Merge fix/api-json-notices
This commit is contained in:
@@ -99,7 +99,7 @@ class CompanyProfileManager
|
||||
|
||||
public function saveProfile(array $data, string $company_logo, string $company_seal): void
|
||||
{
|
||||
$channel = strtolower(preg_replace('/[^a-z0-9\-_]/', '', $data['channel_name'] ?? ''));
|
||||
$channel = preg_replace('/[^a-z0-9\-_]/', '', strtolower(trim($data['channel_name'] ?? '')));
|
||||
|
||||
$sth = $this->pdo->prepare(
|
||||
"UPDATE company_list SET
|
||||
|
||||
@@ -27,6 +27,11 @@ class db_statement extends PDOStatement {
|
||||
$this->pdo = $pdo;
|
||||
}
|
||||
|
||||
// PDOStatement::execute() is declared ?array $params = null : bool. This
|
||||
// override deliberately accepts a looser signature so callers may pass
|
||||
// positional arguments (see func_get_args() below), so the tightened return
|
||||
// type is opted out of rather than the call sites being changed.
|
||||
#[\ReturnTypeWillChange]
|
||||
public function execute($args = null) {
|
||||
// Perform logging here. PDO object is accessible
|
||||
// from $this->pdo.
|
||||
|
||||
@@ -1,4 +1,23 @@
|
||||
<?php
|
||||
// Output buffering must be active before the first byte of HTML below, so that
|
||||
// header() calls made later in the page still work — notably the
|
||||
// not-logged-in redirect in include_topbar.php, which runs *after* this file
|
||||
// has already emitted <!DOCTYPE html>. Without a buffer that redirect depends
|
||||
// entirely on php.ini's output_buffering: it is on for the dev stack but off
|
||||
// in production, where every protected page answered 200 with a half-rendered
|
||||
// body instead of sending the browser to the login form. session.php starts a
|
||||
// buffer for the same reason.
|
||||
if (ob_get_level() === 0) {
|
||||
ob_start();
|
||||
}
|
||||
|
||||
// Never render PHP notices/warnings into the page: they leak absolute server
|
||||
// paths to anonymous visitors and corrupt the markup. Errors still reach the
|
||||
// server log. This mirrors the policy db_auth.php already applies to the JSON
|
||||
// API routes, and keeps the app safe even where php.ini has display_errors on.
|
||||
ini_set('display_errors', '0');
|
||||
ini_set('log_errors', '1');
|
||||
|
||||
// Security headers — emitted before any HTML output.
|
||||
header('X-Content-Type-Options: nosniff');
|
||||
header('X-Frame-Options: SAMEORIGIN');
|
||||
|
||||
@@ -8,6 +8,11 @@ require_once __DIR__ . '/assets/utils/classes/UsageGuard.php';
|
||||
// login_company_id is only written by login_confirm.php after OTP is verified —
|
||||
// using it (not "otp") ensures half-logged-in sessions are also redirected.
|
||||
if(empty($_SESSION["login_company_id"])){
|
||||
// Discard the markup include_header.php has already buffered so the browser
|
||||
// receives a clean redirect rather than a partially rendered page body.
|
||||
while (ob_get_level() > 0) {
|
||||
ob_end_clean();
|
||||
}
|
||||
header('Location: '.$server_url.'login/index.php');
|
||||
exit;
|
||||
}
|
||||
|
||||
@@ -97,9 +97,9 @@ try {
|
||||
$company_name = trim($data['company_name'] ?? '');
|
||||
$company_name2 = trim($data['company_name2'] ?? '');
|
||||
|
||||
// channel_name is the URL slug / identifier — strip everything except
|
||||
// lowercase letters, digits, hyphens, and underscores.
|
||||
$channel_name = strtolower(preg_replace('/[^a-z0-9\-_]/', '', $data['channel_name'] ?? ''));
|
||||
// channel_name is the URL slug / identifier — lowercase first, then strip
|
||||
// everything except lowercase letters, digits, hyphens, and underscores.
|
||||
$channel_name = preg_replace('/[^a-z0-9\-_]/', '', strtolower(trim($data['channel_name'] ?? '')));
|
||||
|
||||
$branch = trim($data['branch'] ?? 'สำนักงานใหญ่');
|
||||
$branch_no = trim($data['branch_no'] ?? '00000');
|
||||
|
||||
@@ -48,7 +48,8 @@
|
||||
</div>
|
||||
<div class="col-md-6">
|
||||
<label class="form-label">Channel Name <span class="text-danger">*</span></label>
|
||||
<input type="text" class="form-control" id="channel_name" placeholder="e.g. my-shop">
|
||||
<input type="text" class="form-control" id="channel_name" placeholder="e.g. my-shop"
|
||||
oninput="this.value=this.value.toLowerCase().replace(/[^a-z0-9_-]/g,'')">
|
||||
<div class="form-text">Unique identifier. Lowercase, no spaces.</div>
|
||||
</div>
|
||||
<div class="col-md-3">
|
||||
|
||||
@@ -2,6 +2,12 @@
|
||||
// app/session.php
|
||||
ob_start(); // ensure output buffering is on regardless of php.ini — prevents stray output from corrupting JSON API responses
|
||||
|
||||
// The buffer is still flushed, so notices would still land in front of the JSON
|
||||
// body and break the client's parse ("Server error occurred."). The login API
|
||||
// engines load this file instead of db_auth.php, so apply the same policy here.
|
||||
ini_set('display_errors', '0');
|
||||
ini_set('log_errors', '1');
|
||||
|
||||
if (session_status() === PHP_SESSION_NONE) {
|
||||
|
||||
// Derive cookie path dynamically from the current script location.
|
||||
|
||||
@@ -121,7 +121,8 @@
|
||||
|
||||
<div class="col-md-6 mb-3">
|
||||
<label class="form-label">Nickname / Channel Name</label>
|
||||
<input type="text" class="form-control" id="channel_name" placeholder="e.g. my-shop">
|
||||
<input type="text" class="form-control" id="channel_name" placeholder="e.g. my-shop"
|
||||
oninput="this.value=this.value.toLowerCase().replace(/[^a-z0-9_-]/g,'')">
|
||||
<div class="form-text">Unique identifier. Lowercase, no spaces.</div>
|
||||
</div>
|
||||
<div class="col-md-3 mb-3">
|
||||
|
||||
Reference in New Issue
Block a user