code audit fixes: require_once, issue flow, role guards
- Upgraded all plain `require` to `require_once` across 172 api/engine and api/engine_report files to prevent class-redeclaration errors - Added issue button, issue_invoice() with GL toastr, and delete_invoice() to expense/manage_purchase_invoice.php, bringing it in line with po/manage_purchase_invoice.php - Added can_delete role guard (admin/owner only) to trash icons on revenue/invoice.php and expense/purchase_invoice.php, matching the existing pattern in finance/receipt.php and finance/payment.php Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 4.6
parent
eddb10aa22
commit
b07882e3f4
@@ -42,11 +42,11 @@
|
||||
* On failure: { "message": "Incorrect Password" }
|
||||
*/
|
||||
|
||||
require '../../../session.php';
|
||||
require '../../../config.php';
|
||||
require '../../../preset.php';
|
||||
require_once '../../../session.php';
|
||||
require_once '../../../config.php';
|
||||
require_once '../../../preset.php';
|
||||
define('UNAUTHENTICATED_ROUTE', true);
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
require_once '../../../assets/utils/db_auth.php';
|
||||
|
||||
// ── Step 1: Reload credentials from session ───────────────────────────────────
|
||||
// These were stored by login_otp.php so the user doesn't have to retype them.
|
||||
|
||||
Reference in New Issue
Block a user