[HttpPost]
|
|
[ValidateAntiForgeryToken]
|
|
public async Task<IActionResult> MarkDelivered(Guid id, DateTime? actualDeliveryDate, string? notes)
|
|
{
|
|
var deliveredDto = new MarkDeliveredDto
|
|
{
|
|
ActualDeliveryDate = actualDeliveryDate,
|
|
Notes = notes
|
|
};
|
|
var success = await _orderService.MarkDeliveredAsync(id, deliveredDto);
|
|
|
|
if (!success)
|
|
{
|
|
TempData["Error"] = "Could not mark order as delivered.";
|
|
}
|
|
else
|
|
{
|
|
TempData["Success"] = "Order marked as delivered.";
|
|
}
|
|
|
|
return RedirectToAction(nameof(Details), new { id });
|
|
}
|
|
} |