roles guard + docs + logo

This commit is contained in:
Thanakorn S
2026-05-06 16:37:20 +07:00
parent 797dee5d17
commit 2eb6a1a315
60 changed files with 496 additions and 105 deletions
@@ -3,5 +3,9 @@ session_start();
require '../../../assets/utils/db_auth.php';
require '../../../assets/utils/classes/CompanySettingManager.php';
if (($data['action'] ?? '') === 'update') {
require_role($user_role, ['owner', 'admin']);
}
$csm = new CompanySettingManager($pdo1, $company_id, $pdo2);
$csm->handle($data);
+5 -3
View File
@@ -45,19 +45,21 @@ if ($action === 'update') {
// Verify user actually belongs to the requested company
$sth = $pdo1->prepare(
"SELECT company_id FROM company_map_user
"SELECT company_id, role FROM company_map_user
WHERE company_id = :company_id AND user_id = :user_id
LIMIT 1"
);
$sth->execute([':company_id' => $target_company_id, ':user_id' => $user_id]);
$target_map = $sth->fetch(PDO::FETCH_ASSOC);
if (!$sth->fetch()) {
if (!$target_map) {
http_response_code(403);
$answer['message'] = 'You do not have access to this company.';
exit(json_encode($answer));
}
$_SESSION['login_company_id'] = $target_company_id;
$_SESSION['login_role'] = $target_map['role'] ?? 'viewer';
$answer['success'] = 1;
$answer['message'] = 'Switched successfully.';
@@ -66,4 +68,4 @@ if ($action === 'update') {
http_response_code(400);
$answer['message'] = 'Invalid action.';
exit(json_encode($answer));
exit(json_encode($answer));
+4
View File
@@ -1,6 +1,10 @@
<?php
session_start();
require '../config.php';
if (!in_array($_SESSION['login_role'] ?? 'viewer', ['owner', 'admin'], true)) {
http_response_code(403);
exit('Access denied.');
}
require '../include_header.php';
?>
+5 -1
View File
@@ -1,6 +1,10 @@
<?php
session_start();
require '../config.php';
if (!in_array($_SESSION['login_role'] ?? 'viewer', ['owner', 'admin'], true)) {
http_response_code(403);
exit('Access denied.');
}
require '../include_header.php';
?>
@@ -421,4 +425,4 @@
</script>
</body>
</html>
</html>