fix: Double-charged shipping fee in Yoco payment + ops staff access

1. Fix Yoco payment amount calculation: order->total already includes
   shipping_fee, so don't add it again. Was charging 2x shipping.

2. Add authorization gate for ops staff access: users with is_admin=true
   can now access the ops page by scanning QR codes.
This commit is contained in:
twotalesanimation
2026-01-02 21:07:21 +02:00
parent ed57956694
commit 4a8b4ddac2
3 changed files with 29 additions and 1 deletions
+1 -1
View File
@@ -296,7 +296,7 @@ class OrderController extends Controller
: 'https://payments.yoco.com/api/checkouts'; : 'https://payments.yoco.com/api/checkouts';
$checkoutData = [ $checkoutData = [
'amount' => (int)(($order->total + $order->shipping_fee) * 100), // Amount in cents, including shipping 'amount' => (int)($order->total * 100), // Amount in cents (total already includes shipping)
'currency' => 'ZAR', 'currency' => 'ZAR',
'successUrl' => route('yoco-success', ['order' => $order->uuid]), 'successUrl' => route('yoco-success', ['order' => $order->uuid]),
'cancelUrl' => route('yoco-cancel', ['order' => $order->uuid]), 'cancelUrl' => route('yoco-cancel', ['order' => $order->uuid]),
+6
View File
@@ -30,5 +30,11 @@ class AppServiceProvider extends ServiceProvider
$cartCount = session('cart') ? count(session('cart')) : 0; $cartCount = session('cart') ? count(session('cart')) : 0;
$view->with('cartCount', $cartCount); $view->with('cartCount', $cartCount);
}); });
// Authorization gates
\Illuminate\Support\Facades\Gate::define('access-ops', function ($user) {
// Allow admin users to access ops
return $user->is_admin === true;
});
} }
} }
@@ -0,0 +1,22 @@
<?php $__env->startSection('content'); ?>
<div class="container mx-auto px-4 py-8">
<div class="bg-yellow-50 border-2 border-yellow-200 rounded-lg p-8 text-center">
<h1 class="text-4xl font-bold text-yellow-900 mb-3">🔒 Access Denied</h1>
<p class="text-yellow-700 mb-6 text-lg">
You do not have permission to access this page. Only operations staff can view QR-based order interfaces.
</p>
<?php if(\Livewire\Mechanisms\ExtendBlade\ExtendBlade::isRenderingLivewireComponent()): ?><!--[if BLOCK]><![endif]--><?php endif; ?><?php if(auth()->check()): ?>
<p class="text-gray-600 mb-6">
Logged in as: <strong><?php echo e(auth()->user()->name); ?></strong>
</p>
<?php endif; ?><?php if(\Livewire\Mechanisms\ExtendBlade\ExtendBlade::isRenderingLivewireComponent()): ?><!--[if ENDBLOCK]><![endif]--><?php endif; ?>
<a href="<?php echo e(route('home')); ?>" class="inline-block bg-blue-600 hover:bg-blue-700 text-white font-bold py-2 px-6 rounded">
Return Home
</a>
</div>
</div>
<?php $__env->stopSection(); ?>
<?php echo $__env->make('layouts.app', array_diff_key(get_defined_vars(), ['__data' => 1, '__path' => 1]))->render(); ?><?php /**PATH /var/www/additional_design/resources/views/ops/unauthorized.blade.php ENDPATH**/ ?>