1 package FS::ClientAPI::MyAccount;
6 use Digest::MD5 qw(md5_hex);
8 use Business::CreditCard;
10 use FS::CGI qw(small_custview); #doh
12 use FS::Record qw(qsearch qsearchs);
13 use FS::Msgcat qw(gettext);
14 use FS::ClientAPI_SessionCache;
21 use FS::cust_main_county;
24 use vars qw( @cust_main_editable_fields );
25 @cust_main_editable_fields = qw(
26 first last company address1 address2 city
27 county state zip country daytime night fax
28 ship_first ship_last ship_company ship_address1 ship_address2 ship_city
29 ship_state ship_zip ship_country ship_daytime ship_night ship_fax
30 payby payinfo payname paystart_month paystart_year payissue payip
33 use subs qw(_provision);
36 $cache ||= new FS::ClientAPI_SessionCache( {
37 'namespace' => 'FS::ClientAPI::MyAccount',
41 #false laziness w/FS::ClientAPI::passwd::passwd
45 my $svc_domain = qsearchs('svc_domain', { 'domain' => $p->{'domain'} } )
46 or return { error => 'Domain '. $p->{'domain'}. ' not found' };
48 my $svc_acct = qsearchs( 'svc_acct', { 'username' => $p->{'username'},
49 'domsvc' => $svc_domain->svcnum, }
51 return { error => 'User not found.' } unless $svc_acct;
53 my $conf = new FS::Conf;
54 my $pkg_svc = $svc_acct->cust_svc->pkg_svc;
55 return { error => 'Only primary user may log in.' }
56 if $conf->exists('selfservice_server-primary_only')
57 && ( ! $pkg_svc || $pkg_svc->primary_svc ne 'Y' );
59 return { error => 'Incorrect password.' }
60 unless $svc_acct->check_password($p->{'password'});
63 'svcnum' => $svc_acct->svcnum,
66 my $cust_pkg = $svc_acct->cust_svc->cust_pkg;
68 my $cust_main = $cust_pkg->cust_main;
69 $session->{'custnum'} = $cust_main->custnum;
74 $session_id = md5_hex(md5_hex(time(). {}. rand(). $$))
75 } until ( ! defined _cache->get($session_id) ); #just in case
77 _cache->set( $session_id, $session, '1 hour' );
79 return { 'error' => '',
80 'session_id' => $session_id,
86 if ( $p->{'session_id'} ) {
87 _cache->remove($p->{'session_id'});
88 return { 'error' => '' };
90 return { 'error' => "Can't resume session" }; #better error message
97 my($context, $session, $custnum) = _custoragent_session_custnum($p);
98 return { 'error' => $session } if $context eq 'error';
101 if ( $custnum ) { #customer record
103 my $search = { 'custnum' => $custnum };
104 $search->{'agentnum'} = $session->{'agentnum'} if $context eq 'agent';
105 my $cust_main = qsearchs('cust_main', $search )
106 or return { 'error' => "unknown custnum $custnum" };
108 $return{balance} = $cust_main->balance;
112 invnum => $_->invnum,
113 date => time2str("%b %o, %Y", $_->_date),
116 } $cust_main->open_cust_bill;
117 $return{open_invoices} = \@open;
119 my $conf = new FS::Conf;
120 $return{small_custview} =
121 small_custview( $cust_main, $conf->config('countrydefault') );
123 $return{name} = $cust_main->first. ' '. $cust_main->get('last');
125 for (@cust_main_editable_fields) {
126 $return{$_} = $cust_main->get($_);
129 if ( $cust_main->payby =~ /^(CARD|DCRD)$/ ) {
130 $return{payinfo} = $cust_main->payinfo_masked;
131 @return{'month', 'year'} = $cust_main->paydate_monthyear;
134 $return{'invoicing_list'} =
135 join(', ', grep { $_ !~ /^(POST|FAX)$/ } $cust_main->invoicing_list );
136 $return{'postal_invoicing'} =
137 0 < ( grep { $_ eq 'POST' } $cust_main->invoicing_list );
139 } elsif ( $session->{'svcnum'} ) { #no customer record
141 my $svc_acct = qsearchs('svc_acct', { 'svcnum' => $session->{'svcnum'} } )
142 or die "unknown svcnum";
143 $return{name} = $svc_acct->email;
147 return { 'error' => 'Expired session' }; #XXX redirect to login w/this err!
151 return { 'error' => '',
152 'custnum' => $custnum,
160 my $session = _cache->get($p->{'session_id'})
161 or return { 'error' => "Can't resume session" }; #better error message
163 my $custnum = $session->{'custnum'}
164 or return { 'error' => "no customer record" };
166 my $cust_main = qsearchs('cust_main', { 'custnum' => $custnum } )
167 or return { 'error' => "unknown custnum $custnum" };
169 my $new = new FS::cust_main { $cust_main->hash };
170 $new->set( $_ => $p->{$_} )
171 foreach grep { exists $p->{$_} } @cust_main_editable_fields;
173 if ( $p->{'payby'} =~ /^(CARD|DCRD)$/ ) {
174 $new->paydate($p->{'year'}. '-'. $p->{'month'}. '-01');
175 if ( $new->payinfo eq $cust_main->payinfo_masked ) {
176 $new->payinfo($cust_main->payinfo);
178 $new->paycvv($p->{'paycvv'});
183 if ( exists $p->{'invoicing_list'} || exists $p->{'postal_invoicing'} ) {
184 #false laziness with httemplate/edit/process/cust_main.cgi
185 @invoicing_list = split( /\s*\,\s*/, $p->{'invoicing_list'} );
186 push @invoicing_list, 'POST' if $p->{'postal_invoicing'};
188 @invoicing_list = $cust_main->invoicing_list;
191 my $error = $new->replace($cust_main, \@invoicing_list);
192 return { 'error' => $error } if $error;
195 return { 'error' => '' };
200 my $session = _cache->get($p->{'session_id'})
201 or return { 'error' => "Can't resume session" }; #better error message
207 my $conf = new FS::Conf;
208 my %states = map { $_->state => 1 }
209 qsearch('cust_main_county', {
210 'country' => $conf->config('countrydefault') || 'US'
213 use vars qw($payment_info); #cache for performance
216 #list all counties/states/countries
217 'cust_main_county' =>
218 [ map { $_->hashref } qsearch('cust_main_county', {}) ],
220 #shortcut for one-country folks
222 [ sort { $a cmp $b } keys %states ],
225 'VISA' => 'VISA card',
226 'MasterCard' => 'MasterCard',
227 'Discover' => 'Discover card',
228 'American Express' => 'American Express card',
229 'Switch' => 'Switch',
239 my %return = %$payment_info;
241 my $custnum = $session->{'custnum'};
243 my $cust_main = qsearchs('cust_main', { 'custnum' => $custnum } )
244 or return { 'error' => "unknown custnum $custnum" };
246 $return{balance} = $cust_main->balance;
248 $return{payname} = $cust_main->payname
249 || ( $cust_main->first. ' '. $cust_main->get('last') );
251 $return{$_} = $cust_main->get($_) for qw(address1 address2 city state zip);
253 $return{payby} = $cust_main->payby;
255 if ( $cust_main->payby =~ /^(CARD|DCRD)$/ ) {
256 #warn $return{card_type} = cardtype($cust_main->payinfo);
257 $return{payinfo} = $cust_main->payinfo;
259 @return{'month', 'year'} = $cust_main->paydate_monthyear;
263 #doubleclick protection
265 $return{paybatch} = "webui-MyAccount-$_date-$$-". rand() * 2**32;
267 return { 'error' => '',
273 #some false laziness with httemplate/process/payment.cgi - look there for
274 #ACH and CVV support stuff
275 sub process_payment {
279 my $session = _cache->get($p->{'session_id'})
280 or return { 'error' => "Can't resume session" }; #better error message
284 my $custnum = $session->{'custnum'};
286 my $cust_main = qsearchs('cust_main', { 'custnum' => $custnum } )
287 or return { 'error' => "unknown custnum $custnum" };
289 $p->{'payname'} =~ /^([\w \,\.\-\']+)$/
290 or return { 'error' => gettext('illegal_name'). " payname: ". $p->{'payname'} };
293 $p->{'paybatch'} =~ /^([\w \!\@\#\$\%\&\(\)\-\+\;\:\'\"\,\.\?\/\=]*)$/
294 or return { 'error' => gettext('illegal_text'). " paybatch: ". $p->{'paybatch'} };
299 #if ( $payby eq 'CHEK' ) {
301 # $p->{'payinfo1'} =~ /^(\d+)$/
302 # or return { 'error' => "illegal account number ". $p->{'payinfo1'} };
304 # $p->{'payinfo2'} =~ /^(\d+)$/
305 # or return { 'error' => "illegal ABA/routing number ". $p->{'payinfo2'} };
307 # $payinfo = $payinfo1. '@'. $payinfo2;
309 #} elsif ( $payby eq 'CARD' ) {
311 $payinfo = $p->{'payinfo'};
313 $payinfo =~ /^(\d{13,16})$/
314 or return { 'error' => gettext('invalid_card') }; # . ": ". $self->payinfo
317 or return { 'error' => gettext('invalid_card') }; # . ": ". $self->payinfo
318 return { 'error' => gettext('unknown_card_type') }
319 if cardtype($payinfo) eq "Unknown";
321 if ( defined $cust_main->dbdef_table->column('paycvv') ) {
322 if ( length($p->{'paycvv'} ) ) {
323 if ( cardtype($payinfo) eq 'American Express card' ) {
324 $p->{'paycvv'} =~ /^(\d{4})$/
325 or return { 'error' => "CVV2 (CID) for American Express cards is four digits." };
328 $p->{'paycvv'} =~ /^(\d{3})$/
329 or return { 'error' => "CVV2 (CVC2/CID) is three digits." };
336 # die "unknown payby $payby";
339 my $error = $cust_main->realtime_bop( 'CC', $p->{'amount'},
341 'payinfo' => $payinfo,
342 'paydate' => $p->{'year'}. '-'. $p->{'month'}. '-01',
343 'payname' => $payname,
344 'paybatch' => $paybatch,
346 map { $_ => $p->{$_} } qw( paystart_month paystart_year payissue payip
347 address1 address2 city state zip )
349 return { 'error' => $error } if $error;
351 $cust_main->apply_payments;
353 if ( $p->{'save'} ) {
354 my $new = new FS::cust_main { $cust_main->hash };
355 $new->set( $_ => $p->{$_} )
356 foreach qw( payname paystart_month paystart_year payissue payip
357 address1 address2 city state zip payinfo );
358 $new->set( 'paydate' => $p->{'year'}. '-'. $p->{'month'}. '-01' );
359 $new->set( 'payby' => $p->{'auto'} ? 'CARD' : 'DCRD' );
360 my $error = $new->replace($cust_main);
361 return { 'error' => $error } if $error;
365 return { 'error' => '' };
373 my $session = _cache->get($p->{'session_id'})
374 or return { 'error' => "Can't resume session" }; #better error message
378 my $custnum = $session->{'custnum'};
380 my $cust_main = qsearchs('cust_main', { 'custnum' => $custnum } )
381 or return { 'error' => "unknown custnum $custnum" };
383 my( $amount, $seconds ) = ( 0, 0 );
384 my $error = $cust_main->recharge_prepay( $p->{'prepaid_cardnum'},
389 return { 'error' => $error } if $error;
391 return { 'error' => '',
393 'seconds' => $seconds,
394 'duration' => duration_exact($seconds),
401 my $session = _cache->get($p->{'session_id'})
402 or return { 'error' => "Can't resume session" }; #better error message
404 my $custnum = $session->{'custnum'};
406 my $invnum = $p->{'invnum'};
408 my $cust_bill = qsearchs('cust_bill', { 'invnum' => $invnum,
409 'custnum' => $custnum } )
410 or return { 'error' => "Can't find invnum" };
414 return { 'error' => '',
416 'invoice_text' => join('', $cust_bill->print_text ),
417 'invoice_html' => $cust_bill->print_html,
425 #sessioning for this? how do we get the session id to the backend invoice
426 # template so it can add it to the link, blah
428 my $templatename = $p->{'templatename'};
430 #false laziness-ish w/view/cust_bill-logo.cgi
432 my $conf = new FS::Conf;
433 if ( $templatename =~ /^([^\.\/]*)$/ && $conf->exists("logo_$1.png") ) {
434 $templatename = "_$1";
439 my $filename = "logo$templatename.png";
441 return { 'error' => '',
442 'logo' => $conf->config_binary($filename),
443 'content_type' => 'image/png', #should allow gif, jpg too
450 my $session = _cache->get($p->{'session_id'})
451 or return { 'error' => "Can't resume session" }; #better error message
453 my $custnum = $session->{'custnum'};
455 my $cust_main = qsearchs('cust_main', { 'custnum' => $custnum } )
456 or return { 'error' => "unknown custnum $custnum" };
458 my @cust_bill = $cust_main->cust_bill;
460 return { 'error' => '',
461 'invoices' => [ map { { 'invnum' => $_->invnum,
462 '_date' => $_->_date,
471 my $session = _cache->get($p->{'session_id'})
472 or return { 'error' => "Can't resume session" }; #better error message
474 my $custnum = $session->{'custnum'};
476 my $cust_main = qsearchs('cust_main', { 'custnum' => $custnum } )
477 or return { 'error' => "unknown custnum $custnum" };
479 my @errors = $cust_main->cancel( 'quiet'=>1 );
481 my $error = scalar(@errors) ? join(' / ', @errors) : '';
483 return { 'error' => $error };
490 my($context, $session, $custnum) = _custoragent_session_custnum($p);
491 return { 'error' => $session } if $context eq 'error';
493 my $search = { 'custnum' => $custnum };
494 $search->{'agentnum'} = $session->{'agentnum'} if $context eq 'agent';
495 my $cust_main = qsearchs('cust_main', $search )
496 or return { 'error' => "unknown custnum $custnum" };
498 #return { 'cust_pkg' => [ map { $_->hashref } $cust_main->ncancelled_pkgs ] };
500 my $conf = new FS::Conf;
502 { 'svcnum' => $session->{'svcnum'},
503 'custnum' => $custnum,
504 'cust_pkg' => [ map {
508 [ map $_->hashref, $_->available_part_svc ],
510 [ map { my $ref = { $_->hash,
511 label => [ $_->label ],
513 $ref->{_password} = $_->svc_x->_password
514 if $context eq 'agent'
515 && $conf->exists('agent-showpasswords')
516 && $_->part_svc->svcdb eq 'svc_acct';
521 } $cust_main->ncancelled_pkgs
524 small_custview( $cust_main, $conf->config('countrydefault') ),
532 my($context, $session, $custnum) = _custoragent_session_custnum($p);
533 return { 'error' => $session } if $context eq 'error';
535 my $search = { 'custnum' => $custnum };
536 $search->{'agentnum'} = $session->{'agentnum'} if $context eq 'agent';
537 my $cust_main = qsearchs('cust_main', $search )
538 or return { 'error' => "unknown custnum $custnum" };
540 #false laziness w/ClientAPI/Signup.pm
542 my $cust_pkg = new FS::cust_pkg ( {
543 'custnum' => $custnum,
544 'pkgpart' => $p->{'pkgpart'},
546 my $error = $cust_pkg->check;
547 return { 'error' => $error } if $error;
550 unless ( $p->{'svcpart'} eq 'none' ) {
554 if ( $p->{'svcpart'} =~ /^(\d+)$/ ) {
556 my $part_svc = qsearchs('part_svc', { 'svcpart' => $svcpart } );
557 return { 'error' => "Unknown svcpart $svcpart" } unless $part_svc;
558 $svcdb = $part_svc->svcdb;
562 $svcpart ||= $cust_pkg->part_pkg->svcpart($svcdb);
565 'svc_acct' => [ qw( username _password sec_phrase popnum ) ],
566 'svc_domain' => [ qw( domain ) ],
567 'svc_external' => [ qw( id title ) ],
570 my $svc_x = "FS::$svcdb"->new( {
571 'svcpart' => $svcpart,
572 map { $_ => $p->{$_} } @{$fields{$svcdb}}
575 if ( $svcdb eq 'svc_acct' ) {
578 while ( length($p->{"snarf_machine$snarfnum"}) ) {
579 my $acct_snarf = new FS::acct_snarf ( {
580 'machine' => $p->{"snarf_machine$snarfnum"},
581 'protocol' => $p->{"snarf_protocol$snarfnum"},
582 'username' => $p->{"snarf_username$snarfnum"},
583 '_password' => $p->{"snarf_password$snarfnum"},
586 push @acct_snarf, $acct_snarf;
588 $svc_x->child_objects( \@acct_snarf );
591 my $y = $svc_x->setdefault; # arguably should be in new method
592 return { 'error' => $y } if $y && !ref($y);
594 $error = $svc_x->check;
595 return { 'error' => $error } if $error;
602 tie my %hash, 'Tie::RefHash';
603 %hash = ( $cust_pkg => \@svc );
605 $error = $cust_main->order_pkgs( \%hash, '', 'noexport' => 1 );
606 return { 'error' => $error } if $error;
608 my $conf = new FS::Conf;
609 if ( $conf->exists('signup_server-realtime') ) {
611 my $old_balance = $cust_main->balance;
613 my $bill_error = $cust_main->bill;
614 $cust_main->apply_payments;
615 $cust_main->apply_credits;
616 $bill_error = $cust_main->collect;
618 if ( $cust_main->balance > $old_balance
619 && $cust_main->balance > 0
620 && $cust_main->payby !~ /^(BILL|DCRD|DCHK)$/ ) {
621 #this makes sense. credit is "un-doing" the invoice
622 $cust_main->credit( sprintf("%.2f", $cust_main->balance - $old_balance ),
623 'self-service decline' );
624 $cust_main->apply_credits( 'order' => 'newest' );
626 $cust_pkg->cancel('quiet'=>1);
627 return { 'error' => '_decline', 'bill_error' => $bill_error };
636 return { error => '', pkgnum => $cust_pkg->pkgnum };
642 my $session = _cache->get($p->{'session_id'})
643 or return { 'error' => "Can't resume session" }; #better error message
645 my $custnum = $session->{'custnum'};
647 my $cust_main = qsearchs('cust_main', { 'custnum' => $custnum } )
648 or return { 'error' => "unknown custnum $custnum" };
650 my $pkgnum = $p->{'pkgnum'};
652 my $cust_pkg = qsearchs('cust_pkg', { 'custnum' => $custnum,
653 'pkgnum' => $pkgnum, } )
654 or return { 'error' => "unknown pkgnum $pkgnum" };
656 my $error = $cust_pkg->cancel( 'quiet'=>1 );
657 return { 'error' => $error };
664 return { 'error' => gettext('passwords_dont_match') }
665 if $p->{'_password'} ne $p->{'_password2'};
666 return { 'error' => gettext('empty_password') }
667 unless length($p->{'_password'});
669 _provision( 'FS::svc_acct',
670 [qw(username _password)],
671 [qw(username _password)],
677 sub provision_external {
679 #_provision( 'FS::svc_external', [qw(id title)], [qw(id title)], $p, @_ );
680 _provision( 'FS::svc_external',
689 my( $class, $fields, $return_fields, $p ) = splice(@_, 0, 4);
691 my($context, $session, $custnum) = _custoragent_session_custnum($p);
692 return { 'error' => $session } if $context eq 'error';
694 my $search = { 'custnum' => $custnum };
695 $search->{'agentnum'} = $session->{'agentnum'} if $context eq 'agent';
696 my $cust_main = qsearchs('cust_main', $search )
697 or return { 'error' => "unknown custnum $custnum" };
699 my $pkgnum = $p->{'pkgnum'};
701 my $cust_pkg = qsearchs('cust_pkg', { 'custnum' => $custnum,
704 or return { 'error' => "unknown pkgnum $pkgnum" };
706 my $part_svc = qsearchs('part_svc', { 'svcpart' => $p->{'svcpart'} } )
707 or return { 'error' => "unknown svcpart $p->{'svcpart'}" };
709 my $svc_x = $class->new( {
710 'pkgnum' => $p->{'pkgnum'},
711 'svcpart' => $p->{'svcpart'},
712 map { $_ => $p->{$_} } @$fields
714 my $error = $svc_x->insert;
715 $svc_x = qsearchs($svc_x->table, { 'svcnum' => $svc_x->svcnum })
718 return { 'svc' => $part_svc->svc,
720 map { $_ => $svc_x->get($_) } @$return_fields
728 my($context, $session, $custnum) = _custoragent_session_custnum($p);
729 return { 'error' => $session } if $context eq 'error';
731 my $search = { 'custnum' => $custnum };
732 $search->{'agentnum'} = $session->{'agentnum'} if $context eq 'agent';
733 my $cust_main = qsearchs('cust_main', $search )
734 or return { 'error' => "unknown custnum $custnum" };
736 my $pkgnum = $p->{'pkgnum'};
738 my $cust_pkg = qsearchs('cust_pkg', { 'custnum' => $custnum,
741 or return { 'error' => "unknown pkgnum $pkgnum" };
743 my $svcpart = $p->{'svcpart'};
745 my $pkg_svc = qsearchs('pkg_svc', { 'pkgpart' => $cust_pkg->pkgpart,
746 'svcpart' => $svcpart, } )
747 or return { 'error' => "unknown svcpart $svcpart for pkgnum $pkgnum" };
748 my $part_svc = $pkg_svc->part_svc;
750 my $conf = new FS::Conf;
753 'svc' => $part_svc->svc,
754 'svcdb' => $part_svc->svcdb,
756 'svcpart' => $svcpart,
757 'custnum' => $custnum,
759 'security_phrase' => 0, #XXX !
760 'svc_acct_pop' => [], #XXX !
762 'init_popstate' => '',
767 small_custview( $cust_main, $conf->config('countrydefault') ),
773 sub unprovision_svc {
776 my($context, $session, $custnum) = _custoragent_session_custnum($p);
777 return { 'error' => $session } if $context eq 'error';
779 my $search = { 'custnum' => $custnum };
780 $search->{'agentnum'} = $session->{'agentnum'} if $context eq 'agent';
781 my $cust_main = qsearchs('cust_main', $search )
782 or return { 'error' => "unknown custnum $custnum" };
784 my $svcnum = $p->{'svcnum'};
786 my $cust_svc = qsearchs('cust_svc', { 'svcnum' => $svcnum, } )
787 or return { 'error' => "unknown svcnum $svcnum" };
789 return { 'error' => "Service $svcnum does not belong to customer $custnum" }
790 unless $cust_svc->cust_pkg->custnum == $custnum;
792 my $conf = new FS::Conf;
794 return { 'svc' => $cust_svc->part_svc->svc,
795 'error' => $cust_svc->cancel,
797 small_custview( $cust_main, $conf->config('countrydefault') ),
804 sub _custoragent_session_custnum {
807 my($context, $session, $custnum);
808 if ( $p->{'session_id'} ) {
810 $context = 'customer';
811 $session = _cache->get($p->{'session_id'})
812 or return ( 'error' => "Can't resume session" ); #better error message
813 $custnum = $session->{'custnum'};
815 } elsif ( $p->{'agent_session_id'} ) {
818 my $agent_cache = new FS::ClientAPI_SessionCache( {
819 'namespace' => 'FS::ClientAPI::Agent',
821 $session = $agent_cache->get($p->{'agent_session_id'})
822 or return ( 'error' => "Can't resume session" ); #better error message
823 $custnum = $p->{'custnum'};
826 return ( 'error' => "Can't resume session" ); #better error message
829 ($context, $session, $custnum);