code audit fixes: require_once, issue flow, role guards

- Upgraded all plain `require` to `require_once` across 172 api/engine
  and api/engine_report files to prevent class-redeclaration errors
- Added issue button, issue_invoice() with GL toastr, and delete_invoice()
  to expense/manage_purchase_invoice.php, bringing it in line with
  po/manage_purchase_invoice.php
- Added can_delete role guard (admin/owner only) to trash icons on
  revenue/invoice.php and expense/purchase_invoice.php, matching the
  existing pattern in finance/receipt.php and finance/payment.php

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
Thanakorn S
2026-05-23 17:06:08 +07:00
co-authored by Claude Sonnet 4.6
parent eddb10aa22
commit b07882e3f4
191 changed files with 534 additions and 464 deletions
+78 -2
View File
@@ -128,6 +128,10 @@
<i class="ti ti-device-floppy me-1"></i>Save
</button>
<button class="btn btn-success w-100" id="btn_issue" onclick="issue_invoice()">
<i class="ti ti-send me-1"></i>Issue
</button>
<a href="#" class="btn btn-outline-info w-100 d-none" id="btn_create_scn">
<i class="ti ti-file-minus me-1"></i>Create Supplier Credit Note
</a>
@@ -136,6 +140,10 @@
<i class="ti ti-ban me-1"></i>Void
</button>
<button class="btn btn-outline-danger w-100 d-none" id="btn_delete" onclick="delete_invoice()">
<i class="ti ti-trash me-1"></i>Delete
</button>
</div>
</div>
@@ -147,6 +155,9 @@
<?php require '../include_ending.php'; ?>
<script>
const can_delete = ['admin', 'owner'].includes(user_role);
var invoice_id = <?php echo $invoice_id; ?>;
var invoice_data = null;
@@ -183,8 +194,13 @@
$('#due_date_row').toggleClass('d-none', is_dn);
$('#due_date, #notes').prop('disabled', !is_editable);
$('#btn_issue').html(is_dn
? '<i class="ti ti-send me-1"></i>Issue Supplier Credit Note'
: '<i class="ti ti-send me-1"></i>Issue Purchase Invoice');
var not_editable_hint = (!is_pi && !is_dn) ? 'Unsupported document type' : '';
set_btn_state('#btn_save', is_editable, not_editable_hint || 'Only draft documents can be edited');
set_btn_state('#btn_save', is_editable, not_editable_hint || 'Only draft documents can be edited');
set_btn_state('#btn_issue', is_editable, not_editable_hint || (status > 0 ? 'Already issued' : 'Only drafts can be issued'));
$('#btn_create_scn')
.toggleClass('d-none', !(is_pi && status >= 1 && status !== 4))
@@ -192,8 +208,10 @@
set_btn_state('#btn_void', is_pi && status >= 1 && status !== 4,
!is_pi ? 'Only purchase invoices can be voided'
: status === 0 ? 'Invoice has not been issued yet'
: status === 0 ? 'Issue the document before voiding'
: status === 4 ? 'Already void' : '');
$('#btn_delete').toggleClass('d-none', !can_delete || !invoice_id);
}
function retrieve_invoice() {
@@ -325,6 +343,64 @@
});
}
function issue_invoice() {
var is_dn = invoice_data && invoice_data.doc_type === 'supplier_credit_note';
var due_date = $('#due_date').val().trim();
if (!is_dn && !due_date) {
bootbox.alert('Please enter a due date before issuing this purchase invoice.');
return;
}
var label = is_dn ? 'Issue Supplier Credit Note' : 'Issue Purchase Invoice';
bootbox.confirm({
message: is_dn ? 'Issue this supplier credit note?' : 'Issue this purchase invoice?',
buttons: {
confirm: { label: label, className: 'btn-success' },
cancel: { label: 'Back', className: 'btn-secondary' }
},
callback: function(result) {
if (!result) return;
ajax_request({
url: '<?php echo $server_url?>order/api/engine/issue_invoice.php',
autoPrepare: true,
checkRequired: 0,
action: 'update',
data: {
invoice_id: invoice_id,
due_date: is_dn ? '' : due_date.split('/').reverse().join('-')
},
onSuccess: function(res) {
retrieve_invoice();
if (res.gl_posted === true) {
toastr.success('GL entry posted automatically.', 'GL Posted');
} else if (res.gl_posted === false) {
toastr.warning('Document issued, but GL posting failed: ' + (res.gl_message || 'Unknown error'), 'GL Skipped', { timeOut: 8000 });
}
}
});
}
});
}
function delete_invoice() {
bootbox.confirm({
message: 'Delete this document? Any GL entry will be removed.',
buttons: { confirm: { label: 'Delete', className: 'btn-danger' }, cancel: { label: 'Back', className: 'btn-secondary' } },
callback: function(result) {
if (!result) return;
ajax_request({
url: '<?php echo $server_url?>order/api/engine/delete_invoice.php',
autoPrepare: false,
checkRequired: 0,
action: 'delete',
data: { id: invoice_id },
onSuccess: function() {
window.location.href = '<?php echo $server_url?>expense/purchase_invoice.php';
}
});
}
});
}
function void_invoice() {
bootbox.confirm({
message: '<strong>Void this purchase invoice?</strong><br>This action cannot be undone.',