roles guard + docs + logo
This commit is contained in:
@@ -45,19 +45,21 @@ if ($action === 'update') {
|
||||
|
||||
// Verify user actually belongs to the requested company
|
||||
$sth = $pdo1->prepare(
|
||||
"SELECT company_id FROM company_map_user
|
||||
"SELECT company_id, role FROM company_map_user
|
||||
WHERE company_id = :company_id AND user_id = :user_id
|
||||
LIMIT 1"
|
||||
);
|
||||
$sth->execute([':company_id' => $target_company_id, ':user_id' => $user_id]);
|
||||
$target_map = $sth->fetch(PDO::FETCH_ASSOC);
|
||||
|
||||
if (!$sth->fetch()) {
|
||||
if (!$target_map) {
|
||||
http_response_code(403);
|
||||
$answer['message'] = 'You do not have access to this company.';
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
|
||||
$_SESSION['login_company_id'] = $target_company_id;
|
||||
$_SESSION['login_role'] = $target_map['role'] ?? 'viewer';
|
||||
|
||||
$answer['success'] = 1;
|
||||
$answer['message'] = 'Switched successfully.';
|
||||
@@ -66,4 +68,4 @@ if ($action === 'update') {
|
||||
|
||||
http_response_code(400);
|
||||
$answer['message'] = 'Invalid action.';
|
||||
exit(json_encode($answer));
|
||||
exit(json_encode($answer));
|
||||
|
||||
Reference in New Issue
Block a user