1) user invitation 2) app access control 3) txn quota guard

This commit is contained in:
Thanakorn S
2026-05-21 11:42:47 +07:00
parent 8ec2e89f79
commit 6eeebfeacb
50 changed files with 1062 additions and 113 deletions
+95 -7
View File
@@ -10,21 +10,109 @@
try {
// All valid app_access values: every registered app key + 'all'
$all_app_keys = array_keys($app_registry);
$all_valid_apps = array_merge($all_app_keys, ['all']);
// What the current owner's license permits assigning to others
$owner_access = $_SESSION['login_app_access'] ?? 'wms';
$owner_allowed_access = $owner_access === 'all' ? $all_valid_apps : [$owner_access];
if ($action === 'create') {
$email = strtolower(trim($data['invite_email'] ?? ''));
$role = trim($data['invite_role'] ?? '');
$email = strtolower(trim($data['invite_email'] ?? ''));
$role = trim($data['invite_role'] ?? '');
$app_access = trim($data['invite_app_access'] ?? '');
if (!in_array($app_access, $owner_allowed_access, true)) {
throw new Exception('App access selection exceeds your license.');
}
$result = $um->inviteUser($email, $role, $app_access);
if ($result['new_user']) {
$base_url = (isset($_SERVER['HTTPS']) && $_SERVER['HTTPS'] === 'on' ? 'https' : 'http')
. '://' . $_SERVER['HTTP_HOST'] . rtrim($server_url, '/');
$invite_url = $base_url . '/login/invited_onboarding.php?token=' . $result['token'];
require_once '../../../assets/utils/module/mailer.php';
$mailer = new mailer(['pdo1' => $pdo1]);
$mailer->send_email([
'company_id' => $company_id,
'to' => $result['email'],
'subject' => 'You have been invited to join the team',
'message' => implode("\n", [
"You have been invited to join the team.",
"",
"Click the button below to set up your account:",
"",
"<a href=\"{$invite_url}\" style=\"display:inline-block;padding:12px 28px;background:#E66239;color:#ffffff;text-decoration:none;border-radius:6px;font-weight:600;\">Accept Invitation</a>",
"",
"Or copy and paste this link into your browser:",
"<a href=\"{$invite_url}\">{$invite_url}</a>",
"",
"This link will expire in 7 days.",
"",
"If you did not expect this invitation, you can ignore this email.",
]),
'channel_name' => 'WMS',
'key' => $pinkey,
]);
$answer['message'] = htmlspecialchars($result['email']) . ' has been invited. An email has been sent to complete their registration.';
} else {
$answer['message'] = htmlspecialchars($result['email']) . ' has been added to your company.';
}
$invited_email = $um->inviteUser($email, $role);
$answer['success'] = 1;
$answer['message'] = htmlspecialchars($invited_email) . ' has been added to your company.';
} elseif ($action === 'update') {
$map_id = (int)($data['map_id'] ?? 0);
$role = trim($data['role'] ?? '');
$map_id = (int)($data['map_id'] ?? 0);
$role = trim($data['role'] ?? '');
$app_access = trim($data['app_access'] ?? '');
$um->updateRole($map_id, $role);
if ($app_access !== '') {
if (!in_array($app_access, $owner_allowed_access, true)) {
throw new Exception('App access selection exceeds your license.');
}
$um->updateAppAccess($map_id, $app_access);
}
$answer['success'] = 1;
$answer['message'] = 'Role updated successfully.';
$answer['message'] = 'Access updated successfully.';
} elseif ($action === 'resend') {
$map_id = (int)($data['map_id'] ?? 0);
$result = $um->resendInvite($map_id);
$base_url = (isset($_SERVER['HTTPS']) && $_SERVER['HTTPS'] === 'on' ? 'https' : 'http')
. '://' . $_SERVER['HTTP_HOST'] . rtrim($server_url, '/');
$invite_url = $base_url . '/login/invited_onboarding.php?token=' . $result['token'];
require_once '../../../assets/utils/module/mailer.php';
$mailer = new mailer(['pdo1' => $pdo1]);
$mailer->send_email([
'company_id' => $company_id,
'to' => $result['email'],
'subject' => 'Your invitation link has been resent',
'message' => implode("\n", [
"Your invitation link has been refreshed.",
"",
"Click the button below to set up your account:",
"",
"<a href=\"{$invite_url}\" style=\"display:inline-block;padding:12px 28px;background:#E66239;color:#ffffff;text-decoration:none;border-radius:6px;font-weight:600;\">Accept Invitation</a>",
"",
"Or copy and paste this link into your browser:",
"<a href=\"{$invite_url}\">{$invite_url}</a>",
"",
"This link will expire in 7 days.",
]),
'channel_name' => 'WMS',
'key' => $pinkey,
]);
$answer['success'] = 1;
$answer['message'] = 'Invitation resent to ' . htmlspecialchars($result['email']) . '.';
} elseif ($action === 'delete') {
$map_id = (int)($data['map_id'] ?? 0);
+6
View File
@@ -39,6 +39,12 @@ if ($action === 'update') {
$_SESSION['login_company_id'] = $target_company_id;
$_SESSION['login_role'] = $target_map['role'] ?? 'viewer';
if (($_SESSION['login_license'] ?? 'user') === 'owner') {
$_SESSION['login_app_access'] = $target_map['user_app_access'] ?? 'wms';
} else {
$_SESSION['login_app_access'] = $target_map['app_access'] ?? 'wms';
}
$answer['success'] = 1;
$answer['message'] = 'Switched successfully.';
exit(json_encode($answer));