code audit fixes: require_once, issue flow, role guards
- Upgraded all plain `require` to `require_once` across 172 api/engine and api/engine_report files to prevent class-redeclaration errors - Added issue button, issue_invoice() with GL toastr, and delete_invoice() to expense/manage_purchase_invoice.php, bringing it in line with po/manage_purchase_invoice.php - Added can_delete role guard (admin/owner only) to trash icons on revenue/invoice.php and expense/purchase_invoice.php, matching the existing pattern in finance/receipt.php and finance/payment.php Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 4.6
parent
eddb10aa22
commit
b07882e3f4
@@ -193,6 +193,7 @@
|
||||
<script>
|
||||
var current_tab = <?php echo json_encode($_GET['tab'] ?? 'purchase_invoice'); ?>;
|
||||
var all_invoices = [];
|
||||
const can_delete = ['admin', 'owner'].includes(user_role);
|
||||
var formula_map = {};
|
||||
|
||||
function load_formula_map() {
|
||||
@@ -352,9 +353,7 @@
|
||||
<a href="javascript:;" title="View GL Entry" class="me-2" onclick="show_gl_modal('purchase_invoice',${inv.id})">
|
||||
<i class="ti ti-book fs-5 text-secondary"></i>
|
||||
</a>
|
||||
<a href="javascript:;" title="Delete" class="link-danger" onclick="delete_invoice(${inv.id},'${escape_html(inv.invoice_number)}')">
|
||||
<i class="ti ti-trash fs-5"></i>
|
||||
</a>
|
||||
${can_delete ? `<a href="javascript:;" title="Delete" class="link-danger" onclick="delete_invoice(${inv.id},'${escape_html(inv.invoice_number)}')"><i class="ti ti-trash fs-5"></i></a>` : ''}
|
||||
</td>
|
||||
</tr>`;
|
||||
});
|
||||
@@ -400,9 +399,7 @@
|
||||
<a href="javascript:;" title="View GL Entry" class="me-2" onclick="show_gl_modal('supplier_credit_note',${scn.id})">
|
||||
<i class="ti ti-book fs-5 text-secondary"></i>
|
||||
</a>
|
||||
<a href="javascript:;" title="Delete" class="link-danger" onclick="delete_invoice(${scn.id},'${escape_html(scn.invoice_number)}')">
|
||||
<i class="ti ti-trash fs-5"></i>
|
||||
</a>
|
||||
${can_delete ? `<a href="javascript:;" title="Delete" class="link-danger" onclick="delete_invoice(${scn.id},'${escape_html(scn.invoice_number)}')"><i class="ti ti-trash fs-5"></i></a>` : ''}
|
||||
</td>
|
||||
</tr>`;
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user