class OrdersController < AdminBaseController
  before_action :set_order, only: [:show, :edit, :update, :destroy]

  # GET /orders
  # GET /orders.json
  def index
    if not current_user.allowed?(:view_orders)
      redirect_to "/admin", alert: "你没有权限进入此页面!" and return
    end

    @q = Order.ransack(params[:q])
    @q.sorts = "id DESC" if @q.sorts.empty?
    @orders = @q.result.page(params[:page])
  end

  # GET /orders/1
  # GET /orders/1.json
  def show
    @q = ShippingBox.where(po: @order.sn).ransack(params[:q])
    @q.sorts = "id DESC" if @q.sorts.empty?
    @shipping_boxes = @q.result.page(params[:page]).per(20)
  end

  # GET /orders/new
  def new
    @order = Order.new
  end

  # GET /orders/1/edit
  def edit
  end

  # POST /orders
  # POST /orders.json
  def create
    if not current_user.allowed?(:create_orders)
      redirect_to "/admin", alert: "你没有权限进入此页面!" and return
    end

    @order = Order.new(order_params)
    @order.created_by = current_user.true_name

    respond_to do |format|
      if @order.save
        format.html { redirect_to @order, info: "Order was successfully created." }
        format.json { render :show, status: :created, location: @order }
      else
        format.html { render :new }
        format.json { render json: @order.errors, status: :unprocessable_entity }
      end
    end
  end

  # PATCH/PUT /orders/1
  # PATCH/PUT /orders/1.json
  def update
    respond_to do |format|
      if @order.update(order_params)
        format.html { redirect_to @order, notice: "Order was successfully updated." }
        format.json { render :show, status: :ok, location: @order }
      else
        format.html { render :edit }
        format.json { render json: @order.errors, status: :unprocessable_entity }
      end
    end
  end

  # DELETE /orders/1
  # DELETE /orders/1.json
  def destroy
    @order.destroy
    respond_to do |format|
      format.html { redirect_to orders_url, notice: "Order was successfully destroyed." }
      format.json { head :no_content }
    end
  end

  private

  # Use callbacks to share common setup or constraints between actions.
  def set_order
    @order = Order.find(params[:id])
  end

  # Only allow a list of trusted parameters through.
  def order_params
    params.require(:order).permit(:sn, :client_id, :due_date, :confirmed_at, :finished_at, :created_by, :status, :remark)
  end
end
