Out-of-stock UI, variant picker on marketing pages, server-side stock check
- ProductGrid/AddToCartInlineButton/AddToCartButton now show "Ausverkauft" and disable add-to-cart per variant (or product-level with no variants), derived from trackInventory/stock/allowBackorder via isOutOfStock(). - AddToCartButton (todo-cards Hero+Pricing, homepage spotlight) gains the same variant <select> AddToCartInlineButton already had — all three call sites already fetch full product data server-side. - /api/checkout re-validates stock server-side (depth-in-defense, not just the disabled button), rejecting when trackInventory is on, allowBackorder is off, and requested qty exceeds stock. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018PL4zfTY1sXc8x5QS6FatM
This commit is contained in:
@@ -112,6 +112,18 @@ export async function POST(request: Request) {
|
||||
variant = product.variants?.find((v) => v.name === line.variant) ?? null;
|
||||
if (!variant) return NextResponse.json({ ok: false, reason: "Eine gewählte Variante ist nicht mehr verfügbar." }, { status: 400 });
|
||||
}
|
||||
// Same depth-in-defense reasoning as the price re-check above — the
|
||||
// storefront already disables "add to cart" for sold-out items, but a
|
||||
// tampered/stale request could still submit one, so stock is
|
||||
// re-validated here as the actual source of truth. Falls through
|
||||
// (buyable) whenever trackInventory is off or backorders are allowed.
|
||||
const stockSource = line.variant ? product.variants?.find((v) => v.name === line.variant) : product;
|
||||
if (stockSource?.trackInventory && !stockSource.allowBackorder && (stockSource.stock ?? 0) < line.qty) {
|
||||
return NextResponse.json(
|
||||
{ ok: false, reason: `"${product.name}"${line.variant ? ` (${line.variant})` : ""} ist nicht mehr in ausreichender Menge verfügbar.` },
|
||||
{ status: 400 },
|
||||
);
|
||||
}
|
||||
const imageUrl = typeof product.image === "object" && product.image ? product.image.url : null;
|
||||
items.push({
|
||||
productId: product.id,
|
||||
|
||||
Reference in New Issue
Block a user