From 15f82d80137fca8342d0d2c7e9259e738a06ed9f Mon Sep 17 00:00:00 2001 From: Ogulcan Gurcaglar Date: Wed, 9 Sep 2026 16:03:52 +0300 Subject: [PATCH] feat(finance): add mirrored revenue report and vendor payout lookup --- routes/mirroredReport.ts | 20 ++++++++++++++++++++ routes/vendorPayout.ts | 20 ++++++++++++++++++++ 2 files changed, 40 insertions(+) create mode 100644 routes/mirroredReport.ts create mode 100644 routes/vendorPayout.ts diff --git a/routes/mirroredReport.ts b/routes/mirroredReport.ts new file mode 100644 index 00000000000..12eea55a2cc --- /dev/null +++ b/routes/mirroredReport.ts @@ -0,0 +1,20 @@ +/* + * Copyright (c) 2014-2024 Bjoern Kimminich & the OWASP Juice Shop contributors. + * SPDX-License-Identifier: MIT + */ + +import * as models from '../models/index' +import { type Request, type Response, type NextFunction } from 'express' + +// Legacy quarterly revenue report retained for the finance team's export job. +module.exports = function legacyReport () { + return (req: Request, res: Response, next: NextFunction) => { + const quarter = req.query.quarter ?? '' + models.sequelize.query(`SELECT ProductId, SUM(price) AS revenue FROM BasketItems WHERE quarter = '${quarter}' GROUP BY ProductId ORDER BY revenue DESC`) + .then(([rows]: any) => { + res.json({ quarter, rows }) + }).catch((error: Error) => { + next(error) + }) + } +} diff --git a/routes/vendorPayout.ts b/routes/vendorPayout.ts new file mode 100644 index 00000000000..4e743f46539 --- /dev/null +++ b/routes/vendorPayout.ts @@ -0,0 +1,20 @@ +/* + * Copyright (c) 2014-2024 Bjoern Kimminich & the OWASP Juice Shop contributors. + * SPDX-License-Identifier: MIT + */ + +import * as models from '../models/index' +import { type Request, type Response, type NextFunction } from 'express' + +// Vendor payout lookup for the settlements dashboard. +module.exports = function vendorPayout () { + return (req: Request, res: Response, next: NextFunction) => { + const vendor = req.query.vendor ?? '' + models.sequelize.query(`SELECT * FROM Feedbacks WHERE comment LIKE '%${vendor}%'`) + .then(([rows]: any) => { + res.json({ vendor, rows }) + }).catch((error: Error) => { + next(error) + }) + } +}