Auftrags-Controller: PDF-Download: nur Dateien aus session_files erlauben.
[kivitendo-erp.git] / SL / Controller / Order.pm
1 package SL::Controller::Order;
2
3 use strict;
4 use parent qw(SL::Controller::Base);
5
6 use SL::Helper::Flash;
7 use SL::Presenter;
8 use SL::Locale::String;
9 use SL::SessionFile::Random;
10 use SL::PriceSource;
11 use SL::Form;
12
13 use SL::DB::Order;
14 use SL::DB::Customer;
15 use SL::DB::Vendor;
16 use SL::DB::TaxZone;
17 use SL::DB::Employee;
18 use SL::DB::Project;
19 use SL::DB::Default;
20 use SL::DB::Unit;
21
22 use SL::Helper::DateTime;
23 use SL::Helper::CreatePDF qw(:all);
24
25 use List::Util qw(max first);
26 use List::MoreUtils qw(none pairwise);
27 use English qw(-no_match_vars);
28 use File::Spec;
29
30 use Rose::Object::MakeMethods::Generic
31 (
32  'scalar --get_set_init' => [ qw(order valid_types type cv p) ],
33 );
34
35
36 # safety
37 __PACKAGE__->run_before('_check_auth');
38
39 __PACKAGE__->run_before('_recalc',
40                         only => [ qw(edit update save save_and_delivery_order create_pdf send_email) ]);
41
42 __PACKAGE__->run_before('_get_unalterable_data',
43                         only => [ qw(save save_and_delivery_order create_pdf send_email) ]);
44
45 #
46 # actions
47 #
48
49 sub action_add {
50   my ($self) = @_;
51
52   $self->order->transdate(DateTime->now_local());
53
54   $self->_pre_render();
55   $self->render(
56     'order/form',
57     title => $self->type eq _sales_order_type()    ? $::locale->text('Add Sales Order')
58            : $self->type eq _purchase_order_type() ? $::locale->text('Add Purchase Order')
59            : '',
60     %{$self->{template_args}}
61   );
62 }
63
64 sub action_edit {
65   my ($self) = @_;
66
67   $self->_pre_render();
68   $self->render(
69     'order/form',
70     title => $self->type eq _sales_order_type()    ? $::locale->text('Edit Sales Order')
71            : $self->type eq _purchase_order_type() ? $::locale->text('Edit Purchase Order')
72            : '',
73     %{$self->{template_args}}
74   );
75 }
76
77 sub action_update {
78   my ($self) = @_;
79
80   $self->_pre_render();
81   $self->render(
82     'order/form',
83     title => $self->type eq _sales_order_type()    ? $::locale->text('Edit Sales Order')
84            : $self->type eq _purchase_order_type() ? $::locale->text('Edit Purchase Order')
85            : '',
86     %{$self->{template_args}}
87   );
88 }
89
90 sub action_save {
91   my ($self) = @_;
92
93   my $errors = $self->_save();
94
95   if (scalar @{ $errors }) {
96     $self->js->flash('error', $_) foreach @{ $errors };
97     return $self->js->render();
98   }
99
100   flash_later('info', $::locale->text('The order has been saved'));
101   my @redirect_params = (
102     action => 'edit',
103     type   => $self->type,
104     id     => $self->order->id,
105   );
106
107   $self->redirect_to(@redirect_params);
108 }
109
110 sub action_create_pdf {
111   my ($self) = @_;
112
113   my $pdf;
114   my @errors = _create_pdf($self->order, \$pdf);
115   if (scalar @errors) {
116     return $self->js->flash('error', t8('Conversion to PDF failed: #1', $errors[0]))->render($self);
117   }
118
119   my $sfile = SL::SessionFile::Random->new(mode => "w");
120   $sfile->fh->print($pdf);
121   $sfile->fh->close;
122
123   # get temporary session filename with stripped path
124   my (undef, undef, $tmp_filename) = File::Spec->splitpath($sfile->file_name);
125   my $pdf_filename =  t8('Sales Order') . '_' . $self->order->ordnumber . '.pdf';
126
127   $self->js
128     ->run('download_pdf', $tmp_filename, $pdf_filename)
129     ->flash('info', t8('The PDF has been created'))->render($self);
130 }
131
132 sub action_download_pdf {
133   my ($self) = @_;
134
135   # given tmp_filename should contain no path, so strip if any
136   my (undef, undef, $tmp_filename) = File::Spec->splitpath($::form->{tmp_filename});
137   my $tmp_filename = File::Spec->catfile(SL::SessionFile->new->get_path, $tmp_filename);
138   return $self->send_file(
139     $tmp_filename,
140     type => 'application/pdf',
141     name => $::form->{pdf_filename},
142   );
143 }
144
145 sub action_show_email_dialog {
146   my ($self) = @_;
147
148   my $cv_method = $self->cv;
149
150   if (!$self->order->$cv_method) {
151     return $self->js->flash('error', t8('Cannot send E-mail without ' . $self->cv))
152                     ->render($self);
153   }
154
155   $self->{email}->{to}   = $self->order->contact->cp_email if $self->order->contact;
156   $self->{email}->{to} ||= $self->order->$cv_method->email;
157   $self->{email}->{cc}   = $self->order->$cv_method->cc;
158   $self->{email}->{bcc}  = join ', ', grep $_, $self->order->$cv_method->bcc, SL::DB::Default->get->global_bcc;
159   # Todo: get addresses from shipto, if any
160
161   my $form = Form->new;
162   $form->{ordnumber} = $self->order->ordnumber;
163   $form->{formname}  = $self->type;
164   $form->{type}      = $self->type;
165   $form->{language} = 'de';
166   $form->{format}   = 'pdf';
167
168   $self->{email}->{subject}             = $form->generate_email_subject();
169   $self->{email}->{attachment_filename} = $form->generate_attachment_filename();
170   $self->{email}->{message}             = $form->create_email_signature();
171
172   my $dialog_html = $self->render('order/tabs/_email_dialog', { output => 0 });
173   $self->js
174       ->run('show_email_dialog', $dialog_html)
175       ->reinit_widgets
176       ->render($self);
177 }
178
179 # Todo: handling error messages: flash is not displayed in dialog, but in the main form
180 sub action_send_email {
181   my ($self) = @_;
182
183   my $mail      = Mailer->new;
184   $mail->{from} = qq|"$::myconfig{name}" <$::myconfig{email}>|;
185   $mail->{$_}   = $::form->{email}->{$_} for qw(to cc bcc subject message);
186
187   my $pdf;
188   my @errors = _create_pdf($self->order, \$pdf, {media => 'email'});
189   if (scalar @errors) {
190     return $self->js->flash('error', t8('Conversion to PDF failed: #1', $errors[0]))->render($self);
191   }
192
193   $mail->{attachments} = [{ "content" => $pdf,
194                             "name"    => $::form->{email}->{attachment_filename} }];
195
196   if (my $err = $mail->send) {
197     return $self->js->flash('error', t8('Sending E-mail: ') . $err)
198                     ->render($self);
199   }
200
201   # internal notes
202   my $intnotes = $self->order->intnotes;
203   $intnotes   .= "\n\n" if $self->order->intnotes;
204   $intnotes   .= t8('[email]')                                                                                        . "\n";
205   $intnotes   .= t8('Date')       . ": " . $::locale->format_date_object(DateTime->now_local, precision => 'seconds') . "\n";
206   $intnotes   .= t8('To (email)') . ": " . $mail->{to}                                                                . "\n";
207   $intnotes   .= t8('Cc')         . ": " . $mail->{cc}                                                                . "\n"    if $mail->{cc};
208   $intnotes   .= t8('Bcc')        . ": " . $mail->{bcc}                                                               . "\n"    if $mail->{bcc};
209   $intnotes   .= t8('Subject')    . ": " . $mail->{subject}                                                           . "\n\n";
210   $intnotes   .= t8('Message')    . ": " . $mail->{message};
211
212   $self->js
213       ->val('#order_intnotes', $intnotes)
214       ->run('close_email_dialog')
215       ->render($self);
216 }
217
218 sub action_save_and_delivery_order {
219   my ($self) = @_;
220
221   my $errors = $self->_save();
222
223   if (scalar @{ $errors }) {
224     $self->js->flash('error', $_) foreach @{ $errors };
225     return $self->js->render();
226   }
227
228   my $delivery_order = $self->order->convert_to_delivery_order($self->order);
229
230   flash_later('info', $::locale->text('The order has been saved'));
231   my @redirect_params = (
232     controller => 'do.pl',
233     action     => 'edit',
234     type       => $delivery_order->type,
235     id         => $delivery_order->id,
236     vc         => $delivery_order->is_sales ? 'customer' : 'vendor',
237   );
238
239   $self->redirect_to(@redirect_params);
240 }
241
242 sub action_customer_vendor_changed {
243   my ($self) = @_;
244
245   if ($self->cv eq 'customer') {
246     $self->order->customer(SL::DB::Manager::Customer->find_by_or_create(id => $::form->{cv_id}));
247
248   } elsif ($self->cv eq 'vendor') {
249     $self->order->vendor(SL::DB::Manager::Vendor->find_by_or_create(id => $::form->{cv_id}));
250   }
251
252   if ($self->order->{$self->cv}->contacts && scalar @{ $self->order->{$self->cv}->contacts } > 0) {
253     $self->js->show('#cp_row');
254   } else {
255     $self->js->hide('#cp_row');
256   }
257
258   if ($self->order->{$self->cv}->shipto && scalar @{ $self->order->{$self->cv}->shipto } > 0) {
259     $self->js->show('#shipto_row');
260   } else {
261     $self->js->hide('#shipto_row');
262   }
263
264   $self->js
265     ->replaceWith('#order_cp_id',     $self->build_contact_select)
266     ->replaceWith('#order_shipto_id', $self->build_shipto_select)
267     ->val('#order_taxzone_id', $self->order->{$self->cv}->taxzone_id)
268     ->focus('#order_' . $self->cv . '_id')
269     ->render($self);
270 }
271
272 sub action_add_item {
273   my ($self) = @_;
274
275   my $form_attr = $::form->{add_item};
276
277   return unless $form_attr->{parts_id};
278
279   my $item = SL::DB::OrderItem->new;
280   $item->assign_attributes(%$form_attr);
281
282   my $part        = SL::DB::Part->new(id => $form_attr->{parts_id})->load;
283   my $cv_method   = $self->cv;
284   my $cv_discount = $self->order->$cv_method? $self->order->$cv_method->discount : 0.0;
285
286   my %new_attr;
287   $new_attr{part}        = $part;
288   $new_attr{description} = $part->description if ! $item->description;
289   $new_attr{qty}         = 1.0                if ! $item->qty;
290   $new_attr{unit}        = $part->unit;
291   $new_attr{sellprice}   = $part->sellprice   if ! $item->sellprice;
292   $new_attr{discount}    = $cv_discount       if ! $item->discount;
293
294   # add_custom_variables adds cvars to an orderitem with no cvars for saving, but
295   # they cannot be retrieved via custom_variables until the order/orderitem is
296   # saved. Adding empty custom_variables to new orderitem here solves this problem.
297   $new_attr{custom_variables} = [];
298
299   $item->assign_attributes(%new_attr);
300
301   $self->order->add_items($item);
302
303   $self->_recalc();
304
305   my $item_id = join('_', 'new', Time::HiRes::gettimeofday(), int rand 1000000000000);
306   my $row_as_html = $self->p->render('order/tabs/_row', ITEM => $item, ID => $item_id);
307
308   $self->js
309     ->append('#row_table_id', $row_as_html)
310     ->val('#add_item_parts_id', '')
311     ->val('#add_item_parts_id_name', '')
312     ->val('#add_item_description', '')
313     ->val('#add_item_qty_as_number', '')
314     ->val('#add_item_sellprice_as_number', '')
315     ->val('#add_item_discount_as_percent', '')
316     ->run('row_table_scroll_down')
317     ->run('row_set_keyboard_events_by_id', $item_id)
318     ->on('.recalc', 'change', 'recalc_amounts_and_taxes')
319     ->focus('#add_item_parts_id_name');
320
321   $self->_js_redisplay_amounts_and_taxes;
322   $self->js->render();
323 }
324
325 sub action_recalc_amounts_and_taxes {
326   my ($self) = @_;
327
328   $self->_recalc();
329
330   $self->_js_redisplay_linetotals;
331   $self->_js_redisplay_amounts_and_taxes;
332   $self->js->render();
333 }
334
335 sub _js_redisplay_linetotals {
336   my ($self) = @_;
337
338   my @data = map {$::form->format_amount(\%::myconfig, $_->{linetotal}, 2, 0)} @{ $self->order->items };
339   $self->js
340     ->run('redisplay_linetotals', \@data);
341 }
342
343 sub _js_redisplay_amounts_and_taxes {
344   my ($self) = @_;
345
346   if (scalar @{ $self->{taxes} }) {
347     $self->js->show('#taxincluded_row_id');
348   } else {
349     $self->js->hide('#taxincluded_row_id');
350   }
351
352   if ($self->order->taxincluded) {
353     $self->js->hide('#subtotal_row_id');
354   } else {
355     $self->js->show('#subtotal_row_id');
356   }
357
358   $self->js
359     ->html('#netamount_id', $::form->format_amount(\%::myconfig, $self->order->netamount, -2))
360     ->html('#amount_id',    $::form->format_amount(\%::myconfig, $self->order->amount,    -2))
361     ->remove('.tax_row')
362     ->insertBefore($self->build_tax_rows, '#amount_row_id');
363 }
364
365 #
366 # helpers
367 #
368
369 sub init_valid_types {
370   [ _sales_order_type(), _purchase_order_type() ];
371 }
372
373 sub init_type {
374   my ($self) = @_;
375
376   if (none { $::form->{type} eq $_ } @{$self->valid_types}) {
377     die "Not a valid type for order";
378   }
379
380   $self->type($::form->{type});
381 }
382
383 sub init_cv {
384   my ($self) = @_;
385
386   my $cv = $self->type eq _sales_order_type()    ? 'customer'
387          : $self->type eq _purchase_order_type() ? 'vendor'
388          : die "Not a valid type for order";
389
390   return $cv;
391 }
392
393 sub init_p {
394   SL::Presenter->get;
395 }
396
397 sub init_order {
398   _make_order();
399 }
400
401 sub _check_auth {
402   my ($self) = @_;
403
404   my $right_for = { map { $_ => $_.'_edit' } @{$self->valid_types} };
405
406   my $right   = $right_for->{ $self->type };
407   $right    ||= 'DOES_NOT_EXIST';
408
409   $::auth->assert($right);
410 }
411
412 sub build_contact_select {
413   my ($self) = @_;
414
415   $self->p->select_tag('order.cp_id', [ $self->order->{$self->cv}->contacts ],
416                        value_key  => 'cp_id',
417                        title_key  => 'full_name_dep',
418                        default    => $self->order->cp_id,
419                        with_empty => 1,
420                        style      => 'width: 300px',
421   );
422 }
423
424 sub build_shipto_select {
425   my ($self) = @_;
426
427   $self->p->select_tag('order.shipto_id', [ $self->order->{$self->cv}->shipto ],
428                        value_key  => 'shipto_id',
429                        title_key  => 'displayable_id',
430                        default    => $self->order->shipto_id,
431                        with_empty => 1,
432                        style      => 'width: 300px',
433   );
434 }
435
436 sub build_tax_rows {
437   my ($self) = @_;
438
439   my $rows_as_html;
440   foreach my $tax (@{ $self->{taxes} }) {
441     $rows_as_html .= $self->p->render('order/tabs/_tax_row', TAX => $tax, TAXINCLUDED => $self->order->taxincluded);
442   }
443   return $rows_as_html;
444 }
445
446
447 sub _make_order {
448   my ($self) = @_;
449
450   # add_items adds items to an order with no items for saving, but they cannot
451   # be retrieved via items until the order is saved. Adding empty items to new
452   # order here solves this problem.
453   my $order;
454   $order   = SL::DB::Manager::Order->find_by(id => $::form->{id}) if $::form->{id};
455   $order ||= SL::DB::Order->new(orderitems => []);
456
457   $order->assign_attributes(%{$::form->{order}});
458
459   return $order;
460 }
461
462
463 sub _recalc {
464   my ($self) = @_;
465
466   # bb: todo: currency later
467   $self->order->currency_id($::instance_conf->get_currency_id());
468
469   my %pat = $self->order->calculate_prices_and_taxes();
470   $self->{taxes} = [];
471   foreach my $tax_chart_id (keys %{ $pat{taxes} }) {
472     my $tax = SL::DB::Manager::Tax->find_by(chart_id => $tax_chart_id);
473
474     my @amount_keys = grep { $pat{amounts}->{$_}->{tax_id} == $tax->id } keys %{ $pat{amounts} };
475     push(@{ $self->{taxes} }, { amount    => $pat{taxes}->{$tax_chart_id},
476                                 netamount => $pat{amounts}->{$amount_keys[0]}->{amount},
477                                 tax       => $tax });
478   }
479
480   pairwise { $a->{linetotal} = $b->{linetotal} } @{$self->order->items}, @{$pat{items}};
481 }
482
483
484 sub _get_unalterable_data {
485   my ($self) = @_;
486
487   foreach my $item (@{ $self->order->items }) {
488     if ($item->id) {
489       # load data from orderitems (db)
490       my $db_item = SL::DB::OrderItem->new(id => $item->id)->load;
491       $item->$_($db_item->$_) for qw(active_discount_source active_price_source longdescription);
492     } else {
493       # set data from part (or other sources)
494       $item->longdescription($item->part->notes);
495       #$item->active_price_source('');
496       #$item->active_discount_source('');
497     }
498
499     # autovivify all cvars that are not in the form (cvars_by_config can do it).
500     # workaround to pre-parse number-cvars (parse_custom_variable_values does not parse number values).
501     foreach my $var (@{ $item->cvars_by_config }) {
502       $var->unparsed_value($::form->parse_amount(\%::myconfig, $var->{__unparsed_value})) if ($var->config->type eq 'number' && exists($var->{__unparsed_value}));
503     }
504     $item->parse_custom_variable_values;
505   }
506 }
507
508
509 sub _save {
510   my ($self) = @_;
511
512   my $errors = [];
513   my $db = $self->order->db;
514
515   $db->do_transaction(
516     sub {
517       $self->order->save();
518   }) || push(@{$errors}, $db->error);
519
520   return $errors;
521 }
522
523
524 sub _pre_render {
525   my ($self) = @_;
526
527   $self->{all_taxzones}        = SL::DB::Manager::TaxZone->get_all_sorted();
528   $self->{all_employees}       = SL::DB::Manager::Employee->get_all(where => [ or => [ id => $self->order->employee_id,
529                                                                                        deleted => 0 ] ],
530                                                                     sort_by => 'name');
531   $self->{all_salesmen}        = SL::DB::Manager::Employee->get_all(where => [ or => [ id => $self->order->salesman_id,
532                                                                                        deleted => 0 ] ],
533                                                                     sort_by => 'name');
534   $self->{all_projects}        = SL::DB::Manager::Project->get_all(where => [ or => [ id => $self->order->globalproject_id,
535                                                                                       active => 1 ] ],
536                                                                    sort_by => 'projectnumber');
537   $self->{all_payment_terms}   = SL::DB::Manager::PaymentTerm->get_all_sorted();
538   $self->{all_delivery_terms}  = SL::DB::Manager::DeliveryTerm->get_all_sorted();
539
540   $self->{current_employee_id} = SL::DB::Manager::Employee->current->id;
541
542   $::request->{layout}->use_javascript("${_}.js")  for qw(ckeditor/ckeditor ckeditor/adapters/jquery);
543 }
544
545 sub _create_pdf {
546   my ($order, $pdf_ref, $params) = @_;
547
548   my $print_form = Form->new('');
549   $print_form->{type}     = 'sales_order';
550   $print_form->{formname} = 'sales_order',
551   $print_form->{format}   = $params->{format} || 'pdf',
552   $print_form->{media}    = $params->{media}  || 'file';
553
554   $order->flatten_to_form($print_form, format_amounts => 1);
555   # flatten_to_form sets payment_terms from customer/vendor - we do not want that here
556   delete $print_form->{payment_terms} if !$print_form->{payment_id};
557
558   my @errors = ();
559   $print_form->throw_on_error(sub {
560     eval {
561       $print_form->prepare_for_printing;
562
563       $$pdf_ref = SL::Helper::CreatePDF->create_pdf(
564         template  => SL::Helper::CreatePDF->find_template(name => $print_form->{formname}),
565         variables => $print_form,
566         variable_content_types => {
567           longdescription => 'html',
568           partnotes       => 'html',
569           notes           => 'html',
570         },
571       );
572       1;
573     } || push @errors, ref($EVAL_ERROR) eq 'SL::X::FormError' ? $EVAL_ERROR->getMessage : $EVAL_ERROR;
574   });
575
576   return @errors;
577 }
578
579 sub _sales_order_type {
580   'sales_order';
581 }
582
583 sub _purchase_order_type {
584   'purchase_order';
585 }
586
587 1;
588
589 __END__
590
591 =encoding utf-8
592
593 =head1 NAME
594
595 SL::Controller::Order - controller for orders
596
597 =head1 TODO
598
599 Testing, PriceSources, pricefactor, units, currency, delivered, delivery order created, ...
600
601 =head1 AUTHOR
602
603 Bernd Bleßmann E<lt>bernd@kivitendo-premium.deE<gt>
604
605 =cut
606