Naming consistance and SESSION issue
This commit is contained in:
@@ -100,3 +100,17 @@
|
||||
width: 24px !important;
|
||||
height: 24px !important;
|
||||
}
|
||||
|
||||
@media (max-width: 991.98px) {
|
||||
#topbar {
|
||||
padding-right: 1.5rem !important;
|
||||
}
|
||||
|
||||
#topbar > div:last-child {
|
||||
margin-left: auto;
|
||||
}
|
||||
|
||||
#topbar .dropdown {
|
||||
margin-left: 0.5rem !important;
|
||||
}
|
||||
}
|
||||
|
||||
Binary file not shown.
|
Before Width: | Height: | Size: 334 KiB After Width: | Height: | Size: 813 KiB |
@@ -19,7 +19,7 @@ class CompanySettingManager
|
||||
{
|
||||
private PDO $pdo;
|
||||
private ?PDO $transactionPdo;
|
||||
private int $companyId;
|
||||
private int $company_id;
|
||||
|
||||
// ── Known keys with their defaults ───────────────────────────────────────
|
||||
private const DEFAULTS = [
|
||||
@@ -32,11 +32,11 @@ class CompanySettingManager
|
||||
'location_label_aisle' => 'Aisle', // advanced level 2 default
|
||||
];
|
||||
|
||||
public function __construct(PDO $pdo, int $companyId, ?PDO $transactionPdo = null)
|
||||
public function __construct(PDO $pdo, int $company_id, ?PDO $transactionPdo = null)
|
||||
{
|
||||
$this->pdo = $pdo;
|
||||
$this->transactionPdo = $transactionPdo;
|
||||
$this->companyId = $companyId;
|
||||
$this->companyId = $company_id;
|
||||
}
|
||||
|
||||
// ─────────────────────────────────────────────────────────────
|
||||
|
||||
@@ -18,10 +18,10 @@
|
||||
*/
|
||||
class ContactManager {
|
||||
|
||||
private $pdo;
|
||||
private $company_id;
|
||||
private PDO $pdo;
|
||||
private int $company_id;
|
||||
|
||||
public function __construct($pdo, $company_id) {
|
||||
public function __construct(PDO $pdo, int $company_id) {
|
||||
$this->pdo = $pdo;
|
||||
$this->company_id = $company_id;
|
||||
}
|
||||
|
||||
@@ -30,10 +30,10 @@
|
||||
*/
|
||||
class InvoiceManager {
|
||||
|
||||
private $pdo;
|
||||
private $company_id;
|
||||
private PDO $pdo;
|
||||
private int $company_id;
|
||||
|
||||
public function __construct($pdo, int $company_id) {
|
||||
public function __construct(PDO $pdo, int $company_id) {
|
||||
$this->pdo = $pdo;
|
||||
$this->company_id = $company_id;
|
||||
}
|
||||
|
||||
@@ -37,10 +37,10 @@
|
||||
*/
|
||||
class OrderManager {
|
||||
|
||||
private $pdo;
|
||||
private $company_id;
|
||||
private PDO $pdo;
|
||||
private int $company_id;
|
||||
|
||||
public function __construct($pdo, int $company_id) {
|
||||
public function __construct(PDO $pdo, int $company_id) {
|
||||
$this->pdo = $pdo;
|
||||
$this->company_id = $company_id;
|
||||
}
|
||||
|
||||
@@ -18,10 +18,10 @@
|
||||
*/
|
||||
class ProductManager {
|
||||
|
||||
private $pdo;
|
||||
private $company_id;
|
||||
private PDO $pdo;
|
||||
private int $company_id;
|
||||
|
||||
public function __construct($pdo, $company_id) {
|
||||
public function __construct(PDO $pdo, int $company_id) {
|
||||
$this->pdo = $pdo;
|
||||
$this->company_id = $company_id;
|
||||
}
|
||||
|
||||
@@ -30,10 +30,10 @@
|
||||
*/
|
||||
class PurchaseOrderManager {
|
||||
|
||||
private $pdo;
|
||||
private $company_id;
|
||||
private PDO $pdo;
|
||||
private int $company_id;
|
||||
|
||||
public function __construct($pdo, int $company_id) {
|
||||
public function __construct(PDO $pdo, int $company_id) {
|
||||
$this->pdo = $pdo;
|
||||
$this->company_id = $company_id;
|
||||
}
|
||||
|
||||
@@ -21,13 +21,13 @@
|
||||
class ReportManager
|
||||
{
|
||||
private PDO $pdo;
|
||||
private int $companyId;
|
||||
private int $company_id;
|
||||
private string $mainDb;
|
||||
|
||||
public function __construct(PDO $pdo, int $companyId, string $mainDb = '')
|
||||
public function __construct(PDO $pdo, int $company_id, string $mainDb = '')
|
||||
{
|
||||
$this->pdo = $pdo;
|
||||
$this->companyId = $companyId;
|
||||
$this->companyId = $company_id;
|
||||
$this->mainDb = $mainDb;
|
||||
}
|
||||
|
||||
|
||||
@@ -31,10 +31,10 @@
|
||||
*/
|
||||
class ReturnManager {
|
||||
|
||||
private $pdo;
|
||||
private $company_id;
|
||||
private PDO $pdo;
|
||||
private int $company_id;
|
||||
|
||||
public function __construct($pdo, int $company_id) {
|
||||
public function __construct(PDO $pdo, int $company_id) {
|
||||
$this->pdo = $pdo;
|
||||
$this->company_id = $company_id;
|
||||
}
|
||||
|
||||
@@ -23,10 +23,10 @@
|
||||
*/
|
||||
class StockManager {
|
||||
|
||||
private $pdo;
|
||||
private $company_id;
|
||||
private PDO $pdo;
|
||||
private int $company_id;
|
||||
|
||||
public function __construct($pdo, $company_id) {
|
||||
public function __construct(PDO $pdo, int $company_id) {
|
||||
$this->pdo = $pdo;
|
||||
$this->company_id = $company_id;
|
||||
}
|
||||
|
||||
@@ -21,10 +21,10 @@
|
||||
*/
|
||||
class WarehouseManager {
|
||||
|
||||
private $pdo;
|
||||
private $company_id;
|
||||
private PDO $pdo;
|
||||
private int $company_id;
|
||||
|
||||
public function __construct($pdo, $company_id, $logging = null) {
|
||||
public function __construct(PDO $pdo, int $company_id, $logging = null) {
|
||||
$this->pdo = $pdo;
|
||||
$this->company_id = $company_id;
|
||||
}
|
||||
|
||||
@@ -10,7 +10,7 @@
|
||||
|
||||
<body>
|
||||
<?php require '../include_topbar.php'; ?>
|
||||
<?php require '../include_master_sidebar.php'; ?>
|
||||
<?php require '../include_sidebar.php'; ?>
|
||||
|
||||
<main id="content" class="content py-15">
|
||||
<div class="container-fluid">
|
||||
|
||||
@@ -10,7 +10,7 @@
|
||||
|
||||
<body>
|
||||
<?php require '../include_topbar.php'; ?>
|
||||
<?php require '../include_master_sidebar.php'; ?>
|
||||
<?php require '../include_sidebar.php'; ?>
|
||||
|
||||
<main id="content" class="content py-15">
|
||||
<div class="container-fluid">
|
||||
|
||||
@@ -560,7 +560,7 @@
|
||||
onSuccess: function(res) {
|
||||
var opts = '<option value="0">— no invoice —</option>';
|
||||
$.each(res.output || [], function(i, inv) {
|
||||
opts += `<option value="${inv.id}">${inv.invoice_number}</option>`;
|
||||
opts += `<option value="${inv.id}">${escape_html(inv.invoice_number)}</option>`;
|
||||
});
|
||||
$('#invoice_id').html(opts);
|
||||
|
||||
|
||||
@@ -367,7 +367,7 @@
|
||||
onSuccess: function(res) {
|
||||
var opts = `<option value="">Select ${label_zone.toLowerCase()}...</option>`;
|
||||
(res.output || []).forEach(function(z) {
|
||||
opts += `<option value="${z.zone}">${z.zone}</option>`;
|
||||
opts += `<option value="${escape_html(z.zone)}">${escape_html(z.zone)}</option>`;
|
||||
});
|
||||
$(`#recv_zone_${rowId}`).html(opts);
|
||||
$(`#recv_aisle_${rowId}`).html(`<option value="">Select ${label_aisle.toLowerCase()}...</option>`);
|
||||
@@ -389,7 +389,7 @@
|
||||
onSuccess: function(res) {
|
||||
var opts = `<option value="">Select ${label_aisle.toLowerCase()}...</option>`;
|
||||
(res.output || []).forEach(function(a) {
|
||||
opts += `<option value="${a}">${a}</option>`;
|
||||
opts += `<option value="${escape_html(a)}">${escape_html(a)}</option>`;
|
||||
});
|
||||
$(`#recv_aisle_${rowId}`).html(opts);
|
||||
$(`#recv_rack_${rowId}`).html(`<option value="">Select ${label_rack.toLowerCase()}...</option>`);
|
||||
@@ -411,7 +411,7 @@
|
||||
onSuccess: function(res) {
|
||||
var opts = `<option value="">Select ${label_rack.toLowerCase()}...</option>`;
|
||||
(res.output || []).forEach(function(r) {
|
||||
opts += `<option value="${r}">${r}</option>`;
|
||||
opts += `<option value="${escape_html(r)}">${escape_html(r)}</option>`;
|
||||
});
|
||||
$(`#recv_rack_${rowId}`).html(opts);
|
||||
if (callback) callback();
|
||||
@@ -909,7 +909,7 @@
|
||||
warehouses = res.output || [];
|
||||
var opts = '<option value="">Select warehouse...</option>';
|
||||
warehouses.forEach(function(w) {
|
||||
opts += `<option value="${w.id}">${w.warehouse_name}</option>`;
|
||||
opts += `<option value="${w.id}">${escape_html(w.warehouse_name)}</option>`;
|
||||
});
|
||||
$('#warehouse_id').html(opts);
|
||||
}
|
||||
|
||||
+15
-3
@@ -1,13 +1,25 @@
|
||||
<?php
|
||||
// app/session.php
|
||||
if (session_status() === PHP_SESSION_NONE) {
|
||||
// Reject client-supplied session IDs — prevents session fixation.
|
||||
|
||||
// Derive cookie path dynamically from the current script location.
|
||||
// e.g. /tr3wms/app/login/api/engine/login_otp.php → /tr3wms/
|
||||
// This relies on the app always living one level under the repo root:
|
||||
// DOCUMENT_ROOT/
|
||||
// tr3wms/ ← repo root (cookie path)
|
||||
// app/
|
||||
// session.php ← this file is always inside app/
|
||||
$parts = explode('/', trim($_SERVER['SCRIPT_NAME'], '/'));
|
||||
$repo_name = '/' . $parts[0] . '/'; // e.g. /tr3wms/
|
||||
|
||||
ini_set('session.use_strict_mode', 1);
|
||||
// Server-side session file lifetime: 1 hour.
|
||||
ini_set('session.gc_maxlifetime', 3600);
|
||||
ini_set('session.cookie_path', $repo_name);
|
||||
ini_set('session.cookie_httponly', 1);
|
||||
ini_set('session.cookie_samesite', 'Lax');
|
||||
session_set_cookie_params([
|
||||
'lifetime' => 0,
|
||||
'path' => '/wms/',
|
||||
'path' => $repo_name,
|
||||
'domain' => '',
|
||||
'secure' => isset($_SERVER['HTTPS']) && $_SERVER['HTTPS'] === 'on',
|
||||
'httponly' => true,
|
||||
|
||||
Reference in New Issue
Block a user