Compare commits

..
8 Commits
9 changed files with 218 additions and 79 deletions
+26 -9
View File
@@ -8,7 +8,6 @@
#
#THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
# This controller class will handle map management
class CustomersController < ApplicationController
include AuthHelper
@@ -26,8 +25,8 @@ class CustomersController < ApplicationController
include SortHelper
helper :timelog
before_action :add_customer, only: :new
before_action :view_customer, except: [:new, :view]
before_action :add_customer, only: [:new, :create]
before_action :view_customer, except: [:new, :create, :view]
skip_before_action :verify_authenticity_token, :check_if_login_required, only: [:view]
def address_to_s(address)
@@ -75,14 +74,28 @@ class CustomersController < ApplicationController
def create
@customer = Customer.new(allowed_params)
@customer.save
log "Customer ##{@customer.id} created successfully."
flash[:notice] = t :notice_customer_created
redirect_to @customer
respond_to do |format|
if @customer.save
log "Customer ##{@customer.id} created successfully."
format.html { redirect_to @customer, notice: l(:notice_successful_create) }
format.json { render json: { id: @customer.id, name: @customer.name }, status: :created }
else
format.html { render :new }
format.json { render json: { errors: @customer.errors.full_messages }, status: :unprocessable_entity }
end
end
rescue => e
log "Failed to create customer: #{e.message}"
flash[:error] = e.message
redirect_to new_customer_path
respond_to do |format|
format.html {
flash[:error] = e.message
redirect_to new_customer_path
}
format.json {
render json: { errors: [e.message] }, status: :internal_server_error
}
end
end
def edit
@@ -136,6 +149,10 @@ class CustomersController < ApplicationController
def new
@customer = Customer.new
if request.xhr?
render partial: 'form', layout: false, locals: { hide_submit: true, hide_toolbar: true }
end
end
def only_one_non_zero?(array)
+65 -7
View File
@@ -1,15 +1,73 @@
<%= call_hook :customer_actions_top, { customer: @customer } %>
<%= link_to t(:label_create_estimate), "https://qbo.intuit.com/app/estimate?nameId=#{@customer.id}", target: :_blank %>
<p>
<%= link_to t(:label_new_issue), new_issue_path(issue: { customer_id: @customer.id }), id: "dynamic-new-issue-link", target: :_blank %>
</p>
<br/>
<br/>
<p>
<%= link_to t(:label_create_estimate), "https://qbo.intuit.com/app/estimate?nameId=#{@customer.id}", target: :_blank %>
</p>
<%= link_to t(:label_create_payment), "https://qbo.intuit.com/app/recvpayment?nameId=#{@customer.id}", target: :_blank %>
<br/>
<br/>
<p>
<%= link_to t(:label_create_payment), "https://qbo.intuit.com/app/recvpayment?nameId=#{@customer.id}", target: :_blank %>
</p>
<%= call_hook :customer_actions_bottom, { customer: @customer } %>
<%= button_to t(:label_edit_customer), edit_customer_path(@customer), method: :get%>
<script>
function handleSingleSelect(event, className) {
if (event.target.checked) {
// Uncheck all other checkboxes of the same type
document.querySelectorAll('.' + className).forEach(cb => {
if (cb !== event.target) {
cb.checked = false;
}
});
}
updateLink();
}
// Bind single-select behavior to checkboxes once the DOM is loaded
document.addEventListener('DOMContentLoaded', function() {
document.querySelectorAll('.estimate-checkbox').forEach(cb => {
cb.addEventListener('change', (e) => handleSingleSelect(e, 'estimate-checkbox'));
});
document.querySelectorAll('.vehicle-checkbox').forEach(cb => {
cb.addEventListener('change', (e) => handleSingleSelect(e, 'vehicle-checkbox'));
});
});
function updateLink() {
const link = document.getElementById('dynamic-new-issue-link');
if (!link) return;
// Cache the pristine base URL on first run
if (!link.dataset.baseUrl) {
link.dataset.baseUrl = link.getAttribute('href');
}
// Build base URL object
let url = new URL(link.dataset.baseUrl, window.location.origin);
// 1. Handle Single Estimate
const checkedEstimate = document.querySelector('.estimate-checkbox:checked');
if (checkedEstimate) {
url.searchParams.set('issue[estimate_id]', checkedEstimate.value);
} else {
url.searchParams.delete('issue[estimate_id]');
}
// 2. Handle Single Vehicle
const checkedVehicle = document.querySelector('.vehicle-checkbox:checked');
if (checkedVehicle) {
url.searchParams.set('issue[vehicle_id]', checkedVehicle.value);
} else {
url.searchParams.delete('issue[vehicle_id]');
}
// Update the link's href attribute
link.setAttribute('href', url.toString());
}
</script>
+25 -29
View File
@@ -2,59 +2,55 @@
<tbody>
<tr>
<th><%=t(:label_name)%></th>
<th><%= t(:label_name) %></th>
<td><%= customer.name %></td>
</tr>
<tr>
<th><%=t(:label_email)%></th>
<th><%= t(:label_email) %></th>
<td><%= customer.email %></td>
</tr>
<tr>
<th><%=t(:label_primary_phone)%></th>
<th><%= t(:label_primary_phone) %></th>
<td><%= number_to_phone(customer&.primary_phone&.gsub(/[^\d]/, '').to_i, area_code: true) %></td>
</tr>
<tr>
<th><%=t(:label_mobile_phone)%></th>
<th><%= t(:label_mobile_phone) %></th>
<td><%= number_to_phone(customer&.mobile_phone&.gsub(/[^\d]/, '').to_i, area_code: true) %></td>
</tr>
<tr>
<th><%=t(:label_billing_address)%></th>
<td><pre><%= @billing_address %></pre></td>
</tr>
<tr>
<th><%=t(:label_shipping_address)%></th>
<td><pre><%= @shipping_address %></pre></td>
<tr>
<th><%= t(:label_billing_address) %></th>
<td><pre><%= @billing_address %></pre></td>
</tr>
<tr>
<th><%=t(:label_account_balance)%></th>
<td>$<%= customer.balance %></td>
<th><%= t(:label_shipping_address) %></th>
<td><pre><%= @shipping_address %></pre></td>
</tr>
<tr>
<th colspan="2"><h4><%=t(:field_notes)%></hr></th>
<th><%= t(:label_account_balance) %></th>
<td>$<%= customer.balance %></td>
</tr>
<% if customer.notes.present? %>
<tr>
<th colspan="2"><h4><%= t(:field_notes) %></h4></th>
</tr>
<tr>
<td colspan="2">
<pre id="note-display" style="text-align: left; white-space: pre-wrap; font-family: inherit;">
<%= customer.notes %>
</pre>
</td>
</tr>
<script>
const preElement = document.getElementById('note-display');
// This takes the text, trims the edges, and puts it back
preElement.textContent = preElement.textContent.trim();
</script>
<tr>
<td colspan="2">
<div class="wiki">
<%= textilizable(customer, :notes) %>
</div>
</td>
</tr>
<% end %>
</tbody>
</table>
<br/>
<br/>
<br/>
+13 -12
View File
@@ -33,25 +33,26 @@
</div>
<div class="clearfix">
<%=t(:field_notes)%>:
<%= t(:field_notes) %>:
<div class="input">
<p>
<%= content_tag :span, id: "issue_description_and_toolbar" do %>
<p>
<%= f.text_area :notes,
cols: 60,
rows: 10,
accesskey: accesskey(:edit),
class: 'wiki-edit',
no_label: true %>
rows: 8,
class: 'wiki-edit',
style: 'width: 95%;',
id: 'customer_notes' %>
<% unless local_assigns[:hide_toolbar] %>
<%= wikitoolbar_for 'customer_notes' %>
<% end %>
</p>
<%= wikitoolbar_for :issue_description %>
</div>
</div>
<div class="actions">
<%= f.submit %>
</div>
<% unless local_assigns[:hide_submit] %>
<div class="actions">
<%= f.submit %>
</div>
<% end %>
<% end %>
</fieldset>
+2 -2
View File
@@ -2,11 +2,11 @@
<% estimates.sort.reverse.each do |estimate| %>
<div class="row">
<%= check_box_tag "estimate_ids[]", estimate.id, false, onchange: "updateLink()", data: { url: estimate_path(estimate), text: "Estimate ##{estimate.to_s}" }, class: "estimate-checkbox appointment" %>
<%= check_box_tag "estimate_ids[]", estimate.id, false, onchange: "updateLink()", data: { text: "Estimate ##{estimate.doc_number}" }, class: "estimate-checkbox appointment" %>
<b><%= link_to "##{estimate.doc_number}", estimate_path(estimate), target: :_blank %></b> <%= estimate.txn_date %>
</div>
<% end %>
<% else %>
<p><%=t(:label_no_estimates)%>.</p>
<% end %>
<% end %>
+1
View File
@@ -65,6 +65,7 @@ en:
label_model: "Model"
label_name: "Name"
label_new_customer: "New Customer"
label_new_issue: "New Issue"
label_qbo_never_synced: "Never Synced"
label_no_customers: "There are no customers matching the search term(s)."
label_no_estimates: "No Estimates"
+1 -1
View File
@@ -14,7 +14,7 @@ Redmine::Plugin.register :redmine_qbo do
name 'Redmine QBO plugin'
author 'Rick Barrette'
description 'A pluging for Redmine to connect with QuickBooks Online to create Time Activity Entries for billable hours logged when an Issue is closed'
version '2026.8.0'
version '2026.8.2'
url 'https://github.com/rickbarrette/redmine_qbo'
author_url 'https://barrettefabrication.com'
settings default: {empty: true}, partial: 'qbo/settings'
@@ -11,27 +11,51 @@
module RedmineQbo
module Patches
module AttachmentsControllerPatch
module Helper
# Check if login is globally required to access the application
def check_if_login_required
# Return true if the user is already logged in
return true if User.current.logged?
# Pull up the attachment and verify if we have a valid token for the issue
attachment = Attachment.find_by(id: params[:id])
return require_login if attachment.nil?
token = CustomerToken.where("token = ? AND expires_at > ?", session[:token], Time.current).first
return true if token&.issue_id == attachment.container_id
# Default to requiring login if all else fails
require_login if Setting.login_required?
end
end
def self.apply
AttachmentsController.class_eval do
helper Helper
# 1. PREPEND: Must run before ANY of Redmine's ApplicationController filters
prepend_before_action :set_customer_token_thread
# 2. Skip global login redirects if the user holds a valid token for this file
skip_before_action :check_if_login_required, if: :valid_customer_token?
skip_before_action :check_project_privacy, raise: false, if: :valid_customer_token?
# Note: We do NOT need to skip :read_authorize anymore.
# Because we patched Attachment#visible?, read_authorize will pass naturally!
private
def set_customer_token_thread
if session[:token].present?
Thread.current[:customer_token] = CustomerToken.active.find_by(token: session[:token])
end
end
def valid_customer_token?
token = Thread.current[:customer_token]
return false unless token
# Handle "Download All" zip requests (object_type=issues, object_id=ID)
if params[:action] == 'download_all'
return params[:object_type] == 'issues' && params[:object_id].to_i == token.issue_id
end
# Handle normal single attachment requests (show, download, thumbnail)
attachment = Attachment.find_by(id: params[:id])
return false unless attachment
# Allow if attachment belongs directly to the Issue
if attachment.container_type == 'Issue' && attachment.container_id == token.issue_id
return true
end
# Allow if attachment belongs to a Journal (comment) on the Issue
if attachment.container_type == 'Journal' && attachment.container.journalized_type == 'Issue' && attachment.container.journalized_id == token.issue_id
return true
end
false
end
end
end
end
+42
View File
@@ -176,6 +176,10 @@ module RedmineQbo
edit_section_links: false,
headings: false,
inline_attachments: false)
# Apply the fix here
text = sanitize_html_for_pdf(text)
pdf.RDMwriteFormattedCell(190, 5, '', '', text, issue.attachments, "LRB")
end
@@ -275,6 +279,10 @@ module RedmineQbo
pdf.ln unless journal.details.empty?
pdf.SetFontStyle('', 8)
text = textilizable(journal, :notes, only_path: false, edit_section_links: false, headings: false, inline_attachments: false)
# Apply the fix here
text = sanitize_html_for_pdf(text)
pdf.RDMwriteFormattedCell(190, 5, '', '', text, issue.attachments, "")
end
pdf.ln
@@ -309,6 +317,40 @@ module RedmineQbo
end
end
private
# NEW HELPER: Aggressively cleans up HTML so RBPDF doesn't crash on tables
def sanitize_html_for_pdf(text)
clean_text = text.to_s.dup
# 1. RBPDF layout engine hates div wrappers. Strip all opening and closing divs.
clean_text.gsub!(/<\/?div[^>]*>/i, '')
# 2. Rebuild tables into a completely flat, pure HTML structure that TCPDF supports
clean_text.gsub!(/<table[^>]*>.*?<\/table>/mi) do |match|
table_html = match.dup
# Strip thead and tbody tags completely
table_html.gsub!(/<\/?thead[^>]*>/i, '')
table_html.gsub!(/<\/?tbody[^>]*>/i, '')
# TCPDF cell width calculations crash on <th> tags. Convert them to <td> + bold.
table_html.gsub!(/<th([^>]*)>/i, '<td\1><strong>')
table_html.gsub!(/<\/th>/i, '</strong></td>')
# Remove all newlines and spaces between tags to prevent stray text nodes crashing the parser
table_html.gsub!(/>\s+</m, '><')
table_html.gsub!(/\r?\n/, '')
# Inject a standardized <table> tag with borders so the table actually renders visibly
table_html.sub!(/<table[^>]*>/i, '<table border="1" cellpadding="4" style="border-collapse: collapse;">')
table_html
end
clean_text
end
end
end
end