closing security gap [ignore guarding change for now]

This commit is contained in:
Thanakorn S
2026-05-07 10:29:14 +07:00
parent a24930f684
commit a75d37e841
13 changed files with 39 additions and 93 deletions
+4 -2
View File
@@ -64,7 +64,7 @@ A multi-tenant Warehouse Management System (WMS) built with PHP, MySQL, and vani
### Security
- Session-based authentication with TOTP-style OTP validation on every API request
- CSRF token enforcement on all POST requests
- Role-based access control: `owner`, `admin`, `staff`, `viewer` (see `ROLES.md`)
- Role-based access control: `owner`, `admin`, `staff`, `viewer`; enforced in many write APIs with `require_role()` and mirrored in page/sidebar UI (see `docs/ROLES.md`)
- Passwords hashed; profile picture uploads sandboxed to `uploads/profile/`
---
@@ -124,7 +124,7 @@ App is served by Apache at `http://localhost/wms/app/`.
| File | Contents |
|------|----------|
| `CHANGELOG.md` | Version history and notable changes |
| `docs/CHANGELOG.md` | Version history and notable changes |
| `docs/ROLES.md` | Role-based access control spec (admin / staff / viewer) |
| `docs/DATABASE.md` | Full schema for both databases — tables, columns, relationships |
| `docs/API.md` | All API endpoints — request fields, response format, error codes |
@@ -134,3 +134,5 @@ App is served by Apache at `http://localhost/wms/app/`.
| `docs/STOCK.md` | Stock ledger, approval flow, rack lifecycle, StockManager/WarehouseManager |
| `docs/SCANNER.md` | scanner.js internals, device support, integrating scanning into new pages |
| `docs/CONTRIBUTING.md` | Patterns for adding new APIs, pages, modules, settings, and schema changes |
Security hardening note: protected API engines must include `assets/utils/db_auth.php`, must reject unauthenticated sessions server-side, and must define role requirements with `require_role()` where the action is not viewer-safe.