roles guard + docs + logo
This commit is contained in:
@@ -88,4 +88,15 @@
|
||||
justify-content: center;
|
||||
z-index: 2;
|
||||
border-radius: inherit;
|
||||
}
|
||||
}
|
||||
|
||||
.logo-area > a > img:first-child {
|
||||
width: 40px;
|
||||
height: 40px;
|
||||
transition: width 0.2s ease, height 0.2s ease;
|
||||
}
|
||||
|
||||
.sidebar.collapsed .logo-area > a > img:first-child {
|
||||
width: 24px !important;
|
||||
height: 24px !important;
|
||||
}
|
||||
|
||||
Binary file not shown.
|
After Width: | Height: | Size: 334 KiB |
File diff suppressed because one or more lines are too long
|
Before Width: | Height: | Size: 11 KiB |
+23
-1
@@ -785,4 +785,26 @@ function set_btn_state(selector, enabled, hint) {
|
||||
.prop('disabled', true)
|
||||
.attr('title', hint || '');
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
var ROLE_RANK = { viewer: 0, staff: 1, admin: 2, owner: 3 };
|
||||
|
||||
function apply_role_ui() {
|
||||
var role = document.getElementById('session-context')?.dataset.role || 'viewer';
|
||||
var rank = ROLE_RANK[role] ?? 0;
|
||||
|
||||
$('[data-min-role]').each(function() {
|
||||
var required = ROLE_RANK[$(this).data('min-role')] ?? 99;
|
||||
if (rank < required) $(this).hide();
|
||||
});
|
||||
}
|
||||
|
||||
$(function() {
|
||||
apply_role_ui();
|
||||
if (window.MutationObserver) {
|
||||
var roleObserver = new MutationObserver(function() {
|
||||
apply_role_ui();
|
||||
});
|
||||
roleObserver.observe(document.body, { childList: true, subtree: true });
|
||||
}
|
||||
});
|
||||
|
||||
@@ -9,6 +9,15 @@ require_once __DIR__."/db_helpers.php";
|
||||
// xhr.responseJSON from being populated automatically in ajax_request().
|
||||
header('Content-Type: application/json; charset=utf-8');
|
||||
|
||||
if (!function_exists('require_role')) {
|
||||
function require_role(string $user_role, array $allowed): void {
|
||||
if (!in_array($user_role, $allowed, true)) {
|
||||
http_response_code(403);
|
||||
exit(json_encode(['success' => 0, 'message' => 'Access denied.']));
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
if(!empty($_SESSION["login_company_id"])){
|
||||
|
||||
// CSRF Validation — add right at the top of the logged-in block
|
||||
@@ -63,6 +72,9 @@ if(!empty($_SESSION["login_company_id"])){
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
|
||||
$user_role = $map[0]['role'] ?? 'viewer';
|
||||
$_SESSION['login_role'] = $user_role;
|
||||
|
||||
}
|
||||
|
||||
// set up ANSWER
|
||||
@@ -86,6 +98,7 @@ if(!empty($_SESSION["login_company_id"])){
|
||||
|
||||
$company_id = (int)$_SESSION["login_company_id"];
|
||||
$user_id = (int)$_SESSION["login_user_id"];
|
||||
$user_role = $_SESSION['login_role'] ?? ($user_role ?? 'viewer');
|
||||
$uuid = bin2hex(random_bytes(16));
|
||||
|
||||
// create json for table logging
|
||||
@@ -98,4 +111,4 @@ if(!empty($_SESSION["login_company_id"])){
|
||||
|
||||
}
|
||||
|
||||
?>
|
||||
?>
|
||||
|
||||
Reference in New Issue
Block a user