Files
unsupervised-scheduler/src/Policy/PolicyController.php
T
thatguygriffandClaude Opus 5 cb347ffca0
CI / Tests (PHP 8.1) (pull_request) Successful in 1m0s
CI / Tests (PHP 8.2) (pull_request) Successful in 1m0s
CI / No Debug Code (pull_request) Successful in 3s
CI / Coding Standards (pull_request) Successful in 3m8s
CI / Build Plugin Zip (pull_request) Skipped
CI / PHPStan (pull_request) Successful in 2m49s
CI / Tests (PHP 8.3) (pull_request) Successful in 2m44s
Demo follow-ups: editable policy name, one-page signup, group classes in upcoming lessons, deletion cleanup
Five items from the latest demo pass:

- A policy's title can be edited from the Policies screen. Only the title
  moves; the slug is what the gates resolve policies by, so a rename can
  never detach a policy from acceptances already recorded against it.
- Signup is one page again. The studio's registration questions move from
  a second step behind "Next" onto the main form, in an "About you" panel
  above the students being added, and that panel also asks an adult
  student for their birth year (the same us_birth_year meta a child's
  uses). register.js disables and hides the whole panel for a pure
  guardian, since the questions describe a student.
- The password is re-scored on submit, not only as it is typed. zxcvbn's
  dictionary arrives after page load, so a password typed straight away
  was never scored at all and the first the student heard of it was the
  server rejecting the whole form.
- Group-class sessions appear alongside lessons wherever upcoming lessons
  are listed: the [us_scheduler] panel (students and instructors) and the
  admin student detail page. GroupClass\SessionSchedule derives them from
  Offering::sessionWindows(), the same derivation the billing scan uses.
  They carry kind = 'group_class' and no Cancel action - a session is one
  date in a term, not a booked slot.
- Deleting a user releases what the account was holding: each upcoming
  lesson is cancelled, its slot freed for rebooking, its pending payment
  voided, and active class enrolments cancelled. Past lessons and paid
  history are left alone.

Tests: composer test (851), composer lint, composer cs all pass.

Co-Authored-By: Claude Opus 5 <[email protected]>
2026-07-30 11:45:04 -03:00

161 lines
5.3 KiB
PHP

<?php
declare(strict_types=1);
namespace Unsupervised\Schedular\Policy;
use Unsupervised\Schedular\Auth\RoleManager;
use Unsupervised\Schedular\Val;
class PolicyController {
public function __construct(
private PolicyRepository $policies,
private PolicyVersionRepository $versions,
private PolicyService $service,
) {}
public function renderPage(): void {
if ( ! current_user_can( RoleManager::CAP_MANAGE_POLICIES ) ) {
wp_die( esc_html__( 'You do not have permission to manage policies.', 'unsupervised-schedular' ) );
}
$notice = '';
$viewVersionId = 0;
if ( isset( $_POST['usc_action'] ) && check_admin_referer( 'usc_policy_action' ) ) {
[ $notice, $viewVersionId ] = $this->handleFormAction();
}
// phpcs:disable WordPress.Security.NonceVerification.Recommended -- read-only policy/version selectors.
$policyId = absint( Val::int( $_GET['policy_id'] ?? 0 ) );
if ( 0 === $viewVersionId ) {
$viewVersionId = absint( Val::int( $_GET['version_id'] ?? 0 ) );
}
// phpcs:enable WordPress.Security.NonceVerification.Recommended
$policyList = $this->policies->findAll();
$selectedPolicy = $policyId > 0 ? $this->policies->findById( $policyId ) : null;
$policyVersions = null !== $selectedPolicy ? $this->versions->findByPolicy( (int) $selectedPolicy->id ) : null;
$viewedVersion = null !== $selectedPolicy ? $this->loadVersionForPolicy( (int) $selectedPolicy->id, $viewVersionId ) : null;
include USC_PLUGIN_DIR . 'templates/admin/policies.php';
}
/**
* Process the posted action.
*
* @return array{string, int} Status notice, and the version to open in the
* viewer (0 to leave the current selection alone).
*/
private function handleFormAction(): array {
// Nonce is verified by the caller (renderPage) before this method runs.
// phpcs:disable WordPress.Security.NonceVerification.Missing
$action = sanitize_key( Val::string( wp_unslash( $_POST['usc_action'] ?? '' ) ) );
if ( 'create_policy' === $action ) {
$title = sanitize_text_field( Val::string( wp_unslash( $_POST['title'] ?? '' ) ) );
$slugRaw = sanitize_text_field( Val::string( wp_unslash( $_POST['slug'] ?? '' ) ) );
$slug = sanitize_title( '' !== $slugRaw ? $slugRaw : $title );
$scope = sanitize_key( Val::string( wp_unslash( $_POST['acceptance_scope'] ?? Policy::SCOPE_BOOKING ) ) );
if ( ! in_array( $scope, Policy::VALID_SCOPES, true ) ) {
$scope = Policy::SCOPE_BOOKING;
}
$withinLimits = mb_strlen( $title ) <= Policy::MAX_TITLE_LENGTH && mb_strlen( $slug ) <= Policy::MAX_SLUG_LENGTH;
if ( '' !== $title && '' !== $slug && $withinLimits && null === $this->policies->findBySlug( $slug ) ) {
$this->service->createPolicy( $title, $slug, $scope );
}
return [ '', 0 ];
}
$policyId = absint( Val::int( $_POST['policy_id'] ?? 0 ) );
if ( $policyId <= 0 || null === $this->policies->findById( $policyId ) ) {
return [ '', 0 ];
}
if ( 'rename_policy' === $action ) {
$title = trim( sanitize_text_field( Val::string( wp_unslash( $_POST['title'] ?? '' ) ) ) );
if ( '' === $title || mb_strlen( $title ) > Policy::MAX_TITLE_LENGTH ) {
return [ '', 0 ];
}
$this->policies->updateTitle( $policyId, $title );
return [
sprintf(
/* translators: %s: the policy's new title. */
__( 'Policy renamed to "%s".', 'unsupervised-schedular' ),
$title
),
0,
];
}
if ( 'add_version' === $action ) {
$body = wp_kses_post( Val::string( wp_unslash( $_POST['body'] ?? '' ) ) );
$this->service->addDraftVersion( $policyId, $body );
}
if ( 'edit_version' === $action ) {
$source = $this->loadVersionForPolicy( $policyId, absint( Val::int( $_POST['version_id'] ?? 0 ) ) );
if ( null === $source ) {
return [ '', 0 ];
}
$body = wp_kses_post( Val::string( wp_unslash( $_POST['body'] ?? '' ) ) );
// A draft has never been shown to a student, so it is edited in place.
// A published (or archived) version is what students accepted, so an
// edit branches a new draft and leaves the original untouched.
if ( PolicyVersion::STATUS_DRAFT === $source->status ) {
$this->versions->updateBody( (int) $source->id, $body );
return [
sprintf(
/* translators: %d: the edited version number. */
__( 'Draft version %d was updated.', 'unsupervised-schedular' ),
$source->versionNumber
),
(int) $source->id,
];
}
return [
sprintf(
/* translators: %d: the version number the edit was based on. */
__( 'Your changes to version %d were saved as a new draft version.', 'unsupervised-schedular' ),
$source->versionNumber
),
$this->service->addDraftVersion( $policyId, $body ),
];
}
if ( 'publish_version' === $action ) {
$versionId = absint( Val::int( $_POST['version_id'] ?? 0 ) );
if ( $versionId > 0 ) {
$this->service->publishVersion( $policyId, $versionId );
}
}
// phpcs:enable WordPress.Security.NonceVerification.Missing
return [ '', 0 ];
}
/**
* Load a version by id, confirming it belongs to the given policy.
*/
private function loadVersionForPolicy( int $policyId, int $versionId ): ?PolicyVersion {
if ( $versionId <= 0 ) {
return null;
}
$version = $this->versions->findById( $versionId );
return null !== $version && $version->policyId === $policyId ? $version : null;
}
}