diff --git a/CHANGELOG.md b/CHANGELOG.md deleted file mode 100644 index df8cf01..0000000 --- a/CHANGELOG.md +++ /dev/null @@ -1,87 +0,0 @@ -# Changelog - -All notable changes to TRx WMS are documented here. -Format: `## [version] — YYYY-MM-DD` with sections Added / Changed / Fixed / Removed. - ---- - -## [Unreleased] - -### Planned -- Role-based access control enforcement across all API endpoints and UI pages (see `ROLES.md`) - ---- - -## [0.6.0] — 2026-05-06 - -### Added -- Barcode system — `md_barcode` table, SKU label page (`ics/sku_barcode_label.php`), Location label page (`ics/location_barcode_label.php`) -- `scanner.js` — unified scanner module supporting USB scanner, handheld, phone camera (Html5Qrcode), and clipboard paste -- Scan-driven stock flows — scan SKU label → scan location label → F2 to save (no mouse required) -- `ics/api/engine/barcode_lookup.php` — validates barcode string, returns typed result (`sku` / `loc` / `raw`) -- `ics/api/engine/validate_scan_location.php` — pre-save location validation for stock in/out/transfer -- `ics/api/engine/sku_label_lots.php`, `sku_label_products.php` — lot and product data feeds for SKU label page -- Cost, price, and margin fields on `md_product` -- Contact module linked to setting sidebar - -### Fixed -- `location_barcode_label.php` — `ON DUPLICATE KEY UPDATE` now includes `status = 1` so previewing a previously-disabled location barcode re-enables it - ---- - -## [0.5.0] — 2026-04 - -### Added -- Purchase Orders (`po/`) — create, confirm, receive, cancel, payment tracking -- Order module (`order/`) — sales orders, returns, invoices (invoice / credit note / debit note), order confirmation, payment status -- `td_order`, `td_invoice`, `td_return`, `td_purchase_order` tables -- Invoice print view (`order/print_invoice.php`) - ---- - -## [0.4.0] — 2026-03 - -### Added -- Warehouse location modes — simple (warehouse + rack) and advanced (warehouse + zone + aisle + rack) -- `company_setting` keys: `advanced_location`, `location_label_rack/zone/aisle`, `default_stock_status`, `auto_complete_on_ship`, `auto_invoice_and_credit_note` -- Per-warehouse stock tables (`td_stock_{warehouse_id}`) — balance = `SUM(in) - SUM(out)` where `status = 1` -- Stock approval flow — transactions created as `status = 0` (draft) and approved separately -- Rack occupancy report (`reports/occupy_rack.php`) -- Expired / near-expiry report (`reports/expired_stock.php`) - -### Changed -- Warehouse layers made switchable via `advanced_location` setting - ---- - -## [0.3.0] — 2026-02 - -### Added -- Contact module (`contact/`) — supplier/customer contacts, contact types -- Stock movement report with date and SKU filters -- Product lot report with expiry date tracking -- Low-stock dashboard widget with restock shortcut - ---- - -## [0.2.0] — 2026-01 - -### Added -- Multi-tenant branch support — `company_list`, `company_map_user`, branch switcher in topbar -- User management (`setting/users.php`) — invite by email, role assignment, remove member -- SMTP configuration (`setting/smtp.php`) -- OTP validation on every API request (HMAC-SHA1 based on user password + session time) -- CSRF token enforcement on all POST requests - ---- - -## [0.1.0] — 2025-12 - -### Added -- Initial project scaffold — PHP + MySQL + Bootstrap 5 + jQuery -- Login / registration / onboarding flow -- Product master (`inventory/product.php`) — SKU, name, UOM, category, barcode -- Warehouse master (`inventory/warehouse.php`) — warehouses and rack definitions -- Stock In / Out / Transfer pages with manual form entry -- `td_stock` base table structure -- Dashboard with basic stock summary diff --git a/README.md b/README.md index 911c282..3a571e1 100755 --- a/README.md +++ b/README.md @@ -64,7 +64,7 @@ A multi-tenant Warehouse Management System (WMS) built with PHP, MySQL, and vani ### Security - Session-based authentication with TOTP-style OTP validation on every API request - CSRF token enforcement on all POST requests -- Role-based access control: `owner`, `admin`, `staff`, `viewer` (see `ROLES.md`) +- Role-based access control: `owner`, `admin`, `staff`, `viewer`; enforced in many write APIs with `require_role()` and mirrored in page/sidebar UI (see `docs/ROLES.md`) - Passwords hashed; profile picture uploads sandboxed to `uploads/profile/` --- @@ -124,7 +124,7 @@ App is served by Apache at `http://localhost/wms/app/`. | File | Contents | |------|----------| -| `CHANGELOG.md` | Version history and notable changes | +| `docs/CHANGELOG.md` | Version history and notable changes | | `docs/ROLES.md` | Role-based access control spec (admin / staff / viewer) | | `docs/DATABASE.md` | Full schema for both databases — tables, columns, relationships | | `docs/API.md` | All API endpoints — request fields, response format, error codes | @@ -134,3 +134,5 @@ App is served by Apache at `http://localhost/wms/app/`. | `docs/STOCK.md` | Stock ledger, approval flow, rack lifecycle, StockManager/WarehouseManager | | `docs/SCANNER.md` | scanner.js internals, device support, integrating scanning into new pages | | `docs/CONTRIBUTING.md` | Patterns for adding new APIs, pages, modules, settings, and schema changes | + +Security hardening note: protected API engines must include `assets/utils/db_auth.php`, must reject unauthenticated sessions server-side, and must define role requirements with `require_role()` where the action is not viewer-safe. diff --git a/app/assets/utils/db_auth.php b/app/assets/utils/db_auth.php index dd3c277..f57d78a 100644 --- a/app/assets/utils/db_auth.php +++ b/app/assets/utils/db_auth.php @@ -77,6 +77,13 @@ if(!empty($_SESSION["login_company_id"])){ } +// Fail closed — reject any request that arrives without an authenticated session +// unless the engine explicitly declared itself a pre-auth route. +if (empty($_SESSION['login_company_id']) && !defined('UNAUTHENTICATED_ROUTE')) { + http_response_code(401); + exit(json_encode(['success' => 0, 'message' => 'Authentication required.'])); +} + // set up ANSWER $answer = array("success"=>0, "message"=>""); diff --git a/app/include_ending.php b/app/include_ending.php index dcfcce6..75e6aa2 100644 --- a/app/include_ending.php +++ b/app/include_ending.php @@ -2,7 +2,7 @@