prepare( "SELECT status, payment_status, `log` FROM td_order WHERE company_id = :company_id AND id = :id" ); $sth->execute([':company_id' => $company_id, ':id' => $id]); $row = $sth->fetch(PDO::FETCH_ASSOC); if (!$row) throw new Exception("Order not found."); if ((int)$row['status'] === -1) throw new Exception("Cannot update payment status of a cancelled order."); $log = json_decode($row['log'] ?? '[]', true) ?: []; $log[] = array_merge($logging, [ 'action' => 'update_payment_status', 'payment_status' => $payment_status, 'previous_status' => (int)$row['payment_status'], ]); $pdo->prepare( "UPDATE td_order SET payment_status = :payment_status, `log` = :log WHERE id = :id AND company_id = :company_id" )->execute([ ':payment_status' => $payment_status, ':log' => json_encode($log), ':id' => $id, ':company_id' => $company_id, ]); }); $answer['success'] = 1; $answer['message'] = 'Payment status updated.'; } catch (PDOException $e) { $answer['message'] = 'Database error, please try again.'; http_response_code(500); } catch (Exception $e) { $answer['message'] = $e->getMessage(); http_response_code(400); } exit(json_encode($answer)); ?>