Add admin actions to the student detail view: cancel, withdraw, edit account
CI / Tests (PHP 8.2) (pull_request) Successful in 43s
CI / No Debug Code (pull_request) Successful in 2s
CI / Tests (PHP 8.3) (pull_request) Successful in 2m37s
CI / Tests (PHP 8.1) (pull_request) Successful in 44s
CI / Coding Standards (pull_request) Successful in 2m43s
CI / PHPStan (pull_request) Successful in 2m50s
CI / Build Plugin Zip (pull_request) Skipped

Adds the #70 follow-up onto the student detail page: studio admins can now
cancel an upcoming lesson (same path as student cancellation — slot freed,
pending payment voided), withdraw an active group-class enrolment (seat
freed, pending payment voided), and edit the student's display name and
email with validation and uniqueness checks.

Action logic lives in the new Auth\StudentActions (unit-tested with mocked
repositories); the controller routes nonce-protected POSTs to it and shows
success/error notices.

Closes #70

Co-Authored-By: Claude Fable 5 <[email protected]>
This commit is contained in:
2026-07-18 18:25:12 -03:00
co-authored by Claude Fable 5
parent c49171695a
commit 5808523140
6 changed files with 393 additions and 15 deletions
+46 -1
View File
@@ -22,6 +22,7 @@ class StudentController {
private EnrollmentRepository $enrollments,
private BillingMethodResolver $resolver,
private StudentHistory $history,
private StudentActions $actions,
) {}
public function renderPage(): void {
@@ -66,7 +67,13 @@ class StudentController {
private function renderDetail( \WP_User $student ): void {
$canBilling = current_user_can( RoleManager::CAP_MANAGE_BILLING );
if ( $canBilling && isset( $_POST['usc_action'] ) && check_admin_referer( 'usc_student_billing' ) ) {
// phpcs:ignore WordPress.Security.NonceVerification.Missing -- routing only; each action below verifies its own nonce.
$action = sanitize_key( Val::string( wp_unslash( $_POST['usc_action'] ?? '' ) ) );
$notice = '';
$error = '';
if ( $canBilling && 'set_billing' === $action && check_admin_referer( 'usc_student_billing' ) ) {
// phpcs:ignore WordPress.Security.NonceVerification.Missing -- nonce checked above.
$method = sanitize_key( Val::string( wp_unslash( $_POST['payment_method'] ?? '' ) ) );
if ( in_array( $method, Payment::VALID_METHODS, true ) ) {
@@ -76,6 +83,42 @@ class StudentController {
}
}
if ( 'update_account' === $action && check_admin_referer( 'usc_student_actions' ) ) {
// phpcs:disable WordPress.Security.NonceVerification.Missing -- nonce checked above.
$displayName = sanitize_text_field( Val::string( wp_unslash( $_POST['display_name'] ?? '' ) ) );
$email = sanitize_email( Val::string( wp_unslash( $_POST['user_email'] ?? '' ) ) );
// phpcs:enable WordPress.Security.NonceVerification.Missing
$result = $this->actions->updateAccount( (int) $student->ID, $displayName, $email );
if ( $result instanceof \WP_Error ) {
$error = $result->get_error_message();
} else {
$notice = __( 'Account details updated.', 'unsupervised-schedular' );
$fresh = get_userdata( (int) $student->ID );
$student = $fresh instanceof \WP_User ? $fresh : $student;
}
}
if ( 'cancel_lesson' === $action && check_admin_referer( 'usc_student_actions' ) ) {
// phpcs:ignore WordPress.Security.NonceVerification.Missing -- nonce checked above.
$lessonId = absint( Val::int( $_POST['lesson_id'] ?? 0 ) );
if ( $this->actions->cancelLesson( $lessonId, (int) $student->ID ) ) {
$notice = __( 'Lesson cancelled.', 'unsupervised-schedular' );
} else {
$error = __( 'This lesson could not be cancelled.', 'unsupervised-schedular' );
}
}
if ( 'withdraw_enrollment' === $action && check_admin_referer( 'usc_student_actions' ) ) {
// phpcs:ignore WordPress.Security.NonceVerification.Missing -- nonce checked above.
$enrollmentId = absint( Val::int( $_POST['enrollment_id'] ?? 0 ) );
if ( $this->actions->withdrawEnrollment( $enrollmentId, (int) $student->ID ) ) {
$notice = __( 'Enrolment withdrawn.', 'unsupervised-schedular' );
} else {
$error = __( 'This enrolment could not be withdrawn.', 'unsupervised-schedular' );
}
}
$billingOverride = Val::string( get_user_meta( (int) $student->ID, BillingMethodResolver::META_METHOD, true ) );
$billingDefault = $this->resolver->defaultMethod();
@@ -94,6 +137,7 @@ class StudentController {
$offering = $this->offerings->findById( $enrollment->offeringId );
return [
'id' => (int) $enrollment->id,
'offering' => $offering ? $offering->title : (string) $enrollment->offeringId,
'status' => $enrollment->status,
];
@@ -120,6 +164,7 @@ class StudentController {
$instructor = get_userdata( $lesson->instructorId );
return [
'id' => (int) $lesson->id,
'start_dt' => $slot ? $slot->startDt : '',
'end_dt' => $slot ? $slot->endDt : '',
'offering' => $offering ? $offering->title : '—',