roles guard + docs + logo
This commit is contained in:
@@ -9,6 +9,15 @@ require_once __DIR__."/db_helpers.php";
|
||||
// xhr.responseJSON from being populated automatically in ajax_request().
|
||||
header('Content-Type: application/json; charset=utf-8');
|
||||
|
||||
if (!function_exists('require_role')) {
|
||||
function require_role(string $user_role, array $allowed): void {
|
||||
if (!in_array($user_role, $allowed, true)) {
|
||||
http_response_code(403);
|
||||
exit(json_encode(['success' => 0, 'message' => 'Access denied.']));
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
if(!empty($_SESSION["login_company_id"])){
|
||||
|
||||
// CSRF Validation — add right at the top of the logged-in block
|
||||
@@ -63,6 +72,9 @@ if(!empty($_SESSION["login_company_id"])){
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
|
||||
$user_role = $map[0]['role'] ?? 'viewer';
|
||||
$_SESSION['login_role'] = $user_role;
|
||||
|
||||
}
|
||||
|
||||
// set up ANSWER
|
||||
@@ -86,6 +98,7 @@ if(!empty($_SESSION["login_company_id"])){
|
||||
|
||||
$company_id = (int)$_SESSION["login_company_id"];
|
||||
$user_id = (int)$_SESSION["login_user_id"];
|
||||
$user_role = $_SESSION['login_role'] ?? ($user_role ?? 'viewer');
|
||||
$uuid = bin2hex(random_bytes(16));
|
||||
|
||||
// create json for table logging
|
||||
@@ -98,4 +111,4 @@ if(!empty($_SESSION["login_company_id"])){
|
||||
|
||||
}
|
||||
|
||||
?>
|
||||
?>
|
||||
|
||||
Reference in New Issue
Block a user