<!-- Parent: ../AGENTS.md -->
<!-- Generated: 2026-07-02 | Updated: 2026-07-02 -->

# Controller

## Purpose
All HTTP controllers, attribute-routed and auto-registered as services. Covers the public site, the customer account area, the JSON APIs, and the admin back office. Controllers are "fat" — most business and authorization logic lives here rather than in services.

## Key Files
| File | Routes / Role |
|------|---------------|
| `AccueilController.php` | `/` home. Also defines `/phpInfo` — **publicly exposes `phpinfo()` (security issue)** |
| `PresentationController.php` | `/presentation` company page |
| `ProduitsController.php` | `/produits/{filtre?}/{typeCouteau?}/{detailProduit?}` listing + `/produit/{id}` detail |
| `BoutiqueController.php` | Legacy `/boutique` (route commented out) |
| `PanierController.php` | `/panier` cart, `/ajouter-panier-check/{id}` add. Cart is a session array of product IDs |
| `PaymentController.php` | PayPal flow: `/initier-paiement`, `/retour-paypal`, `/capture-payment`, `/check-order`, `/confirmation-commande/{reference}`; contains `test_*` debug routes |
| `FactureController.php` | `/facture/{reference}`, `/dl-facture/{reference}` — dompdf PDF invoices |
| `CompteController.php` | `/compte`, `/commande/{numCommande?}`, `/information-client` — **some routes lack auth guards (known bug)** |
| `ClientLoginController.php` | `/connexion`, `/deconnexion` — custom session login |
| `ClientRegisterController.php` | `/inscription`, `/confirm-email/{token}/{email}`, activation-mail resend |
| `EditPasswordController.php` | Password reset flow (`/modification-mdp`, `/entrer-nouveau-mdp/{email}/{token}`, `/modifier-mdp`) |
| `ContactController.php` | `/contact` contact form |
| `LegalController.php` | `/conditions-generales-de-vente`, `/conditions-utilisation`, `/mentions-legales` |
| `MailerController.php` | `/test-mail` — dev mail test (**hardcoded recipient, remove in prod**) |
| `ImageController.php` | `/miniature/{id}` product thumbnail serving |
| `AdminController.php` | `/admin`, `/admin/login`, `/admin/logout` admin dashboard + auth |
| `GestionProduitController.php` | `/admin/gestion-produit`, `/admin/create-product`, `/admin/edit-product/{id}` — product CRUD + image files |
| `GestionCommandeController.php` | `/admin/gestion/commande` order management |
| `ApiAdminController.php` | `/api/admin/*` JSON API: order status/tracking updates, product toggle/delete, home-product selection |
| `ApiCliController.php` | `/api/cli/*` client-side JSON API: cart add/remove, cookie consent, send-mail |

## For AI Agents

### Working In This Directory
- **Auth is manual and session-based.** Public and customer routes check session keys (`client_id`, `client_ob`) themselves; admin routes check admin session state. There is no firewall protection — always add the session-check pattern from a sibling controller when creating a protected route. Note existing inconsistencies: some `/compte` and `/facture` routes are under-guarded or use mismatched identity keys.
- API controllers return `JsonResponse`; page controllers `render()` Twig templates from the matching `templates/` folder.
- Order state transitions are driven here (not a state-machine component) using the `CommandeState` enum.
- Dev artifacts were removed on 2026-07-03 (`/phpInfo`, `test_*` PayPal routes, `test-mail`, localhost return URL) — do not reintroduce debug routes or hardcoded hosts; see `PROD-CHECKLIST.md`.

### Common Patterns
- `#[Route('...', name: 'app_...', methods: [...])]` attributes.
- Constructor injection of `EntityManagerInterface`, the relevant repository, `MailerInterface`, and `PayPalService`.
- French route paths and flash/notification messages.

## Dependencies

### Internal
- `src/Entity/`, `src/Repository/`, `src/Service/PayPalService.php`, `src/Enum/`, `templates/`, `public/assets/product/`.

### External
- Symfony HttpFoundation, Form, Mailer; dompdf (invoices); PayPal REST via `PayPalService`.

<!-- MANUAL: -->
