encapsulate setting api [OOP]

This commit is contained in:
Thanakorn S
2026-05-07 08:56:40 +07:00
parent 47cc2819d3
commit 0d2fa3e3bd
6 changed files with 314 additions and 303 deletions
+14 -181
View File
@@ -1,214 +1,47 @@
<?php
session_start();
require '../../../assets/utils/db_auth.php';
require '../../../assets/utils/classes/UserManager.php';
// ─── Role guard: only owner/admin can manage users ────────────────────────
$sth = $pdo1->prepare("
SELECT role FROM company_map_user
WHERE company_id = :company_id AND user_id = :user_id
LIMIT 1
");
$sth->execute([':company_id' => $company_id, ':user_id' => $user_id]);
db_check($sth, $answer);
$caller_role = $sth->fetchColumn();
if (!in_array($caller_role, ['owner', 'admin'], true)) {
$answer['message'] = 'You do not have permission to manage users.';
http_response_code(403);
exit(json_encode($answer));
}
require_role($user_role, ['owner', 'admin']);
$action = $data['action'] ?? '';
$um = new UserManager($pdo1, $company_id, $user_id);
try {
// ══════════════════════════════════════════════════════════════════════
// CREATE — invite a user by email
// ══════════════════════════════════════════════════════════════════════
if ($action === 'create') {
$email = strtolower(trim($data['invite_email'] ?? ''));
$role = trim($data['invite_role'] ?? '');
$invite_email = strtolower(trim($data['invite_email'] ?? ''));
$invite_role = trim($data['invite_role'] ?? '');
if (!filter_var($invite_email, FILTER_VALIDATE_EMAIL)) {
$answer['message'] = 'Invalid email address.';
http_response_code(422);
exit(json_encode($answer));
}
$allowed_roles = ['admin', 'staff', 'viewer'];
if (!in_array($invite_role, $allowed_roles, true)) {
$answer['message'] = 'Invalid role selected.';
http_response_code(422);
exit(json_encode($answer));
}
// Look up user by email
$sth = $pdo1->prepare("SELECT user_id, email FROM user WHERE email = :email LIMIT 1");
$sth->execute([':email' => $invite_email]);
db_check($sth, $answer);
$target = $sth->fetch(PDO::FETCH_ASSOC);
if (!$target) {
$answer['message'] = 'No registered account found with that email address.';
http_response_code(404);
exit(json_encode($answer));
}
$target_user_id = (int)$target['user_id'];
// Prevent inviting self
if ($target_user_id === (int)$user_id) {
$answer['message'] = 'You cannot invite yourself.';
http_response_code(422);
exit(json_encode($answer));
}
// Check if already mapped to this company
$sth = $pdo1->prepare("
SELECT map_id FROM company_map_user
WHERE company_id = :company_id AND user_id = :user_id
LIMIT 1
");
$sth->execute([':company_id' => $company_id, ':user_id' => $target_user_id]);
db_check($sth, $answer);
$existing = $sth->fetch(PDO::FETCH_ASSOC);
if ($existing) {
$answer['message'] = 'This user is already a member of your company.';
http_response_code(409);
exit(json_encode($answer));
}
$sth = $pdo1->prepare("
INSERT INTO company_map_user
(company_id, user_id, role, created_at)
VALUES
(:company_id, :user_id, :role, NOW())
");
$sth->execute([
':company_id' => $company_id,
':user_id' => $target_user_id,
':role' => $invite_role,
]);
db_check($sth, $answer);
$invited_email = $um->inviteUser($email, $role);
$answer['success'] = 1;
$answer['message'] = htmlspecialchars($target['email']) . ' has been added to your company.';
$answer['message'] = htmlspecialchars($invited_email) . ' has been added to your company.';
// ══════════════════════════════════════════════════════════════════════
// UPDATE — change a user's role
// ══════════════════════════════════════════════════════════════════════
} elseif ($action === 'update') {
$map_id = (int)($data['map_id'] ?? 0);
$role = trim($data['role'] ?? '');
$map_id = (int)($data['map_id'] ?? 0);
$new_role = trim($data['role'] ?? '');
$allowed_roles = ['admin', 'staff', 'viewer'];
if (!$map_id || !in_array($new_role, $allowed_roles, true)) {
$answer['message'] = 'Invalid request.';
http_response_code(422);
exit(json_encode($answer));
}
// Verify map belongs to this company and is not the owner
$sth = $pdo1->prepare("
SELECT role FROM company_map_user
WHERE map_id = :map_id AND company_id = :company_id
LIMIT 1
");
$sth->execute([':map_id' => $map_id, ':company_id' => $company_id]);
db_check($sth, $answer);
$target_role = $sth->fetchColumn();
if ($target_role === false) {
$answer['message'] = 'User not found.';
http_response_code(404);
exit(json_encode($answer));
}
if ($target_role === 'owner') {
$answer['message'] = 'Owner role cannot be changed.';
http_response_code(403);
exit(json_encode($answer));
}
$sth = $pdo1->prepare("
UPDATE company_map_user
SET role = :role
WHERE map_id = :map_id AND company_id = :company_id
");
$sth->execute([
':role' => $new_role,
':map_id' => $map_id,
':company_id' => $company_id,
]);
db_check($sth, $answer);
$um->updateRole($map_id, $role);
$answer['success'] = 1;
$answer['message'] = 'Role updated successfully.';
// ══════════════════════════════════════════════════════════════════════
// DELETE — remove user from company
// ══════════════════════════════════════════════════════════════════════
} elseif ($action === 'delete') {
$map_id = (int)($data['map_id'] ?? 0);
if (!$map_id) {
$answer['message'] = 'Invalid request.';
http_response_code(422);
exit(json_encode($answer));
}
// Verify map belongs to this company, and isn't the owner
$sth = $pdo1->prepare("
SELECT role, user_id FROM company_map_user
WHERE map_id = :map_id AND company_id = :company_id
LIMIT 1
");
$sth->execute([':map_id' => $map_id, ':company_id' => $company_id]);
db_check($sth, $answer);
$row = $sth->fetch(PDO::FETCH_ASSOC);
if (!$row) {
$answer['message'] = 'User not found.';
http_response_code(404);
exit(json_encode($answer));
}
if ($row['role'] === 'owner') {
$answer['message'] = 'The owner cannot be removed.';
http_response_code(403);
exit(json_encode($answer));
}
// Prevent removing yourself
if ((int)$row['user_id'] === (int)$user_id) {
$answer['message'] = 'You cannot remove yourself.';
http_response_code(403);
exit(json_encode($answer));
}
// Hard delete — just remove the row
$sth = $pdo1->prepare("
DELETE FROM company_map_user
WHERE map_id = :map_id AND company_id = :company_id
");
$sth->execute([':map_id' => $map_id, ':company_id' => $company_id]);
db_check($sth, $answer);
$um->removeUser($map_id);
$answer['success'] = 1;
$answer['message'] = 'User has been removed from this company.';
} else {
$answer['message'] = 'Unknown action.';
http_response_code(400);
}
} catch (Exception $e) {
$answer['message'] = 'An error occurred. Please try again.';
http_response_code(500);
$answer['message'] = $e->getMessage();
http_response_code(400);
}
exit(json_encode($answer));
?>
?>
+8 -24
View File
@@ -1,33 +1,17 @@
<?php
session_start();
require '../../../assets/utils/db_auth.php';
require '../../../assets/utils/classes/UserManager.php';
$um = new UserManager($pdo1, $company_id, $user_id);
try {
$sth = $pdo1->prepare(
"SELECT user_id, username, name, surname,
email, phone, country, address, profile_picture
FROM user
WHERE user_id = :user_id
LIMIT 1"
);
$sth->execute([':user_id' => $user_id]);
db_check($sth, $answer);
$user = $sth->fetch(PDO::FETCH_ASSOC);
if (!$user) {
$answer['message'] = 'User not found.';
http_response_code(404);
exit(json_encode($answer));
}
$answer['success'] = 1;
$answer['output'] = $user;
$answer['output'] = $um->getProfile();
} catch (Exception $e) {
$answer['message'] = 'Failed to load profile.';
http_response_code(500);
$answer['message'] = $e->getMessage();
http_response_code(404);
}
exit(json_encode($answer));
exit(json_encode($answer));
?>
+5 -32
View File
@@ -1,38 +1,11 @@
<?php
session_start();
require '../../../assets/utils/db_auth.php';
require '../../../assets/utils/classes/UserManager.php';
try {
// Fetch all users mapped to this company, joined with user profile
$sth = $pdo1->prepare("
SELECT
m.map_id,
m.role,
m.created_at,
u.user_id,
u.username,
u.name,
u.surname,
u.email,
u.profile_picture
FROM company_map_user m
JOIN user u ON u.user_id = m.user_id
WHERE m.company_id = :company_id
ORDER BY
FIELD(m.role, 'owner', 'admin', 'staff', 'viewer'),
u.name ASC
");
$sth->execute([':company_id' => $company_id]);
db_check($sth, $answer);
$answer['success'] = 1;
$answer['output'] = $sth->fetchAll(PDO::FETCH_ASSOC);
} catch (Exception $e) {
$answer['message'] = 'Failed to load users.';
http_response_code(500);
}
$um = new UserManager($pdo1, $company_id, $user_id);
$answer['success'] = 1;
$answer['output'] = $um->getCompanyUsers();
exit(json_encode($answer));
?>
?>
+6 -44
View File
@@ -1,50 +1,12 @@
<?php
session_start();
require '../../../assets/utils/db_auth.php';
require '../../../assets/utils/classes/UserManager.php';
try {
$keyword = trim($data['keyword'] ?? '');
if ($keyword === '') {
$answer['success'] = 1;
$answer['result'] = [];
exit(json_encode($answer));
}
$like = '%' . $keyword . '%';
// Search users by email NOT already active/pending in this company
$sth = $pdo1->prepare("
SELECT
u.user_id,
u.username,
u.name,
u.surname,
u.email
FROM user u
WHERE
u.email LIKE :kw
AND u.user_id NOT IN (
SELECT user_id FROM company_map_user
WHERE company_id = :company_id
)
ORDER BY u.email ASC
LIMIT 10
");
$sth->execute([
':kw' => $like,
':company_id' => $company_id,
]);
db_check($sth, $answer);
$answer['success'] = 1;
$answer['result'] = $sth->fetchAll(PDO::FETCH_ASSOC);
} catch (Exception $e) {
$answer['message'] = 'Search failed.';
http_response_code(500);
}
$keyword = trim($data['keyword'] ?? '');
$um = new UserManager($pdo1, $company_id, $user_id);
$answer['success'] = 1;
$answer['result'] = $um->searchUsers($keyword);
exit(json_encode($answer));
?>
?>
+8 -22
View File
@@ -4,46 +4,31 @@
*
* action: 'read' → return list of companies the user belongs to
* action: 'update' → switch to the requested company_id
*
* Both actions verify that the user is actually a member of the target company
* via company_map_user before touching the session.
*/
session_start();
require '../../../assets/utils/db_auth.php';
require '../../../assets/utils/classes/UserManager.php';
$action = $data['action'] ?? '';
// ── READ: return all companies this user belongs to ───────────────────────────
if ($action === 'read') {
$sth = $pdo1->prepare(
"SELECT cl.company_id, cl.channel_name, cl.company_name, cl.branch, cmu.role
FROM company_map_user cmu
JOIN company_list cl ON cl.company_id = cmu.company_id
WHERE cmu.user_id = :user_id
ORDER BY cl.company_name ASC"
);
$sth->execute([':user_id' => $user_id]);
$companies = $sth->fetchAll(PDO::FETCH_ASSOC);
$um = new UserManager($pdo1, $company_id, $user_id);
$answer['success'] = 1;
$answer['output'] = $companies;
$answer['current'] = (int) $_SESSION['login_company_id'];
$answer['output'] = $um->getCompanyList();
$answer['current'] = (int)$_SESSION['login_company_id'];
exit(json_encode($answer));
}
// ── UPDATE: switch to a different company ─────────────────────────────────────
if ($action === 'update') {
$target_company_id = (int)($data['company_id'] ?? 0);
if (!$target_company_id) {
http_response_code(400);
$answer['message'] = 'Invalid company.';
http_response_code(400);
exit(json_encode($answer));
}
// Verify user actually belongs to the requested company
$sth = $pdo1->prepare(
"SELECT company_id, role FROM company_map_user
WHERE company_id = :company_id AND user_id = :user_id
@@ -53,8 +38,8 @@ if ($action === 'update') {
$target_map = $sth->fetch(PDO::FETCH_ASSOC);
if (!$target_map) {
http_response_code(403);
$answer['message'] = 'You do not have access to this company.';
http_response_code(403);
exit(json_encode($answer));
}
@@ -66,6 +51,7 @@ if ($action === 'update') {
exit(json_encode($answer));
}
http_response_code(400);
$answer['message'] = 'Invalid action.';
http_response_code(400);
exit(json_encode($answer));
?>