roles guard + docs + logo

This commit is contained in:
Thanakorn S
2026-05-06 16:37:20 +07:00
parent 797dee5d17
commit 2eb6a1a315
60 changed files with 496 additions and 105 deletions
+12 -1
View File
@@ -88,4 +88,15 @@
justify-content: center;
z-index: 2;
border-radius: inherit;
}
}
.logo-area > a > img:first-child {
width: 40px;
height: 40px;
transition: width 0.2s ease, height 0.2s ease;
}
.sidebar.collapsed .logo-area > a > img:first-child {
width: 24px !important;
height: 24px !important;
}
Binary file not shown.

After

Width:  |  Height:  |  Size: 334 KiB

File diff suppressed because one or more lines are too long

Before

Width:  |  Height:  |  Size: 11 KiB

+23 -1
View File
@@ -785,4 +785,26 @@ function set_btn_state(selector, enabled, hint) {
.prop('disabled', true)
.attr('title', hint || '');
}
}
}
var ROLE_RANK = { viewer: 0, staff: 1, admin: 2, owner: 3 };
function apply_role_ui() {
var role = document.getElementById('session-context')?.dataset.role || 'viewer';
var rank = ROLE_RANK[role] ?? 0;
$('[data-min-role]').each(function() {
var required = ROLE_RANK[$(this).data('min-role')] ?? 99;
if (rank < required) $(this).hide();
});
}
$(function() {
apply_role_ui();
if (window.MutationObserver) {
var roleObserver = new MutationObserver(function() {
apply_role_ui();
});
roleObserver.observe(document.body, { childList: true, subtree: true });
}
});
+14 -1
View File
@@ -9,6 +9,15 @@ require_once __DIR__."/db_helpers.php";
// xhr.responseJSON from being populated automatically in ajax_request().
header('Content-Type: application/json; charset=utf-8');
if (!function_exists('require_role')) {
function require_role(string $user_role, array $allowed): void {
if (!in_array($user_role, $allowed, true)) {
http_response_code(403);
exit(json_encode(['success' => 0, 'message' => 'Access denied.']));
}
}
}
if(!empty($_SESSION["login_company_id"])){
// CSRF Validation — add right at the top of the logged-in block
@@ -63,6 +72,9 @@ if(!empty($_SESSION["login_company_id"])){
exit(json_encode($answer));
}
$user_role = $map[0]['role'] ?? 'viewer';
$_SESSION['login_role'] = $user_role;
}
// set up ANSWER
@@ -86,6 +98,7 @@ if(!empty($_SESSION["login_company_id"])){
$company_id = (int)$_SESSION["login_company_id"];
$user_id = (int)$_SESSION["login_user_id"];
$user_role = $_SESSION['login_role'] ?? ($user_role ?? 'viewer');
$uuid = bin2hex(random_bytes(16));
// create json for table logging
@@ -98,4 +111,4 @@ if(!empty($_SESSION["login_company_id"])){
}
?>
?>