closing security gap [ignore guarding change for now]
This commit is contained in:
@@ -64,7 +64,7 @@ A multi-tenant Warehouse Management System (WMS) built with PHP, MySQL, and vani
|
||||
### Security
|
||||
- Session-based authentication with TOTP-style OTP validation on every API request
|
||||
- CSRF token enforcement on all POST requests
|
||||
- Role-based access control: `owner`, `admin`, `staff`, `viewer` (see `ROLES.md`)
|
||||
- Role-based access control: `owner`, `admin`, `staff`, `viewer`; enforced in many write APIs with `require_role()` and mirrored in page/sidebar UI (see `docs/ROLES.md`)
|
||||
- Passwords hashed; profile picture uploads sandboxed to `uploads/profile/`
|
||||
|
||||
---
|
||||
@@ -124,7 +124,7 @@ App is served by Apache at `http://localhost/wms/app/`.
|
||||
|
||||
| File | Contents |
|
||||
|------|----------|
|
||||
| `CHANGELOG.md` | Version history and notable changes |
|
||||
| `docs/CHANGELOG.md` | Version history and notable changes |
|
||||
| `docs/ROLES.md` | Role-based access control spec (admin / staff / viewer) |
|
||||
| `docs/DATABASE.md` | Full schema for both databases — tables, columns, relationships |
|
||||
| `docs/API.md` | All API endpoints — request fields, response format, error codes |
|
||||
@@ -134,3 +134,5 @@ App is served by Apache at `http://localhost/wms/app/`.
|
||||
| `docs/STOCK.md` | Stock ledger, approval flow, rack lifecycle, StockManager/WarehouseManager |
|
||||
| `docs/SCANNER.md` | scanner.js internals, device support, integrating scanning into new pages |
|
||||
| `docs/CONTRIBUTING.md` | Patterns for adding new APIs, pages, modules, settings, and schema changes |
|
||||
|
||||
Security hardening note: protected API engines must include `assets/utils/db_auth.php`, must reject unauthenticated sessions server-side, and must define role requirements with `require_role()` where the action is not viewer-safe.
|
||||
|
||||
Reference in New Issue
Block a user