centralize roles guards
This commit is contained in:
@@ -3,6 +3,8 @@
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
require '../../../assets/utils/classes/FileUploader.php';
|
||||
|
||||
require_role($user_role, ['owner', 'admin']);
|
||||
|
||||
// ─── Allowed upload MIME types ────────────────────────────────────────────
|
||||
const ALLOWED_MIME = ['image/jpeg', 'image/png', 'image/gif', 'image/webp'];
|
||||
const MAX_SIZE = 2 * 1024 * 1024; // 2 MB
|
||||
|
||||
@@ -2,20 +2,7 @@
|
||||
session_start();
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
|
||||
// ─── Role guard: only owner/admin ────────────────────────────────────────
|
||||
$sth = $pdo1->prepare("
|
||||
SELECT role FROM company_map_user
|
||||
WHERE company_id = :company_id AND user_id = :user_id
|
||||
LIMIT 1
|
||||
");
|
||||
$sth->execute([':company_id' => $company_id, ':user_id' => $user_id]);
|
||||
db_check($sth, $answer);
|
||||
|
||||
if (!in_array($sth->fetchColumn(), ['owner', 'admin'], true)) {
|
||||
$answer['message'] = 'You do not have permission to change SMTP settings.';
|
||||
http_response_code(403);
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
require_role($user_role, ['owner', 'admin']);
|
||||
|
||||
// ─── Encrypt password — same method/key/iv as config.php ─────────────────
|
||||
function encrypt_password(string $plain): string {
|
||||
|
||||
@@ -2,6 +2,8 @@
|
||||
session_start();
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
|
||||
require_role($user_role, ['owner', 'admin']);
|
||||
|
||||
try {
|
||||
|
||||
$to = trim($data['test_email'] ?? '');
|
||||
|
||||
Reference in New Issue
Block a user