diff --git a/CHANGELOG.md b/CHANGELOG.md index 9b26825..383f82b 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -7,6 +7,10 @@ and this project follows [Semantic Versioning](https://semver.org/). ## [Unreleased] +### Added + +- Supervisors can now unassign a donation that was previously applied to a registration, from a new "Assigned donations" list on the Payments page. This reverses the allocation (the registration's balance goes back up and the donation becomes available again), reverting the registration's status and revoking any tickets issued only because that allocation completed payment — blocked if a ticket has already been scanned. The registrant is notified by email/WhatsApp, mirroring the notification sent when a donation is first applied. + ### Performance - Reconciling a Yoco card payment or sending a payment link on the supervisor Payments page no longer blocks the response on ticket-PDF generation and email/WhatsApp sends — these now run in the background, matching how manual payments already worked. diff --git a/backend/src/controllers/paymentController.js b/backend/src/controllers/paymentController.js index bc2534f..44f030c 100644 --- a/backend/src/controllers/paymentController.js +++ b/backend/src/controllers/paymentController.js @@ -5,7 +5,7 @@ const { computeRegistrationTotalDue, refreshPricingForRegistration } = require(' const axios = require('axios'); const { emailTickets } = require('./ticketController'); const { safeErrorMessage } = require('../utils/errorUtils'); -const { assertEventOpen } = require('../utils/cashupUtils'); +const { assertEventOpen, assertRegistrationEventOpen } = require('../utils/cashupUtils'); // @desc Create a new payment // @route POST /api/payments @@ -770,6 +770,129 @@ const assignDonationToRegistration = async (req, res) => { } }; +// @desc Reverse a previous donation assignment — hard-deletes the leg payment and reverts +// the registration's status/tickets. The donation itself (never touched by assign) +// is unaffected, so its remaining balance simply goes back up. +// @route POST /api/payments/unassign-donation +// @access Private/Supervisor +const unassignDonationFromRegistration = async (req, res) => { + try { + const { legId } = req.body; + if (!legId) { + res.status(400); + throw new Error('legId is required'); + } + + const leg = await prisma.payment.findUnique({ where: { id: legId } }); + if (!leg) { + res.status(404); + throw new Error('Payment not found'); + } + + // Mirror the frontend's isDonationLeg check: a real donation-assignment leg is a positive, + // non-donation payment that references a donation via originalPaymentId. This also rejects + // refund rows, which set originalPaymentId too but always with a negative amount. + if (leg.isDonation || !leg.originalPaymentId || !(leg.amount > 0)) { + res.status(400); + throw new Error('This payment is not a donation-assignment leg'); + } + if (!leg.registrationId) { + res.status(400); + throw new Error('This leg is not linked to a registration'); + } + + const donation = await prisma.payment.findUnique({ where: { id: leg.originalPaymentId } }); + if (!donation || !donation.isDonation) { + res.status(400); + throw new Error('The original donation for this leg could not be found'); + } + + await assertRegistrationEventOpen(leg.registrationId, res); + + const registration = await prisma.registration.findUnique({ + where: { id: leg.registrationId }, + include: { + registrationOptions: { include: { eventOption: { include: { earlyBirdTiers: true } } } }, + payments: true + } + }); + if (!registration) { + res.status(404); + throw new Error('Registration not found'); + } + + const originalStatus = registration.status; + const totalPaidExisting = registration.payments.reduce((sum, p) => sum + p.amount, 0); + const totalDue = computeRegistrationTotalDue(registration, new Date()); + const totalPaidAfter = totalPaidExisting - leg.amount; + const willDowngradeFromPaid = (originalStatus === 'paid') && (totalPaidAfter < totalDue); + + if (willDowngradeFromPaid) { + // Same guard createRefund uses: block if any ticket on the registration has been scanned. + const regTickets = await prisma.ticket.findMany({ + where: { registrationOption: { registrationId: leg.registrationId } }, + include: { usages: true } + }); + const hasUsed = regTickets.some(t => t.isUsed || (t.usages && t.usages.length > 0)); + if (hasUsed) { + res.status(400); + throw new Error('Cannot unassign this donation because a ticket has already been used'); + } + } + + await prisma.payment.delete({ where: { id: legId } }); + + // Recompute status the same way createRefund does after removing money from a registration. + const updatedRegistration = await prisma.registration.findUnique({ + where: { id: leg.registrationId }, + include: { + registrationOptions: { include: { eventOption: { include: { earlyBirdTiers: true } } } }, + payments: true + } + }); + let finalRegistration = updatedRegistration; + if (updatedRegistration) { + const totalPaid = updatedRegistration.payments.reduce((sum, p) => sum + p.amount, 0); + const totalDueNow = computeRegistrationTotalDue(updatedRegistration, new Date()); + let newStatus; + if (totalPaid >= totalDueNow) newStatus = 'paid'; + else if (totalPaid > 0) newStatus = 'partial_paid'; + else newStatus = 'pending'; + finalRegistration = await prisma.registration.update({ + where: { id: leg.registrationId }, + data: { status: newStatus, updatedAt: new Date() } + }); + + // Same blunt scope createRefund uses — tickets aren't tagged per-leg, so a downgrade + // clears every unused ticket on the registration, not just the ones this leg funded. + if (originalStatus === 'paid' && newStatus !== 'paid') { + await prisma.ticket.deleteMany({ + where: { + registrationOption: { registrationId: leg.registrationId }, + isUsed: false + } + }); + } + } + + // Fire-and-forget notification + const { sendDonationUnassignmentEmails } = require('../utils/notifications'); + const _udLeg = { id: leg.id, amount: leg.amount, createdAt: leg.createdAt, method: leg.method, externalId: leg.externalId, userId: leg.userId, registrationId: leg.registrationId }; + (async () => { + try { await sendDonationUnassignmentEmails(_udLeg); } + catch (e) { console.error('Failed to send emails after unassigning donation:', e); } + })(); + + return res.status(200).json({ + message: 'Donation unassigned', + updatedRegistration: finalRegistration, + donationId: donation.id + }); + } catch (error) { + res.status(res.statusCode === 200 ? 400 : res.statusCode).json({ message: safeErrorMessage(error) }); + } +}; + // Internal helper: create a Yoco checkout for a registration and return { checkoutId, redirectUrl, amount } // Does NOT check user authorization — callers are responsible for ensuring the user owns the registration. async function createRegistrationCheckoutInternal(registrationId, userId, { successUrl, cancelUrl, failureUrl } = {}) { @@ -1301,6 +1424,7 @@ module.exports = { getPaymentsByRegistration, getPaymentsByEvent, assignDonationToRegistration, + unassignDonationFromRegistration, createYocoCheckout, createRegistrationCheckoutInternal, sendPaymentLink, diff --git a/backend/src/routes/paymentRoutes.js b/backend/src/routes/paymentRoutes.js index 1774b47..67f761a 100644 --- a/backend/src/routes/paymentRoutes.js +++ b/backend/src/routes/paymentRoutes.js @@ -8,6 +8,7 @@ const { getPaymentsByRegistration, getPaymentsByEvent, assignDonationToRegistration, + unassignDonationFromRegistration, createYocoCheckout, sendPaymentLink, createRefund, @@ -27,6 +28,7 @@ router.get('/registration/:registrationId', protect, getPaymentsByRegistration); router.get('/', protect, supervisor, getPayments); router.get('/event/:eventId', protect, staff, getPaymentsByEvent); router.put('/assign-donation', protect, supervisor, assignDonationToRegistration); +router.post('/unassign-donation', protect, supervisor, unassignDonationFromRegistration); router.post('/refund', protect, supervisor, createRefund); router.get('/admin/stats', protect, admin, getPaymentStats); diff --git a/backend/src/utils/notifications.js b/backend/src/utils/notifications.js index 3776a90..84cf5ed 100644 --- a/backend/src/utils/notifications.js +++ b/backend/src/utils/notifications.js @@ -639,6 +639,83 @@ function buildPaymentAdminNotice(payment) { return { to, subject, text, html: emailWrapper(body) }; } +// ─── Donation unassignment ───────────────────────────────────────────────────── +// +// Sent when staff reverse a previous donation-assignment. Distinct from +// buildDonationAppliedToRegistrant: the leg payment no longer exists by the time this runs +// (it's hard-deleted before the notification fires), so callers pass a synthetic payment-shaped +// object — { amount, createdAt, registration } — built from the leg's captured values plus a +// freshly re-fetched registration so the balance table reflects the post-removal total. +// Kept anonymous (no donor name), same reasoning as the "applied" email. + +function buildDonationUnassignedFromRegistrant(payment) { + const org = getOrg(); + const reg = payment.registration; + const eventTitle = reg?.event?.title || 'the event'; + const totalDue = computeRegistrationTotalDue(reg, new Date()); + const totalPaid = (reg?.payments || []).reduce((s, p) => s + (p.amount || 0), 0); + const balance = Math.max(totalDue - totalPaid, 0); + const isUserActive = reg?.user?.isActive; + const subject = `A donation was removed from your registration – ${eventTitle}`; + const preheader = `A donation of ${fmtAmount(payment.amount)} was removed from your registration for ${eventTitle}.`; + + const body = ` +
A donation was removed from your registration
+Your balance has changed
+ +Hi ${reg?.user?.name || 'there'},
++ A donation of ${fmtAmount(payment.amount)} previously applied to your registration for ${eventTitle} has been removed by our team. +
+ + ${callout(`${fmtAmount(payment.amount)} removed| Total due | +${fmtAmount(totalDue)} | +
| Total paid | +${fmtAmount(totalPaid)} | +
| ${balance <= 0 ? 'Fully paid ✓' : 'Balance remaining'} | +${fmtAmount(balance)} | +