dolibarr 22.0.5
api_orders.class.php
1<?php
2/* Copyright (C) 2015 Jean-François Ferry <jfefe@aternatik.fr>
3 * Copyright (C) 2016 Laurent Destailleur <eldy@users.sourceforge.net>
4 * Copyright (C) 2024 Frédéric France <frederic.france@free.fr>
5 * Copyright (C) 2025 MDW <mdeweerd@users.noreply.github.com>
6 *
7 * This program is free software; you can redistribute it and/or modify
8 * it under the terms of the GNU General Public License as published by
9 * the Free Software Foundation; either version 3 of the License, or
10 * (at your option) any later version.
11 *
12 * This program is distributed in the hope that it will be useful,
13 * but WITHOUT ANY WARRANTY; without even the implied warranty of
14 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
15 * GNU General Public License for more details.
16 *
17 * You should have received a copy of the GNU General Public License
18 * along with this program. If not, see <https://www.gnu.org/licenses/>.
19 */
20
21use Luracast\Restler\RestException;
22
23require_once DOL_DOCUMENT_ROOT.'/commande/class/commande.class.php';
24
31class Orders extends DolibarrApi
32{
36 public static $FIELDS = array(
37 'socid',
38 'date'
39 );
40
44 public $commande;
45
49 public function __construct()
50 {
51 global $db;
52
53 $this->db = $db;
54 $this->commande = new Commande($this->db);
55 }
56
68 public function get($id, $contact_list = -1)
69 {
70 return $this->_fetch($id, '', '', $contact_list);
71 }
72
86 public function getByRef($ref, $contact_list = -1)
87 {
88 return $this->_fetch(0, $ref, '', $contact_list);
89 }
90
104 public function getByRefExt($ref_ext, $contact_list = -1)
105 {
106 return $this->_fetch(0, '', $ref_ext, $contact_list);
107 }
108
122 private function _fetch($id, $ref = '', $ref_ext = '', $contact_list = -1)
123 {
124 if (!DolibarrApiAccess::$user->hasRight('commande', 'lire')) {
125 throw new RestException(403);
126 }
127
128 $result = $this->commande->fetch($id, $ref, $ref_ext);
129 if (!$result) {
130 throw new RestException(404, 'Order not found');
131 }
132
133 if (!DolibarrApi::_checkAccessToResource('commande', $this->commande->id)) {
134 throw new RestException(403, 'Access not allowed for login '.DolibarrApiAccess::$user->login);
135 }
136
137 if ($contact_list > -1) {
138 // Add external contacts ids
139 $tmparray = $this->commande->liste_contact(-1, 'external', $contact_list);
140 if (is_array($tmparray)) {
141 $this->commande->contacts_ids = $tmparray;
142 }
143 $tmparray = $this->commande->liste_contact(-1, 'internal', $contact_list);
144 if (is_array($tmparray)) {
145 $this->commande->contacts_ids_internal = $tmparray;
146 }
147 }
148
149 $this->commande->fetchObjectLinked();
150
151 // Add online_payment_url, cf #20477
152 require_once DOL_DOCUMENT_ROOT.'/core/lib/payments.lib.php';
153 $this->commande->online_payment_url = getOnlinePaymentUrl(0, 'order', $this->commande->ref);
154
155 return $this->_cleanObjectDatas($this->commande);
156 }
157
180 public function index($sortfield = "t.rowid", $sortorder = 'ASC', $limit = 100, $page = 0, $thirdparty_ids = '', $sqlfilters = '', $sqlfilterlines = '', $properties = '', $pagination_data = false, $loadlinkedobjects = 0)
181 {
182 if (!DolibarrApiAccess::$user->hasRight('commande', 'lire')) {
183 throw new RestException(403);
184 }
185
186 $obj_ret = array();
187
188 // case of external user, $thirdparty_ids param is ignored and replaced by user's socid
189 $socids = DolibarrApiAccess::$user->socid ?: $thirdparty_ids;
190
191 // If the internal user must only see his customers, force searching by him
192 $search_sale = 0;
193 if (!DolibarrApiAccess::$user->hasRight('societe', 'client', 'voir') && !$socids) {
194 $search_sale = DolibarrApiAccess::$user->id;
195 }
196
197 $sql = "SELECT t.rowid";
198 $sql .= " FROM ".MAIN_DB_PREFIX."commande AS t";
199 $sql .= " LEFT JOIN ".MAIN_DB_PREFIX."commande_extrafields AS ef ON (ef.fk_object = t.rowid)"; // Modification VMR Global Solutions to include extrafields as search parameters in the API GET call, so we will be able to filter on extrafields
200 $sql .= ' WHERE t.entity IN ('.getEntity('commande').')';
201 if ($socids) {
202 $sql .= " AND t.fk_soc IN (".$this->db->sanitize($socids).")";
203 }
204 // Search on sale representative
205 if ($search_sale && $search_sale != '-1') {
206 if ($search_sale == -2) {
207 $sql .= " AND NOT EXISTS (SELECT sc.fk_soc FROM ".MAIN_DB_PREFIX."societe_commerciaux as sc WHERE sc.fk_soc = t.fk_soc)";
208 } elseif ($search_sale > 0) {
209 $sql .= " AND EXISTS (SELECT sc.fk_soc FROM ".MAIN_DB_PREFIX."societe_commerciaux as sc WHERE sc.fk_soc = t.fk_soc AND sc.fk_user = ".((int) $search_sale).")";
210 }
211 }
212 // Add sql filters
213 if ($sqlfilters) {
214 $errormessage = '';
215 $sql .= forgeSQLFromUniversalSearchCriteria($sqlfilters, $errormessage);
216 if ($errormessage) {
217 throw new RestException(400, 'Error when validating parameter sqlfilters -> '.$errormessage);
218 }
219 }
220 // Add sql filters for lines
221 if ($sqlfilterlines) {
222 $errormessage = '';
223 $sql .= " AND EXISTS (SELECT tl.rowid FROM ".MAIN_DB_PREFIX."commandedet AS tl WHERE tl.fk_commande = t.rowid";
224 $sql .= forgeSQLFromUniversalSearchCriteria($sqlfilterlines, $errormessage);
225 $sql .= ")";
226 if ($errormessage) {
227 throw new RestException(400, 'Error when validating parameter sqlfilterlines -> '.$errormessage);
228 }
229 }
230
231 //this query will return total orders with the filters given
232 $sqlTotals = str_replace('SELECT t.rowid', 'SELECT count(t.rowid) as total', $sql);
233
234 $sql .= $this->db->order($sortfield, $sortorder);
235 if ($limit) {
236 if ($page < 0) {
237 $page = 0;
238 }
239 $offset = $limit * $page;
240
241 $sql .= $this->db->plimit($limit + 1, $offset);
242 }
243
244 dol_syslog("API Rest request");
245 $result = $this->db->query($sql);
246
247 if ($result) {
248 $num = $this->db->num_rows($result);
249 $min = min($num, ($limit <= 0 ? $num : $limit));
250 $i = 0;
251 while ($i < $min) {
252 $obj = $this->db->fetch_object($result);
253 $commande_static = new Commande($this->db);
254 if ($commande_static->fetch($obj->rowid) > 0) {
255 // Add external contacts ids
256 $tmparray = $commande_static->liste_contact(-1, 'external', 1);
257 if (is_array($tmparray)) {
258 $commande_static->contacts_ids = $tmparray;
259 }
260
261 if ($loadlinkedobjects) {
262 // retrieve linked objects
263 $commande_static->fetchObjectLinked();
264 }
265
266 // Add online_payment_url, cf #20477
267 require_once DOL_DOCUMENT_ROOT.'/core/lib/payments.lib.php';
268 $commande_static->online_payment_url = getOnlinePaymentUrl(0, 'order', $commande_static->ref);
269
270 $obj_ret[] = $this->_filterObjectProperties($this->_cleanObjectDatas($commande_static), $properties);
271 }
272 $i++;
273 }
274 } else {
275 throw new RestException(503, 'Error when retrieve commande list : '.$this->db->lasterror());
276 }
277
278 //if $pagination_data is true the response will contain element data with all values and element pagination with pagination data(total,page,limit)
279 if ($pagination_data) {
280 $totalsResult = $this->db->query($sqlTotals);
281 $total = $this->db->fetch_object($totalsResult)->total;
282
283 $tmp = $obj_ret;
284 $obj_ret = [];
285
286 $obj_ret['data'] = $tmp;
287 $obj_ret['pagination'] = [
288 'total' => (int) $total,
289 'page' => $page, //count starts from 0
290 'page_count' => ceil((int) $total / $limit),
291 'limit' => $limit
292 ];
293 }
294
295 return $obj_ret;
296 }
297
308 public function post($request_data = null)
309 {
310 if (!DolibarrApiAccess::$user->hasRight('commande', 'creer')) {
311 throw new RestException(403, "Insuffisant rights");
312 }
313 // Check mandatory fields
314 $result = $this->_validate($request_data);
315
316 foreach ($request_data as $field => $value) {
317 if ($field === 'caller') {
318 // Add a mention of caller so on trigger called after action, we can filter to avoid a loop if we try to sync back again with the caller
319 $this->commande->context['caller'] = sanitizeVal($request_data['caller'], 'aZ09');
320 continue;
321 }
322
323 $this->commande->$field = $this->_checkValForAPI($field, $value, $this->commande);
324 }
325 /*if (isset($request_data["lines"])) {
326 $lines = array();
327 foreach ($request_data["lines"] as $line) {
328 array_push($lines, (object) $line);
329 }
330 $this->commande->lines = $lines;
331 }*/
332
333 if ($this->commande->create(DolibarrApiAccess::$user) < 0) {
334 throw new RestException(500, "Error creating order", array_merge(array($this->commande->error), $this->commande->errors));
335 }
336
337 return ((int) $this->commande->id);
338 }
339
351 public function getLines($id)
352 {
353 if (!DolibarrApiAccess::$user->hasRight('commande', 'lire')) {
354 throw new RestException(403);
355 }
356
357 $result = $this->commande->fetch($id);
358 if (!$result) {
359 throw new RestException(404, 'Order not found');
360 }
361
362 if (!DolibarrApi::_checkAccessToResource('commande', $this->commande->id)) {
363 throw new RestException(403, 'Access not allowed for login '.DolibarrApiAccess::$user->login);
364 }
365 $this->commande->getLinesArray();
366 $result = array();
367 foreach ($this->commande->lines as $line) {
368 array_push($result, $this->_cleanObjectDatas($line));
369 }
370 return $result;
371 }
372
384 public function getLine($id, $lineid, $properties = '')
385 {
386 if (!DolibarrApiAccess::$user->hasRight('commande', 'lire')) {
387 throw new RestException(403);
388 }
389
390 $result = $this->commande->fetch($id);
391 if (!$result) {
392 throw new RestException(404, 'Order not found');
393 }
394
395 if (!DolibarrApi::_checkAccessToResource('commande', $this->commande->id)) {
396 throw new RestException(403, 'Access not allowed for login '.DolibarrApiAccess::$user->login);
397 }
398
399 $this->commande->fetch_lines();
400 foreach ($this->commande->lines as $line) {
401 if ($line->id == $lineid) {
402 return $this->_filterObjectProperties($this->_cleanObjectDatas($line), $properties);
403 }
404 }
405 throw new RestException(404, 'Line not found');
406 }
407
420 public function postLine($id, $request_data = null)
421 {
422 if (!DolibarrApiAccess::$user->hasRight('commande', 'creer')) {
423 throw new RestException(403);
424 }
425
426 $result = $this->commande->fetch($id);
427 if (!$result) {
428 throw new RestException(404, 'Order not found');
429 }
430
431 if (!DolibarrApi::_checkAccessToResource('commande', $this->commande->id)) {
432 throw new RestException(403, 'Access not allowed for login '.DolibarrApiAccess::$user->login);
433 }
434
435 $request_data = (object) $request_data;
436
437 $request_data->desc = sanitizeVal($request_data->desc, 'restricthtml');
438 $request_data->label = sanitizeVal($request_data->label);
439
440 $updateRes = $this->commande->addline(
441 $request_data->desc,
442 $request_data->subprice,
443 $request_data->qty,
444 $request_data->tva_tx,
445 $request_data->localtax1_tx,
446 $request_data->localtax2_tx,
447 $request_data->fk_product,
448 $request_data->remise_percent,
449 $request_data->info_bits,
450 $request_data->fk_remise_except,
451 $request_data->price_base_type ? $request_data->price_base_type : 'HT',
452 $request_data->subprice,
453 $request_data->date_start,
454 $request_data->date_end,
455 $request_data->product_type,
456 $request_data->rang,
457 $request_data->special_code,
458 $request_data->fk_parent_line,
459 $request_data->fk_fournprice,
460 $request_data->pa_ht,
461 $request_data->label,
462 $request_data->array_options,
463 $request_data->fk_unit,
464 $request_data->origin,
465 $request_data->origin_id,
466 $request_data->multicurrency_subprice,
467 $request_data->ref_ext
468 );
469
470 if ($updateRes > 0) {
471 return $updateRes;
472 } else {
473 throw new RestException(400, $this->commande->error);
474 }
475 }
476
489 public function putLine($id, $lineid, $request_data = null)
490 {
491 if (!DolibarrApiAccess::$user->hasRight('commande', 'creer')) {
492 throw new RestException(403);
493 }
494
495 $result = $this->commande->fetch($id);
496 if (!$result) {
497 throw new RestException(404, 'Order not found');
498 }
499
500 if (!DolibarrApi::_checkAccessToResource('commande', $this->commande->id)) {
501 throw new RestException(403, 'Access not allowed for login '.DolibarrApiAccess::$user->login);
502 }
503
504 $request_data = (object) $request_data;
505
506 $request_data->desc = sanitizeVal($request_data->desc, 'restricthtml');
507 $request_data->label = sanitizeVal($request_data->label);
508
509 $orderline = new OrderLine($this->db);
510 $result = $orderline->fetch($lineid);
511 if (!$result) {
512 throw new RestException(404, 'Order line not found');
513 }
514
515 if ($orderline->fk_commande != $id) {
516 throw new RestException(403, 'Line does not belong to this order');
517 }
518
519 $updateRes = $this->commande->updateline(
520 $lineid,
521 $request_data->desc,
522 $request_data->subprice,
523 $request_data->qty,
524 $request_data->remise_percent,
525 $request_data->tva_tx,
526 $request_data->localtax1_tx,
527 $request_data->localtax2_tx,
528 $request_data->price_base_type ? $request_data->price_base_type : 'HT',
529 $request_data->info_bits,
530 $request_data->date_start,
531 $request_data->date_end,
532 $request_data->product_type,
533 $request_data->fk_parent_line,
534 0,
535 $request_data->fk_fournprice,
536 $request_data->pa_ht,
537 $request_data->label,
538 $request_data->special_code,
539 $request_data->array_options,
540 $request_data->fk_unit,
541 $request_data->multicurrency_subprice,
542 0,
543 $request_data->ref_ext,
544 $request_data->rang
545 );
546
547 if ($updateRes > 0) {
548 $result = $this->get($id);
549 unset($result->line);
550 return $this->_cleanObjectDatas($result);
551 }
552 return false;
553 }
554
567 public function deleteLine($id, $lineid)
568 {
569 if (!DolibarrApiAccess::$user->hasRight('commande', 'creer')) {
570 throw new RestException(403);
571 }
572
573 $result = $this->commande->fetch($id);
574 if (!$result) {
575 throw new RestException(404, 'Order not found');
576 }
577
578 if (!DolibarrApi::_checkAccessToResource('commande', $this->commande->id)) {
579 throw new RestException(403, 'Access not allowed for login '.DolibarrApiAccess::$user->login);
580 }
581
582 $updateRes = $this->commande->deleteLine(DolibarrApiAccess::$user, $lineid, $id);
583 if ($updateRes > 0) {
584 return $this->get($id);
585 } else {
586 throw new RestException(405, $this->commande->error);
587 }
588 }
589
603 public function getContacts($id, $type = '')
604 {
605 if (!DolibarrApiAccess::$user->hasRight('commande', 'lire')) {
606 throw new RestException(403);
607 }
608
609 $result = $this->commande->fetch($id);
610 if (!$result) {
611 throw new RestException(404, 'Order not found');
612 }
613
614 if (!DolibarrApi::_checkAccessToResource('commande', $this->commande->id)) {
615 throw new RestException(403, 'Access not allowed for login '.DolibarrApiAccess::$user->login);
616 }
617
618 $contacts = $this->commande->liste_contact(-1, 'external', 0, $type);
619
620 return $this->_cleanObjectDatas($contacts);
621 }
622
638 public function postContact($id, $contactid, $type)
639 {
640 if (!DolibarrApiAccess::$user->hasRight('commande', 'creer')) {
641 throw new RestException(403);
642 }
643
644 $result = $this->commande->fetch($id);
645 if (!$result) {
646 throw new RestException(404, 'Order not found');
647 }
648
649 if (!DolibarrApi::_checkAccessToResource('commande', $this->commande->id)) {
650 throw new RestException(403, 'Access not allowed for login '.DolibarrApiAccess::$user->login);
651 }
652
653 $result = $this->commande->add_contact($contactid, $type, 'external');
654
655 if ($result < 0) {
656 throw new RestException(500, 'Error when added the contact');
657 }
658
659 if ($result == 0) {
660 throw new RestException(304, 'contact already added');
661 }
662
663 return array(
664 'success' => array(
665 'code' => 200,
666 'message' => 'Contact linked to the order'
667 )
668 );
669 }
670
688 public function deleteContact($id, $contactid, $type)
689 {
690 if (!DolibarrApiAccess::$user->hasRight('commande', 'creer')) {
691 throw new RestException(403);
692 }
693
694 $result = $this->commande->fetch($id);
695 if (!$result) {
696 throw new RestException(404, 'Order not found');
697 }
698
699 if (!DolibarrApi::_checkAccessToResource('commande', $this->commande->id)) {
700 throw new RestException(403, 'Access not allowed for login '.DolibarrApiAccess::$user->login);
701 }
702
703 $contacts = $this->commande->liste_contact();
704
705 foreach ($contacts as $contact) {
706 if ($contact['id'] == $contactid && $contact['code'] == $type) {
707 $result = $this->commande->delete_contact($contact['rowid']);
708
709 if (!$result) {
710 throw new RestException(500, 'Error when deleted the contact');
711 }
712 }
713 }
714
715 return array(
716 'success' => array(
717 'code' => 200,
718 'message' => 'Contact unlinked from order'
719 )
720 );
721 }
722
732 public function put($id, $request_data = null)
733 {
734 if (!DolibarrApiAccess::$user->hasRight('commande', 'creer')) {
735 throw new RestException(403);
736 }
737
738 $result = $this->commande->fetch($id);
739 if (!$result) {
740 throw new RestException(404, 'Order not found');
741 }
742
743 if (!DolibarrApi::_checkAccessToResource('commande', $this->commande->id)) {
744 throw new RestException(403, 'Access not allowed for login '.DolibarrApiAccess::$user->login);
745 }
746 foreach ($request_data as $field => $value) {
747 if ($field == 'id') {
748 continue;
749 }
750 if ($field === 'caller') {
751 // Add a mention of caller so on trigger called after action, we can filter to avoid a loop if we try to sync back again with the caller
752 $this->commande->context['caller'] = sanitizeVal($request_data['caller'], 'aZ09');
753 continue;
754 }
755 if ($field == 'array_options' && is_array($value)) {
756 foreach ($value as $index => $val) {
757 $this->commande->array_options[$index] = $this->_checkValForAPI($field, $val, $this->commande);
758 }
759 continue;
760 }
761
762 $this->commande->$field = $this->_checkValForAPI($field, $value, $this->commande);
763 }
764
765 // Update availability
766 if (!empty($this->commande->availability_id)) {
767 if ($this->commande->availability($this->commande->availability_id) < 0) {
768 throw new RestException(400, 'Error while updating availability');
769 }
770 }
771
772 if ($this->commande->update(DolibarrApiAccess::$user) > 0) {
773 return $this->get($id);
774 } else {
775 throw new RestException(500, $this->commande->error);
776 }
777 }
778
787 public function delete($id)
788 {
789 if (!DolibarrApiAccess::$user->hasRight('commande', 'supprimer')) {
790 throw new RestException(403);
791 }
792 $result = $this->commande->fetch($id);
793 if (!$result) {
794 throw new RestException(404, 'Order not found');
795 }
796
797 if (!DolibarrApi::_checkAccessToResource('commande', $this->commande->id)) {
798 throw new RestException(403, 'Access not allowed for login '.DolibarrApiAccess::$user->login);
799 }
800
801 if (!$this->commande->delete(DolibarrApiAccess::$user)) {
802 throw new RestException(500, 'Error when deleting order : '.$this->commande->error);
803 }
804
805 return array(
806 'success' => array(
807 'code' => 200,
808 'message' => 'Order deleted'
809 )
810 );
811 }
812
834 public function validate($id, $idwarehouse = 0, $notrigger = 0)
835 {
836 if (!DolibarrApiAccess::$user->hasRight('commande', 'creer')) {
837 throw new RestException(403);
838 }
839 $result = $this->commande->fetch($id);
840 if (!$result) {
841 throw new RestException(404, 'Order not found');
842 }
843
844 $result = $this->commande->fetch_thirdparty(); // do not check result, as failure is not fatal (used only for mail notification substitutes)
845
846 if (!DolibarrApi::_checkAccessToResource('commande', $this->commande->id)) {
847 throw new RestException(403, 'Access not allowed for login '.DolibarrApiAccess::$user->login);
848 }
849
850 $result = $this->commande->valid(DolibarrApiAccess::$user, $idwarehouse, $notrigger);
851 if ($result == 0) {
852 throw new RestException(304, 'Error nothing done. May be object is already validated');
853 }
854 if ($result < 0) {
855 throw new RestException(500, 'Error when validating Order: '.$this->commande->error);
856 }
857 $result = $this->commande->fetch($id);
858
859 $this->commande->fetchObjectLinked();
860
861 //fix #20477 : add online_payment_url
862 require_once DOL_DOCUMENT_ROOT.'/core/lib/payments.lib.php';
863 $this->commande->online_payment_url = getOnlinePaymentUrl(0, 'order', $this->commande->ref);
864
865 return $this->_cleanObjectDatas($this->commande);
866 }
867
885 public function reopen($id)
886 {
887 if (!DolibarrApiAccess::$user->hasRight('commande', 'creer')) {
888 throw new RestException(403);
889 }
890 if (empty($id)) {
891 throw new RestException(400, 'Order ID is mandatory');
892 }
893 $result = $this->commande->fetch($id);
894 if (!$result) {
895 throw new RestException(404, 'Order not found');
896 }
897
898 $result = $this->commande->set_reopen(DolibarrApiAccess::$user);
899 if ($result < 0) {
900 throw new RestException(405, $this->commande->error);
901 } elseif ($result == 0) {
902 throw new RestException(304);
903 }
904
905 return $result;
906 }
907
921 public function setinvoiced($id)
922 {
923 if (!DolibarrApiAccess::$user->hasRight('commande', 'creer')) {
924 throw new RestException(403);
925 }
926 if (empty($id)) {
927 throw new RestException(400, 'Order ID is mandatory');
928 }
929 $result = $this->commande->fetch($id);
930 if (!$result) {
931 throw new RestException(404, 'Order not found');
932 }
933
934 $result = $this->commande->classifyBilled(DolibarrApiAccess::$user);
935 if ($result < 0) {
936 throw new RestException(400, $this->commande->error);
937 }
938
939 $result = $this->commande->fetch($id);
940 if (!$result) {
941 throw new RestException(404, 'Order not found');
942 }
943
944 if (!DolibarrApi::_checkAccessToResource('commande', $this->commande->id)) {
945 throw new RestException(403, 'Access not allowed for login '.DolibarrApiAccess::$user->login);
946 }
947
948 $this->commande->fetchObjectLinked();
949
950 return $this->_cleanObjectDatas($this->commande);
951 }
952
962 public function close($id, $notrigger = 0)
963 {
964 if (!DolibarrApiAccess::$user->hasRight('commande', 'creer')) {
965 throw new RestException(403);
966 }
967 $result = $this->commande->fetch($id);
968 if (!$result) {
969 throw new RestException(404, 'Order not found');
970 }
971
972 if (!DolibarrApi::_checkAccessToResource('commande', $this->commande->id)) {
973 throw new RestException(403, 'Access not allowed for login '.DolibarrApiAccess::$user->login);
974 }
975
976 $result = $this->commande->cloture(DolibarrApiAccess::$user, $notrigger);
977 if ($result == 0) {
978 throw new RestException(304, 'Error nothing done. May be object is already closed');
979 }
980 if ($result < 0) {
981 throw new RestException(500, 'Error when closing Order: '.$this->commande->error);
982 }
983
984 $result = $this->commande->fetch($id);
985 if (!$result) {
986 throw new RestException(404, 'Order not found');
987 }
988
989 if (!DolibarrApi::_checkAccessToResource('commande', $this->commande->id)) {
990 throw new RestException(403, 'Access not allowed for login '.DolibarrApiAccess::$user->login);
991 }
992
993 $this->commande->fetchObjectLinked();
994
995 return $this->_cleanObjectDatas($this->commande);
996 }
997
1007 public function settodraft($id, $idwarehouse = -1)
1008 {
1009 if (!DolibarrApiAccess::$user->hasRight('commande', 'creer')) {
1010 throw new RestException(403);
1011 }
1012 $result = $this->commande->fetch($id);
1013 if (!$result) {
1014 throw new RestException(404, 'Order not found');
1015 }
1016
1017 if (!DolibarrApi::_checkAccessToResource('commande', $this->commande->id)) {
1018 throw new RestException(403, 'Access not allowed for login '.DolibarrApiAccess::$user->login);
1019 }
1020
1021 $result = $this->commande->setDraft(DolibarrApiAccess::$user, $idwarehouse);
1022 if ($result == 0) {
1023 throw new RestException(304, 'Nothing done. May be object is already closed');
1024 }
1025 if ($result < 0) {
1026 throw new RestException(500, 'Error when closing Order: '.$this->commande->error);
1027 }
1028
1029 $result = $this->commande->fetch($id);
1030 if (!$result) {
1031 throw new RestException(404, 'Order not found');
1032 }
1033
1034 if (!DolibarrApi::_checkAccessToResource('commande', $this->commande->id)) {
1035 throw new RestException(403, 'Access not allowed for login '.DolibarrApiAccess::$user->login);
1036 }
1037
1038 $this->commande->fetchObjectLinked();
1039
1040 return $this->_cleanObjectDatas($this->commande);
1041 }
1042
1043
1057 public function createOrderFromProposal($proposalid)
1058 {
1059 require_once DOL_DOCUMENT_ROOT.'/comm/propal/class/propal.class.php';
1060
1061 if (!DolibarrApiAccess::$user->hasRight('propal', 'lire')) {
1062 throw new RestException(403);
1063 }
1064 if (!DolibarrApiAccess::$user->hasRight('commande', 'creer')) {
1065 throw new RestException(403);
1066 }
1067 if (empty($proposalid)) {
1068 throw new RestException(400, 'Proposal ID is mandatory');
1069 }
1070
1071 $propal = new Propal($this->db);
1072 $result = $propal->fetch($proposalid);
1073 if (!$result) {
1074 throw new RestException(404, 'Proposal not found');
1075 }
1076
1077 $result = $this->commande->createFromProposal($propal, DolibarrApiAccess::$user);
1078 if ($result < 0) {
1079 throw new RestException(405, $this->commande->error);
1080 }
1081 $this->commande->fetchObjectLinked();
1082
1083 return $this->_cleanObjectDatas($this->commande);
1084 }
1085
1101 public function getOrderShipments($id)
1102 {
1103 require_once DOL_DOCUMENT_ROOT.'/expedition/class/expedition.class.php';
1104 if (!DolibarrApiAccess::$user->hasRight('expedition', 'lire')) {
1105 throw new RestException(403);
1106 }
1107 if (!DolibarrApi::_checkAccessToResource('commande', $id)) {
1108 throw new RestException(403, 'Access not allowed for login '.DolibarrApiAccess::$user->login);
1109 }
1110 $obj_ret = array();
1111 $sql = "SELECT e.rowid";
1112 $sql .= " FROM ".MAIN_DB_PREFIX."expedition as e";
1113 $sql .= " JOIN ".MAIN_DB_PREFIX."expeditiondet as edet";
1114 $sql .= " ON e.rowid = edet.fk_expedition";
1115 $sql .= " JOIN ".MAIN_DB_PREFIX."commandedet as cdet";
1116 $sql .= " ON edet.fk_elementdet = cdet.rowid";
1117 $sql .= " JOIN ".MAIN_DB_PREFIX."commande as c";
1118 $sql .= " ON cdet.fk_commande = c.rowid";
1119 $sql .= " WHERE c.rowid = ".((int) $id);
1120 $sql .= " GROUP BY e.rowid";
1121 $sql .= $this->db->order("e.rowid", "ASC");
1122
1123 dol_syslog("API Rest request");
1124 $result = $this->db->query($sql);
1125
1126 if ($result) {
1127 $num = $this->db->num_rows($result);
1128 if ($num <= 0) {
1129 throw new RestException(404, 'Shipments not found ');
1130 }
1131 $i = 0;
1132 while ($i < $num) {
1133 $obj = $this->db->fetch_object($result);
1134 $shipment_static = new Expedition($this->db);
1135 if ($shipment_static->fetch($obj->rowid)) {
1136 $obj_ret[] = $this->_cleanObjectDatas($shipment_static);
1137 }
1138 $i++;
1139 }
1140 } else {
1141 throw new RestException(500, 'Error when retrieve shipment list : '.$this->db->lasterror());
1142 }
1143 return $obj_ret;
1144 }
1145
1160 public function createOrderShipment($id, $warehouse_id)
1161 {
1162 require_once DOL_DOCUMENT_ROOT.'/expedition/class/expedition.class.php';
1163 if (!DolibarrApiAccess::$user->hasRight('expedition', 'creer')) {
1164 throw new RestException(403);
1165 }
1166 if ($warehouse_id <= 0) {
1167 throw new RestException(404, 'Warehouse not found');
1168 }
1169 $result = $this->commande->fetch($id);
1170 if (!$result) {
1171 throw new RestException(404, 'Order not found');
1172 }
1173 if (!DolibarrApi::_checkAccessToResource('commande', $this->commande->id)) {
1174 throw new RestException(403, 'Access not allowed for login '.DolibarrApiAccess::$user->login);
1175 }
1176 $shipment = new Expedition($this->db);
1177 $shipment->socid = $this->commande->socid;
1178 $shipment->origin_id = $this->commande->id;
1179 $shipment->origin = $this->commande->element;
1180 $result = $shipment->create(DolibarrApiAccess::$user);
1181 if ($result <= 0) {
1182 throw new RestException(500, 'Error on creating expedition :'.$this->db->lasterror());
1183 }
1184 foreach ($this->commande->lines as $line) {
1185 $result = $shipment->create_line($warehouse_id, $line->id, $line->qty);
1186 if ($result <= 0) {
1187 throw new RestException(500, 'Error on creating expedition lines:'.$this->db->lasterror());
1188 }
1189 }
1190 return $shipment->id;
1191 }
1192
1193 // phpcs:disable PEAR.NamingConventions.ValidFunctionName.PublicUnderscore
1200 protected function _cleanObjectDatas($object)
1201 {
1202 // phpcs:enable
1203 $object = parent::_cleanObjectDatas($object);
1204
1205 unset($object->note);
1206 unset($object->address);
1207 unset($object->barcode_type);
1208 unset($object->barcode_type_code);
1209 unset($object->barcode_type_label);
1210 unset($object->barcode_type_coder);
1211
1212 return $object;
1213 }
1214
1222 private function _validate($data)
1223 {
1224 if ($data === null) {
1225 $data = array();
1226 }
1227 $commande = array();
1228 foreach (Orders::$FIELDS as $field) {
1229 if (!isset($data[$field])) {
1230 throw new RestException(400, $field." field missing");
1231 }
1232 $commande[$field] = $data[$field];
1233 }
1234 return $commande;
1235 }
1236}
$id
Support class for third parties, contacts, members, users or resources.
Definition account.php:48
if( $user->socid > 0) if(! $user->hasRight('accounting', 'chartofaccount')) $object
Definition card.php:67
Class to manage customers orders.
Class for API REST v1.
Definition api.class.php:33
_filterObjectProperties($object, $properties)
Filter properties that will be returned on object.
static _checkAccessToResource($resource, $resource_id=0, $dbtablename='', $feature2='', $dbt_keyfield='fk_soc', $dbt_select='rowid')
Check access by user to a given resource.
_checkValForAPI($field, $value, $object)
Check and convert a string depending on its type/name.
Definition api.class.php:98
Class to manage order lines.
deleteContact($id, $contactid, $type)
Unlink a contact type of given order.
__construct()
Constructor.
_validate($data)
Validate fields before create or update object.
deleteLine($id, $lineid)
Delete a line of a given order.
getByRef($ref, $contact_list=-1)
Get properties of an order object by ref.
close($id, $notrigger=0)
Close an order (Classify it as "Delivered")
index($sortfield="t.rowid", $sortorder='ASC', $limit=100, $page=0, $thirdparty_ids='', $sqlfilters='', $sqlfilterlines='', $properties='', $pagination_data=false, $loadlinkedobjects=0)
List orders.
_cleanObjectDatas($object)
Clean sensible object datas.
_fetch($id, $ref='', $ref_ext='', $contact_list=-1)
Get properties of an order object.
put($id, $request_data=null)
Update order general fields (won't touch lines of order)
getLines($id)
Get lines of an order.
postContact($id, $contactid, $type)
Add a contact type of given order.
reopen($id)
Tag the order as validated (opened)
setinvoiced($id)
Classify the order as invoiced.
getContacts($id, $type='')
Get contacts of given order.
getLine($id, $lineid, $properties='')
Get properties of a line of an order object by id.
postLine($id, $request_data=null)
Add a line to given order.
post($request_data=null)
Create a sale order.
validate($id, $idwarehouse=0, $notrigger=0)
Validate an order.
createOrderFromProposal($proposalid)
Create an order using an existing proposal.
putLine($id, $lineid, $request_data=null)
Update a line to given order.
getOrderShipments($id)
Get the shipments of an order.
settodraft($id, $idwarehouse=-1)
Set an order to draft.
createOrderShipment($id, $warehouse_id)
Create the shipment of an order.
getByRefExt($ref_ext, $contact_list=-1)
Get properties of an order object by ref_ext.
Class to manage proposals.
forgeSQLFromUniversalSearchCriteria($filter, &$errorstr='', $noand=0, $nopar=0, $noerror=0)
forgeSQLFromUniversalSearchCriteria
sanitizeVal($out='', $check='alphanohtml', $filter=null, $options=null)
Return a sanitized or empty value after checking value against a rule.
dol_syslog($message, $level=LOG_INFO, $ident=0, $suffixinfilename='', $restricttologhandler='', $logcontext=null)
Write log message into outputs.