Files
opensourcepos/app/Controllers/Jobs.php
T
objecttothis 171dd056b3 fix(jobs): validate all throttles before saving any
Bug: saveThrottles validated and saved throttles in same loop.
Invalid entry mid-loop stopped processing but left already-saved
throttles committed, and omitted throttles could still get deleted
via notToDelete tracking — partial/inconsistent state on failure.

- app/Controllers/Jobs.php: split into two passes — validate all
  throttleData entries first; on any invalid entry, roll back
  transaction and return failure immediately before touching DB.
  Only save/delete once full payload validated. Drop now-redundant
  $success flag folded into invalid-entry early return.
- tests/Controllers/JobsControllerTest.php: add test asserting
  existing throttles stay unchanged in DB when payload contains
  invalid throttle data.

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-09-17 16:22:55 +04:00

163 lines
5.2 KiB
PHP

<?php
namespace App\Controllers;
use App\Models\Appconfig;
use App\Models\JobThrottle;
use CodeIgniter\Database\BaseConnection;
use CodeIgniter\HTTP\ResponseInterface;
use Config\Database;
use ReflectionException;
class Jobs extends Secure_Controller
{
private BaseConnection $db;
private Appconfig $appconfig;
private JobThrottle $jobThrottle;
private array $config;
public function __construct()
{
parent::__construct('jobs');
$this->db = Database::connect();
$this->appconfig = model(Appconfig::class);
$this->jobThrottle = model(JobThrottle::class);
$this->config = $this->global_view_data['config'];
}
/**
* @return string
* @noinspection PhpUnused
*/
public function getIndex(): string
{
$data['config'] = $this->config;
$data['throttles'] = $this->jobThrottle->getAll()->getResultArray();
return view('jobs/manage', $data);
}
/**
* Saves settings configuration. Used in app/Views/jobs/settings_config.php
*
* @throws ReflectionException
* @return ResponseInterface
* @noinspection PhpUnused
*/
public function postSaveSettings(): ResponseInterface
{
$rules = [
'mode' => 'required|in_list[auto,web,manual]',
'web_max_seconds' => 'required|is_natural'
];
$messages = [
'mode' => ['in_list' => lang('Jobs.mode_invalid')],
'web_max_seconds' => ['is_natural' => lang('Jobs.web_max_seconds_invalid')]
];
if ($response = $this->validateFields($rules, $messages)) {
return $response;
}
$batchSaveData = [
'jobs_mode' => $this->request->getPost('mode'),
'jobs_web_max_seconds' => $this->request->getPost('web_max_seconds', FILTER_SANITIZE_NUMBER_INT)
];
$success = $this->appconfig->batch_save($batchSaveData);
return $this->response->setJSON(['success' => $success, 'message' => lang('Jobs.saved_' . ($success ? '' : 'un') . 'successfully')]);
}
/**
* Saves throttle configuration. Used in app/Views/jobs/settings_config.php
*
* @throws ReflectionException
* @return ResponseInterface
* @noinspection PhpUnused
*/
public function postSaveThrottles(): ResponseInterface
{
$allowedPeriods = ['minute', 'hour', 'day', 'month'];
$this->db->transStart();
$notToDelete = [];
$arraySave = [];
foreach ($this->request->getPost() as $key => $value) {
if (str_starts_with($key, 'throttle_count_') && preg_match('/^throttle_count_(\d+)$/', $key, $matches)) {
$throttleId = $matches[1];
$notToDelete[] = $throttleId;
$arraySave[$throttleId]['max_count'] = $value;
} elseif (str_starts_with($key, 'throttle_period_') && preg_match('/^throttle_period_(\d+)$/', $key, $matches)) {
$throttleId = $matches[1];
$arraySave[$throttleId]['period'] = $value;
}
}
foreach ($arraySave as $throttleData) {
if (!ctype_digit((string)$throttleData['max_count']) || !in_array($throttleData['period'], $allowedPeriods, true)) {
$this->db->transRollback();
return $this->response->setJSON(['success' => false, 'message' => lang('Jobs.saved_unsuccessfully')]);
}
}
foreach ($arraySave as $throttleId => $throttleData) {
$savedThrottleId = $this->jobThrottle->saveValue($throttleData, $throttleId);
$notToDelete[] = (string)$savedThrottleId;
}
// All throttles not available in post will be deleted now
$deletedThrottles = $this->jobThrottle->getAll()->getResultArray();
foreach ($deletedThrottles as $throttle) {
if (!in_array($throttle['throttle_id'], $notToDelete)) {
$this->jobThrottle->delete($throttle['throttle_id']);
}
}
$this->db->transComplete();
$success = $this->db->transStatus();
return $this->response->setJSON(['success' => $success, 'message' => lang('Jobs.saved_' . ($success ? '' : 'un') . 'successfully')]);
}
/**
* @return string
* @noinspection PhpUnused
*/
public function getThrottles(): string
{
$throttles = $this->jobThrottle->getAll()->getResultArray();
return view('partial/job_throttles', ['throttles' => $throttles]);
}
/**
* Stub for Phase 1 scaffolding. Real processing is wired up in a later phase.
*
* @return ResponseInterface
* @noinspection PhpUnused
*/
public function postProcessAllJobs(): ResponseInterface
{
return $this->response->setJSON(['success' => false, 'stub' => true, 'message' => lang('Jobs.not_yet_implemented')]);
}
/**
* Stub for Phase 1 scaffolding. Real processing is wired up in a later phase.
*
* @return ResponseInterface
* @noinspection PhpUnused
*/
public function postProcessSelectedJobs(): ResponseInterface
{
return $this->response->setJSON(['success' => false, 'stub' => true, 'message' => lang('Jobs.not_yet_implemented')]);
}
}