1) user invitation 2) app access control 3) txn quota guard
This commit is contained in:
@@ -820,6 +820,20 @@ function ajax_request(options) {
|
||||
throw xhr;
|
||||
}
|
||||
|
||||
// Usage limit reached — show upgrade notice instead of generic error
|
||||
if (xhr?.status === 402) {
|
||||
const d = xhr?.responseJSON ?? {};
|
||||
const daily = d.daily_limit > 0 ? `Daily: <strong>${d.daily_count} / ${d.daily_limit}</strong>` : null;
|
||||
const weekly = d.weekly_limit > 0 ? `Weekly: <strong>${d.weekly_count} / ${d.weekly_limit}</strong>` : null;
|
||||
const detail = [daily, weekly].filter(Boolean).join(' | ');
|
||||
bootbox.alert(
|
||||
`<strong>Usage limit reached.</strong><br>${detail}<br><br>` +
|
||||
`Reports are locked until the quota resets. Upgrade your package for higher limits.`
|
||||
);
|
||||
options.onError?.(xhr, 'limit_reached');
|
||||
throw xhr;
|
||||
}
|
||||
|
||||
// Extract server's error message from JSON response
|
||||
let serverMessage = xhr?.responseJSON?.message;
|
||||
|
||||
|
||||
@@ -148,7 +148,17 @@ class ContactManager {
|
||||
*/
|
||||
public function saveContactType(array $data, array $logging): void
|
||||
{
|
||||
$id = (int)($data['id'] ?? 0);
|
||||
$id = (int)($data['id'] ?? 0);
|
||||
$name = (string)($data['contact_type'] ?? '');
|
||||
|
||||
$dupSth = $this->pdo->prepare(
|
||||
"SELECT id FROM md_contact_type
|
||||
WHERE company_id = :cid AND contact_type = :name" . ($id > 0 ? " AND id != :id" : "") . " LIMIT 1"
|
||||
);
|
||||
$dupParams = [':cid' => $this->company_id, ':name' => $name];
|
||||
if ($id > 0) $dupParams[':id'] = $id;
|
||||
$dupSth->execute($dupParams);
|
||||
if ($dupSth->fetchColumn()) throw new Exception("A contact type with this name already exists.");
|
||||
|
||||
$sth = $this->pdo->prepare(
|
||||
"SELECT `log` FROM md_contact_type
|
||||
|
||||
@@ -154,7 +154,17 @@ class ProductManager {
|
||||
*/
|
||||
public function saveCategory(array $data, array $logging): void
|
||||
{
|
||||
$id = (int)($data['id'] ?? 0);
|
||||
$id = (int)($data['id'] ?? 0);
|
||||
$slug = (string)($data['slug'] ?? '');
|
||||
|
||||
$dupSth = $this->pdo->prepare(
|
||||
"SELECT id FROM md_product_category
|
||||
WHERE company_id = :cid AND slug = :slug" . ($id > 0 ? " AND id != :id" : "") . " LIMIT 1"
|
||||
);
|
||||
$dupParams = [':cid' => $this->company_id, ':slug' => $slug];
|
||||
if ($id > 0) $dupParams[':id'] = $id;
|
||||
$dupSth->execute($dupParams);
|
||||
if ($dupSth->fetchColumn()) throw new Exception("A category with this slug already exists.");
|
||||
|
||||
$sth = $this->pdo->prepare(
|
||||
"SELECT `log` FROM md_product_category
|
||||
@@ -355,7 +365,17 @@ class ProductManager {
|
||||
*/
|
||||
public function saveProduct(array $data, array $logging, string $product_image): void
|
||||
{
|
||||
$id = (int)($data['id'] ?? 0);
|
||||
$id = (int)($data['id'] ?? 0);
|
||||
$sku = (string)($data['sku'] ?? '');
|
||||
|
||||
$dupSth = $this->pdo->prepare(
|
||||
"SELECT id FROM md_product
|
||||
WHERE company_id = :cid AND sku = :sku" . ($id > 0 ? " AND id != :id" : "") . " LIMIT 1"
|
||||
);
|
||||
$dupParams = [':cid' => $this->company_id, ':sku' => $sku];
|
||||
if ($id > 0) $dupParams[':id'] = $id;
|
||||
$dupSth->execute($dupParams);
|
||||
if ($dupSth->fetchColumn()) throw new Exception("A product with this SKU already exists.");
|
||||
|
||||
$sth = $this->pdo->prepare(
|
||||
"SELECT `log` FROM md_product
|
||||
|
||||
@@ -0,0 +1,99 @@
|
||||
<?php
|
||||
|
||||
class UsageGuard {
|
||||
|
||||
private PDO $pdo;
|
||||
private int $company_id;
|
||||
private array $pkg;
|
||||
|
||||
public function __construct(PDO $pdo1, int $company_id, array $packages) {
|
||||
$this->pdo = $pdo1;
|
||||
$this->company_id = $company_id;
|
||||
$this->pkg = $this->resolvePackage($packages);
|
||||
}
|
||||
|
||||
private function resolvePackage(array $packages): array {
|
||||
$sth = $this->pdo->prepare(
|
||||
"SELECT package FROM company_list WHERE company_id = :cid LIMIT 1"
|
||||
);
|
||||
$sth->execute([':cid' => $this->company_id]);
|
||||
$name = $sth->fetchColumn() ?: 'starter';
|
||||
return $packages[$name] ?? $packages['starter'] ?? [
|
||||
'daily_limit' => 30,
|
||||
'weekly_limit' => 100,
|
||||
'lock_on_limit' => ['dashboard'],
|
||||
];
|
||||
}
|
||||
|
||||
public function increment(): void {
|
||||
$today = date('Y-m-d');
|
||||
$this->pdo->prepare(
|
||||
"INSERT INTO company_usage (company_id, day_date, daily_count)
|
||||
VALUES (:cid, :today, 1)
|
||||
ON DUPLICATE KEY UPDATE daily_count = daily_count + 1"
|
||||
)->execute([':cid' => $this->company_id, ':today' => $today]);
|
||||
}
|
||||
|
||||
public function assertFeatureAccessible(string $feature): void {
|
||||
$lock_on = $this->pkg['lock_on_limit'] ?? [];
|
||||
if (!in_array($feature, $lock_on, true)) {
|
||||
return;
|
||||
}
|
||||
|
||||
$status = $this->getStatus();
|
||||
$daily_limit = (int)($this->pkg['daily_limit'] ?? 0);
|
||||
$weekly_limit = (int)($this->pkg['weekly_limit'] ?? 0);
|
||||
|
||||
$over_daily = $daily_limit > 0 && $status['daily_count'] >= $daily_limit;
|
||||
$over_weekly = $weekly_limit > 0 && $status['weekly_count'] >= $weekly_limit;
|
||||
|
||||
if ($over_daily || $over_weekly) {
|
||||
http_response_code(402);
|
||||
exit(json_encode([
|
||||
'success' => 0,
|
||||
'message' => 'Usage limit reached. Upgrade your package to access reports.',
|
||||
'limit_reached' => true,
|
||||
'daily_count' => $status['daily_count'],
|
||||
'daily_limit' => $status['daily_limit'],
|
||||
'weekly_count' => $status['weekly_count'],
|
||||
'weekly_limit' => $status['weekly_limit'],
|
||||
]));
|
||||
}
|
||||
}
|
||||
|
||||
public function getStatus(): array {
|
||||
$today = date('Y-m-d');
|
||||
$day_of_week = (int)date('N');
|
||||
$week_start = date('Y-m-d', strtotime('-' . ($day_of_week - 1) . ' days'));
|
||||
|
||||
$sth = $this->pdo->prepare(
|
||||
"SELECT daily_count FROM company_usage
|
||||
WHERE company_id = :cid AND day_date = :today LIMIT 1"
|
||||
);
|
||||
$sth->execute([':cid' => $this->company_id, ':today' => $today]);
|
||||
$daily_count = (int)($sth->fetchColumn() ?: 0);
|
||||
|
||||
$sth = $this->pdo->prepare(
|
||||
"SELECT COALESCE(SUM(daily_count), 0) FROM company_usage
|
||||
WHERE company_id = :cid AND day_date BETWEEN :wstart AND :today"
|
||||
);
|
||||
$sth->execute([
|
||||
':cid' => $this->company_id,
|
||||
':wstart'=> $week_start,
|
||||
':today' => $today,
|
||||
]);
|
||||
$weekly_count = (int)$sth->fetchColumn();
|
||||
|
||||
$daily_limit = (int)($this->pkg['daily_limit'] ?? 0);
|
||||
$weekly_limit = (int)($this->pkg['weekly_limit'] ?? 0);
|
||||
|
||||
return [
|
||||
'daily_count' => $daily_count,
|
||||
'weekly_count' => $weekly_count,
|
||||
'daily_limit' => $daily_limit,
|
||||
'weekly_limit' => $weekly_limit,
|
||||
'daily_pct' => $daily_limit > 0 ? min(100, (int)round($daily_count / $daily_limit * 100)) : 0,
|
||||
'weekly_pct' => $weekly_limit > 0 ? min(100, (int)round($weekly_count / $weekly_limit * 100)) : 0,
|
||||
];
|
||||
}
|
||||
}
|
||||
@@ -118,9 +118,10 @@ class UserManager {
|
||||
public function getCompanyAccess(int $company_id): ?array
|
||||
{
|
||||
$sth = $this->pdo->prepare(
|
||||
"SELECT company_id, role
|
||||
FROM company_map_user
|
||||
WHERE company_id = :company_id AND user_id = :user_id
|
||||
"SELECT m.company_id, m.role, m.app_access, u.license, u.app_access AS user_app_access
|
||||
FROM company_map_user m
|
||||
JOIN user u ON u.user_id = m.user_id
|
||||
WHERE m.company_id = :company_id AND m.user_id = :user_id
|
||||
LIMIT 1"
|
||||
);
|
||||
$sth->execute([':company_id' => $company_id, ':user_id' => $this->user_id]);
|
||||
@@ -146,13 +147,16 @@ class UserManager {
|
||||
"SELECT
|
||||
m.map_id,
|
||||
m.role,
|
||||
CASE WHEN u.license = 'owner' THEN u.app_access ELSE m.app_access END AS app_access,
|
||||
m.created_at,
|
||||
u.user_id,
|
||||
u.username,
|
||||
u.name,
|
||||
u.surname,
|
||||
u.email,
|
||||
u.profile_picture
|
||||
u.profile_picture,
|
||||
u.status,
|
||||
(m.invite_token IS NOT NULL) AS is_pending_invite
|
||||
FROM company_map_user m
|
||||
JOIN user u ON u.user_id = m.user_id
|
||||
WHERE m.company_id = :company_id
|
||||
@@ -194,17 +198,18 @@ class UserManager {
|
||||
}
|
||||
|
||||
/**
|
||||
* Add a registered user to the current company by email.
|
||||
* Add a user to the current company by email.
|
||||
*
|
||||
* Validates email format, role, and that the target account exists.
|
||||
* Blocks inviting self or someone already mapped to the company.
|
||||
* If the email is already registered: maps them to this company directly.
|
||||
* If the email is not registered: creates a pending account (license='user',
|
||||
* default_company = this company) and returns an invite token so the caller
|
||||
* can email them a link to invited_onboarding.php to complete registration.
|
||||
* The invited user inherits this company's SMTP for OTP login.
|
||||
*
|
||||
* @param string $email Email address of the user to invite.
|
||||
* @param string $role Role to assign: 'admin', 'staff', or 'viewer'.
|
||||
* @return string The invited user's email, for use in the success message.
|
||||
* @return array ['new_user' => bool, 'email' => string, 'token' => string|null]
|
||||
* @throws Exception On any validation or constraint failure.
|
||||
*/
|
||||
public function inviteUser(string $email, string $role): string {
|
||||
public function inviteUser(string $email, string $role, string $app_access): array {
|
||||
if (!filter_var($email, FILTER_VALIDATE_EMAIL)) {
|
||||
throw new Exception('Invalid email address.');
|
||||
}
|
||||
@@ -220,36 +225,114 @@ class UserManager {
|
||||
$sth->execute([':email' => $email]);
|
||||
$target = $sth->fetch(PDO::FETCH_ASSOC);
|
||||
|
||||
if (!$target) {
|
||||
throw new Exception('No registered account found with that email address.');
|
||||
if ($target) {
|
||||
$target_user_id = (int)$target['user_id'];
|
||||
|
||||
if ($target_user_id === $this->user_id) {
|
||||
throw new Exception('You cannot invite yourself.');
|
||||
}
|
||||
|
||||
$sth = $this->pdo->prepare(
|
||||
"SELECT map_id FROM company_map_user
|
||||
WHERE company_id = :company_id AND user_id = :user_id
|
||||
LIMIT 1"
|
||||
);
|
||||
$sth->execute([':company_id' => $this->company_id, ':user_id' => $target_user_id]);
|
||||
if ($sth->fetch()) {
|
||||
throw new Exception('This user is already a member of your company.');
|
||||
}
|
||||
|
||||
$this->pdo->prepare(
|
||||
"INSERT INTO company_map_user (company_id, user_id, role, app_access, created_at)
|
||||
VALUES (:company_id, :user_id, :role, :app_access, NOW())"
|
||||
)->execute([
|
||||
':company_id' => $this->company_id,
|
||||
':user_id' => $target_user_id,
|
||||
':role' => $role,
|
||||
':app_access' => $app_access,
|
||||
]);
|
||||
|
||||
return ['new_user' => false, 'email' => $target['email'], 'token' => null];
|
||||
}
|
||||
|
||||
$target_user_id = (int)$target['user_id'];
|
||||
|
||||
if ($target_user_id === $this->user_id) {
|
||||
throw new Exception('You cannot invite yourself.');
|
||||
}
|
||||
|
||||
$sth = $this->pdo->prepare(
|
||||
"SELECT map_id FROM company_map_user
|
||||
WHERE company_id = :company_id AND user_id = :user_id
|
||||
LIMIT 1"
|
||||
);
|
||||
$sth->execute([':company_id' => $this->company_id, ':user_id' => $target_user_id]);
|
||||
if ($sth->fetch()) {
|
||||
throw new Exception('This user is already a member of your company.');
|
||||
}
|
||||
// Email not in system — create a pending invited account
|
||||
$invite_token = bin2hex(random_bytes(32));
|
||||
$expires_at = date('Y-m-d H:i:s', strtotime('+7 days'));
|
||||
$temp_username = 'invited_' . bin2hex(random_bytes(8));
|
||||
|
||||
$this->pdo->prepare(
|
||||
"INSERT INTO company_map_user (company_id, user_id, role, created_at)
|
||||
VALUES (:company_id, :user_id, :role, NOW())"
|
||||
"INSERT INTO user
|
||||
(username, name, surname, email, password, status, license, default_company,
|
||||
profile_picture, verify_token, verify_expires_at)
|
||||
VALUES
|
||||
(:username, '', '', :email, '', 'pending', 'user', :default_company,
|
||||
'', :token, :expires)"
|
||||
)->execute([
|
||||
':username' => $temp_username,
|
||||
':email' => $email,
|
||||
':default_company' => $this->company_id,
|
||||
':token' => $invite_token,
|
||||
':expires' => $expires_at,
|
||||
]);
|
||||
$new_user_id = (int)$this->pdo->lastInsertId();
|
||||
|
||||
$this->pdo->prepare(
|
||||
"INSERT INTO company_map_user (company_id, user_id, role, app_access, invite_token, created_at)
|
||||
VALUES (:company_id, :user_id, :role, :app_access, :token, NOW())"
|
||||
)->execute([
|
||||
':company_id' => $this->company_id,
|
||||
':user_id' => $target_user_id,
|
||||
':user_id' => $new_user_id,
|
||||
':role' => $role,
|
||||
':app_access' => $app_access,
|
||||
':token' => $invite_token,
|
||||
]);
|
||||
|
||||
return $target['email'];
|
||||
return ['new_user' => true, 'email' => $email, 'token' => $invite_token];
|
||||
}
|
||||
|
||||
/**
|
||||
* Regenerate an invite token for a pending invited user and return it.
|
||||
*
|
||||
* Only works on license='user' + status='pending' accounts that still have
|
||||
* an invite_token in company_map_user. Owner-pending accounts (mid-onboarding)
|
||||
* are never touched.
|
||||
*
|
||||
* @param int $map_id The company_map_user.map_id of the pending member.
|
||||
* @return array ['email' => string, 'token' => string]
|
||||
* @throws Exception If the member is not found or is not a pending invite.
|
||||
*/
|
||||
public function resendInvite(int $map_id): array {
|
||||
if (!$map_id) throw new Exception('Invalid request.');
|
||||
|
||||
$sth = $this->pdo->prepare(
|
||||
"SELECT u.user_id, u.email, u.status, u.license, m.invite_token
|
||||
FROM company_map_user m
|
||||
JOIN user u ON u.user_id = m.user_id
|
||||
WHERE m.map_id = :map_id AND m.company_id = :company_id
|
||||
LIMIT 1"
|
||||
);
|
||||
$sth->execute([':map_id' => $map_id, ':company_id' => $this->company_id]);
|
||||
$row = $sth->fetch(PDO::FETCH_ASSOC);
|
||||
|
||||
if (!$row) throw new Exception('User not found.');
|
||||
if ($row['license'] !== 'user') throw new Exception('Cannot resend invite to an owner account.');
|
||||
if ($row['status'] !== 'pending') throw new Exception('User has already accepted the invitation.');
|
||||
if (!$row['invite_token']) throw new Exception('No pending invitation found for this user.');
|
||||
|
||||
$new_token = bin2hex(random_bytes(32));
|
||||
$expires_at = date('Y-m-d H:i:s', strtotime('+7 days'));
|
||||
|
||||
$this->pdo->prepare(
|
||||
"UPDATE user SET verify_token = :token, verify_expires_at = :expires
|
||||
WHERE user_id = :uid"
|
||||
)->execute([':token' => $new_token, ':expires' => $expires_at, ':uid' => (int)$row['user_id']]);
|
||||
|
||||
$this->pdo->prepare(
|
||||
"UPDATE company_map_user SET invite_token = :token
|
||||
WHERE map_id = :map_id AND company_id = :company_id"
|
||||
)->execute([':token' => $new_token, ':map_id' => $map_id, ':company_id' => $this->company_id]);
|
||||
|
||||
return ['email' => $row['email'], 'token' => $new_token];
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -290,6 +373,45 @@ class UserManager {
|
||||
]);
|
||||
}
|
||||
|
||||
/**
|
||||
* Update the app_access of a non-owner company member.
|
||||
*
|
||||
* Owner's app_access is managed via user.app_access (their license); it
|
||||
* cannot be changed here. Caller must have already validated the value is
|
||||
* within the owner's license.
|
||||
*
|
||||
* @param int $map_id The company_map_user.map_id to update.
|
||||
* @param string $app_access New value: 'wms', 'accounting', or 'all'.
|
||||
* @throws Exception If the member is not found or is the owner.
|
||||
*/
|
||||
public function updateAppAccess(int $map_id, string $app_access): void {
|
||||
if (!$map_id || $app_access === '') {
|
||||
throw new Exception('Invalid request.');
|
||||
}
|
||||
|
||||
$sth = $this->pdo->prepare(
|
||||
"SELECT u.license FROM company_map_user m
|
||||
JOIN user u ON u.user_id = m.user_id
|
||||
WHERE m.map_id = :map_id AND m.company_id = :company_id
|
||||
LIMIT 1"
|
||||
);
|
||||
$sth->execute([':map_id' => $map_id, ':company_id' => $this->company_id]);
|
||||
$license = $sth->fetchColumn();
|
||||
|
||||
if ($license === false) throw new Exception('User not found.');
|
||||
if ($license === 'owner') throw new Exception('Owner app access is determined by their license.');
|
||||
|
||||
$this->pdo->prepare(
|
||||
"UPDATE company_map_user
|
||||
SET app_access = :app_access
|
||||
WHERE map_id = :map_id AND company_id = :company_id"
|
||||
)->execute([
|
||||
':app_access' => $app_access,
|
||||
':map_id' => $map_id,
|
||||
':company_id' => $this->company_id,
|
||||
]);
|
||||
}
|
||||
|
||||
/**
|
||||
* Remove a user from the current company.
|
||||
*
|
||||
@@ -318,5 +440,17 @@ class UserManager {
|
||||
"DELETE FROM company_map_user
|
||||
WHERE map_id = :map_id AND company_id = :company_id"
|
||||
)->execute([':map_id' => $map_id, ':company_id' => $this->company_id]);
|
||||
|
||||
// If this was a pending invited account that was never activated, delete
|
||||
// the placeholder user row so the email is free for future invitations.
|
||||
$sth = $this->pdo->prepare(
|
||||
"SELECT license, status FROM user WHERE user_id = :uid LIMIT 1"
|
||||
);
|
||||
$sth->execute([':uid' => (int)$row['user_id']]);
|
||||
$u = $sth->fetch(PDO::FETCH_ASSOC);
|
||||
if ($u && $u['license'] === 'user' && $u['status'] === 'pending') {
|
||||
$this->pdo->prepare("DELETE FROM user WHERE user_id = :uid")
|
||||
->execute([':uid' => (int)$row['user_id']]);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -8,7 +8,7 @@
|
||||
* Lifecycle:
|
||||
* post() — first-time GL creation; throws if a record already exists.
|
||||
* replace() — snapshot current lines into td_gl.history, then delete + re-insert.
|
||||
* delete() — hard-delete both td_gl and all its td_gl_item rows (used on void).
|
||||
* delete() — create a reversal journal entry (audit trail), then hard-delete the original.
|
||||
*/
|
||||
class GlManager
|
||||
{
|
||||
@@ -213,7 +213,8 @@ class GlManager
|
||||
public function delete(string $source_type, int $source_id): void
|
||||
{
|
||||
$sth = $this->pdo->prepare(
|
||||
"SELECT id, journal_date, period FROM td_gl
|
||||
"SELECT id, reference, description, journal_date, period, formula_id
|
||||
FROM td_gl
|
||||
WHERE company_id = :cid
|
||||
AND source_type = :source_type
|
||||
AND source_id = :source_id
|
||||
@@ -229,7 +230,40 @@ class GlManager
|
||||
if (!$gl_id) return;
|
||||
|
||||
$journal_date = $this->resolveJournalDate($gl['journal_date'] ?? null, (string)($gl['period'] ?? ''));
|
||||
$this->assertPostingWindow($journal_date, 'GL posting deletion');
|
||||
$this->assertPostingWindow($journal_date, 'GL void');
|
||||
|
||||
$original_lines = $this->getLines($gl_id);
|
||||
|
||||
if (!empty($original_lines)) {
|
||||
$reversal_lines = array_map(fn($line) => [
|
||||
'account_code' => $line['account_code'],
|
||||
'department_id' => (int)$line['department_id'],
|
||||
'debit' => (float)$line['credit'],
|
||||
'credit' => (float)$line['debit'],
|
||||
'description' => 'VOID: ' . $line['description'],
|
||||
], $original_lines);
|
||||
|
||||
$now = date('Y-m-d H:i:s');
|
||||
$this->pdo->prepare(
|
||||
"INSERT INTO td_gl
|
||||
(company_id, source_type, source_id, reference, description, journal_date,
|
||||
formula_id, period, current_version, history, created_at, updated_at)
|
||||
VALUES
|
||||
(:cid, 'reversal', :source_id, :reference, :description, :journal_date,
|
||||
:formula_id, :period, 1, '[]', :created_at, :updated_at)"
|
||||
)->execute([
|
||||
':cid' => $this->companyId,
|
||||
':source_id' => $gl_id,
|
||||
':reference' => 'VOID/' . ($gl['reference'] ?? ''),
|
||||
':description' => 'Void: ' . ($gl['description'] ?? ''),
|
||||
':journal_date' => $journal_date,
|
||||
':formula_id' => (int)($gl['formula_id'] ?? 0),
|
||||
':period' => $gl['period'] ?? '',
|
||||
':created_at' => $now,
|
||||
':updated_at' => $now,
|
||||
]);
|
||||
$this->insertLines((int)$this->pdo->lastInsertId(), $reversal_lines);
|
||||
}
|
||||
|
||||
$this->pdo->prepare(
|
||||
"DELETE FROM td_gl_item WHERE company_id = :cid AND gl_id = :gl_id"
|
||||
|
||||
Reference in New Issue
Block a user