70ca2fa74a
Client sees only Total. Salary is calculated from salary_base = client_price
× (1 − margin/100). Margin never appears in customer-facing surfaces (PDF,
tracking JSON, portal).
Terminology: "marjă internă" — internal profit margin. NOT VAT/TVA. Never
called NDS/TVA anywhere in the code to avoid confusion with real Moldova
tax reporting (Doc 19/1C integration).
== Configuration ==
Fallback chain (in MarginResolver::resolve):
1. WorkOrder.override_margin_pct — per-Fișă for special contracts/VIP
2. User.internal_margin_pct — per-mechanic (main setting)
3. Company.settings.default_internal_margin_pct — tenant default
4. 0.0 — no margin
Example (mechanic Andrei with 20% margin):
User enters price_per_hour = 250 for 1h diagnosis
→ total = 250 (what client sees, goes into PDF)
→ salary_base = 250 × 0.80 = 200 (what mechanic gets salaried on)
→ applied_margin_pct = 20 (frozen)
If admin later changes Andrei's margin to 40%, the row's salary_base does
NOT change — history is immutable. Only new rows use the new margin.
Solves the retroactive-recompute problem for closed payroll periods.
== salary_base freeze semantics ==
wo_works gains 2 columns:
salary_base decimal(10,2) nullable
applied_margin_pct decimal(5,2) nullable
Frozen at save time by WorkOrderWork::saving hook. Recomputes only if
total OR master_id changes (i.e., someone actively edits the price or
reassigns the mechanic — in those cases we WANT the salary_base to
follow). Legacy rows (before this feature) have null salary_base;
PayrollCalculator falls back to total for them.
== PayrollCalculator uses salary_base ==
Previously: sum(wo_works.total) × works_pct → gave the mechanic a cut
of the price INCLUDING margin.
Now: sum(salary_base ?? total) × works_pct → the cut is from the
labor rate excluding margin.
Impact: for a 250 lei diagnosis at 20% margin with 50% payroll cut, the
mechanic gets 200 × 50% = 100 lei (was 250 × 50% = 125 lei). The shop
keeps the 50 lei margin regardless of the payroll %.
== RBAC gate ==
New permission FINANCE_VIEW_INTERNAL_MARGIN. Assigned to owner + admin +
manager + accountant in seed matrix. Not granted to mechanic,
receptionist, or viewer — those roles never see the "Bază salariu"
disclosure line or the margin % fields.
== UI surfaces ==
UserResource — new "Salariu & marjă" section (visible only with
FINANCE_VIEW_INTERNAL_MARGIN):
- Tarif orar (MDL)
- Marjă internă (%) with helper text explaining the -X% semantics
- Placeholder tells manager the exact formula
WorkOrderResource form — new override_margin_pct field in the "Plată &
total" section, gated by same permission. Helper text: "Doar pentru
cazuri speciale. Lasă gol pentru a folosi marja mecanicului."
WorksRelationManager (WO edit page) — Total column now shows a gray
subtitle line "Bază salariu: 200.00 MDL · marjă 20%" ONLY for users
with FINANCE_VIEW_INTERNAL_MARGIN. Everyone else sees just Total.
== Contract tests: NO leak ==
InternalMarginTest verifies with black-box grepping that:
- WorkOrderPdfService::generate output contains NONE of
{salary_base, internal_margin, applied_margin_pct, marja intern,
Bază salariu}
- /api/track/{token} JSON payload contains NONE of the same terms
- wo_parts table has no salary_base column (margin ONLY on labor)
- Changing mechanic.internal_margin_pct after work is saved does NOT
rewrite the historical salary_base (frozen)
- WO override wins over mechanic margin (contract-priced clients)
- Fallback chain: WO → mechanic → company default → 0
== Suite ==
298 passed (828 assertions). Was 285. +13 InternalMarginTest.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
247 lines
8.2 KiB
PHP
247 lines
8.2 KiB
PHP
<?php
|
|
|
|
namespace App\Models\Tenant;
|
|
|
|
use App\Models\Concerns\BelongsToTenant;
|
|
use Filament\Auth\MultiFactor\App\Contracts\HasAppAuthentication;
|
|
use Filament\Auth\MultiFactor\App\Contracts\HasAppAuthenticationRecovery;
|
|
use Filament\Auth\MultiFactor\Email\Contracts\HasEmailAuthentication;
|
|
use Filament\Models\Contracts\FilamentUser;
|
|
use Filament\Panel;
|
|
use Illuminate\Database\Eloquent\Factories\HasFactory;
|
|
use Illuminate\Database\Eloquent\SoftDeletes;
|
|
use Illuminate\Foundation\Auth\User as Authenticatable;
|
|
use Illuminate\Database\Eloquent\Relations\HasMany;
|
|
use Illuminate\Notifications\Notifiable;
|
|
use Laravel\Sanctum\HasApiTokens;
|
|
use Spatie\Permission\Traits\HasRoles;
|
|
|
|
/**
|
|
* Tenant-bound user. Belongs to exactly one Company.
|
|
* UNIQUE(company_id, email) — same email can exist in different tenants
|
|
* as completely separate accounts.
|
|
*/
|
|
class User extends Authenticatable implements FilamentUser, HasAppAuthentication, HasAppAuthenticationRecovery, HasEmailAuthentication
|
|
{
|
|
use BelongsToTenant, HasApiTokens, HasFactory, HasRoles, Notifiable, SoftDeletes;
|
|
|
|
/** Spatie Permission scope key matches the team_foreign_key (company_id). */
|
|
protected $guard_name = 'web';
|
|
|
|
protected $fillable = [
|
|
'company_id', 'name', 'email', 'phone', 'avatar_url',
|
|
'role', 'status', 'locale',
|
|
'specialization', 'color', 'hourly_rate', 'internal_margin_pct',
|
|
'email_verified_at', 'password', 'last_login_at',
|
|
'email_authentication_at',
|
|
'app_authentication_secret', 'app_authentication_recovery_codes',
|
|
'invited_at', 'invited_by_id', 'accepted_at', 'invitation_token',
|
|
];
|
|
|
|
protected $hidden = [
|
|
'password', 'remember_token',
|
|
];
|
|
|
|
protected function casts(): array
|
|
{
|
|
return [
|
|
'email_verified_at' => 'datetime',
|
|
'last_login_at' => 'datetime',
|
|
'email_authentication_at' => 'datetime',
|
|
'invited_at' => 'datetime',
|
|
'accepted_at' => 'datetime',
|
|
'password' => 'hashed',
|
|
'app_authentication_secret' => 'encrypted',
|
|
'app_authentication_recovery_codes' => 'encrypted:array',
|
|
];
|
|
}
|
|
|
|
public function canAccessPanel(Panel $panel): bool
|
|
{
|
|
return $panel->getId() === 'tenant'
|
|
&& $this->status === 'active';
|
|
}
|
|
|
|
public function isAdmin(): bool
|
|
{
|
|
return $this->role === 'admin' || $this->role === 'owner' || $this->hasAnyRole(['admin', 'owner']);
|
|
}
|
|
|
|
public function isOwner(): bool
|
|
{
|
|
return $this->role === 'owner' || $this->hasRole('owner');
|
|
}
|
|
|
|
public function isAccountant(): bool
|
|
{
|
|
return $this->role === 'accountant' || $this->hasRole('accountant');
|
|
}
|
|
|
|
public function isMechanic(): bool
|
|
{
|
|
return in_array($this->role, ['mechanic', 'master'], true) || $this->hasAnyRole(['mechanic']);
|
|
}
|
|
|
|
public function permissionOverrides(): HasMany
|
|
{
|
|
return $this->hasMany(UserPermissionOverride::class);
|
|
}
|
|
|
|
public function invitedBy(): \Illuminate\Database\Eloquent\Relations\BelongsTo
|
|
{
|
|
return $this->belongsTo(self::class, 'invited_by_id');
|
|
}
|
|
|
|
public function company(): \Illuminate\Database\Eloquent\Relations\BelongsTo
|
|
{
|
|
return $this->belongsTo(\App\Models\Central\Company::class);
|
|
}
|
|
|
|
/**
|
|
* Permission check honoring (in order):
|
|
* 1. Active deny-override → false
|
|
* 2. Active grant-override → true
|
|
* 3. Admin/owner bypass → true
|
|
* 4. Standard role-based check
|
|
*/
|
|
public function canDo(string $permission): bool
|
|
{
|
|
$override = $this->activeOverrideFor($permission);
|
|
if ($override) {
|
|
if ($override->mode === 'deny') {
|
|
$this->logDeniedIfSensitive($permission);
|
|
return false;
|
|
}
|
|
if ($override->mode === 'grant') return true;
|
|
}
|
|
|
|
// Owner + admin bypass for permissions without explicit deny.
|
|
if ($this->isAdmin()) return true;
|
|
|
|
try {
|
|
$allowed = $this->can($permission);
|
|
if (! $allowed) $this->logDeniedIfSensitive($permission);
|
|
return $allowed;
|
|
} catch (\Throwable $e) {
|
|
return false;
|
|
}
|
|
}
|
|
|
|
private function activeOverrideFor(string $permissionSlug): ?UserPermissionOverride
|
|
{
|
|
return $this->permissionOverrides()
|
|
->whereHas('permission', fn ($q) => $q->where('name', $permissionSlug))
|
|
->where(fn ($q) => $q->whereNull('expires_at')->orWhere('expires_at', '>', now()))
|
|
->first();
|
|
}
|
|
|
|
/** Sensitive permissions whose deny we should record for audit. */
|
|
private const AUDITED_DENIALS = [
|
|
'admin.users.manage', 'admin.roles.manage', 'admin.settings.edit', 'admin.backup.download',
|
|
'finance.delete_payment', 'finance.view_pl',
|
|
'salaries.mark_paid', 'salaries.view_all',
|
|
'work_orders.delete', 'work_orders.approve_discount_any',
|
|
];
|
|
|
|
private function logDeniedIfSensitive(string $permission): void
|
|
{
|
|
if (! in_array($permission, self::AUDITED_DENIALS, true)) return;
|
|
try {
|
|
activity('permissions')
|
|
->causedBy($this)
|
|
->withProperties(['permission' => $permission])
|
|
->event('permission_denied')
|
|
->log("permission denied: $permission for user #{$this->id}");
|
|
} catch (\Throwable $e) {
|
|
// activity-log may be misconfigured in some contexts — never let auth fail because of it.
|
|
}
|
|
}
|
|
|
|
/** Has 2FA app authentication enabled (Filament native). */
|
|
public function hasTwoFactorEnabled(): bool
|
|
{
|
|
return $this->app_authentication_secret !== null;
|
|
}
|
|
|
|
/** Pending invitation (sent but not yet accepted). */
|
|
public function isPendingInvitation(): bool
|
|
{
|
|
return $this->invited_at !== null && $this->accepted_at === null;
|
|
}
|
|
|
|
/**
|
|
* Create + send an invitation: generates a random token, marks invited_at,
|
|
* and queues the email with the signed accept link. Idempotent — calling
|
|
* again regenerates the token (useful for "resend invitation").
|
|
*/
|
|
public function sendInvitation(?User $invitedBy = null): string
|
|
{
|
|
$token = bin2hex(random_bytes(32)); // 64 chars
|
|
$this->forceFill([
|
|
'invitation_token' => hash('sha256', $token),
|
|
'invited_at' => now(),
|
|
'invited_by_id' => $invitedBy?->id ?? auth()->id(),
|
|
'accepted_at' => null,
|
|
'status' => 'inactive', // can't login until accepted
|
|
])->saveQuietly();
|
|
|
|
\Illuminate\Support\Facades\Mail::to($this->email)
|
|
->queue(new \App\Mail\UserInvitationMail($this, $token));
|
|
|
|
return $token; // returned mainly for tests / API
|
|
}
|
|
|
|
public static function findByInvitationToken(string $rawToken): ?self
|
|
{
|
|
return self::where('invitation_token', hash('sha256', $rawToken))->first();
|
|
}
|
|
|
|
public function acceptInvitation(string $password): void
|
|
{
|
|
$this->forceFill([
|
|
'password' => $password, // hashed cast handles it
|
|
'invitation_token' => null,
|
|
'accepted_at' => now(),
|
|
'status' => 'active',
|
|
'email_verified_at' => now(),
|
|
])->save();
|
|
}
|
|
|
|
public function hasEmailAuthentication(): bool
|
|
{
|
|
return $this->email_authentication_at !== null;
|
|
}
|
|
|
|
public function toggleEmailAuthentication(bool $condition): void
|
|
{
|
|
$this->forceFill([
|
|
'email_authentication_at' => $condition ? now() : null,
|
|
])->saveQuietly();
|
|
}
|
|
|
|
public function getAppAuthenticationSecret(): ?string
|
|
{
|
|
return $this->app_authentication_secret;
|
|
}
|
|
|
|
public function saveAppAuthenticationSecret(?string $secret): void
|
|
{
|
|
$this->forceFill(['app_authentication_secret' => $secret])->saveQuietly();
|
|
}
|
|
|
|
public function getAppAuthenticationHolderName(): string
|
|
{
|
|
return $this->email;
|
|
}
|
|
|
|
public function getAppAuthenticationRecoveryCodes(): ?array
|
|
{
|
|
return $this->app_authentication_recovery_codes;
|
|
}
|
|
|
|
public function saveAppAuthenticationRecoveryCodes(?array $codes): void
|
|
{
|
|
$this->forceFill(['app_authentication_recovery_codes' => $codes])->saveQuietly();
|
|
}
|
|
}
|