diff --git a/README.md b/README.md
index 3a571e1..4c9593a 100755
--- a/README.md
+++ b/README.md
@@ -1,4 +1,4 @@
-# TRx WMS
+# TR3 WMS
A multi-tenant Warehouse Management System (WMS) built with PHP, MySQL, and vanilla JavaScript. Designed for small-to-medium operations that need barcode-driven stock control, lot/serial traceability, and multi-warehouse support — accessible from any browser without installing a native app.
@@ -64,7 +64,7 @@ A multi-tenant Warehouse Management System (WMS) built with PHP, MySQL, and vani
### Security
- Session-based authentication with TOTP-style OTP validation on every API request
- CSRF token enforcement on all POST requests
-- Role-based access control: `owner`, `admin`, `staff`, `viewer`; enforced in many write APIs with `require_role()` and mirrored in page/sidebar UI (see `docs/ROLES.md`)
+- Role-based access control: `owner`, `admin`, `staff`, `viewer`; enforced in protected write APIs with `require_role()` and mirrored in page/sidebar UI (see `docs/ROLES.md`)
- Passwords hashed; profile picture uploads sandboxed to `uploads/profile/`
---
@@ -73,11 +73,12 @@ A multi-tenant Warehouse Management System (WMS) built with PHP, MySQL, and vani
| Layer | Technology |
|-------|-----------|
-| Backend | PHP 8.x, Apache |
+| Backend | PHP 8.x, Apache, Composer |
| Databases | MySQL — `wms` (system/auth), `wms2` (operational data) |
| Frontend | Bootstrap 5, jQuery, Flatpickr, ApexCharts, JsBarcode, Html5Qrcode |
| Build | Vite (`npm run dev` / `npm run build`) |
| Auth | Session + HMAC-SHA1 OTP + CSRF tokens |
+| Tests | PHPUnit 10 integration tests under `tests/` |
---
@@ -105,6 +106,10 @@ app/
## Local Development
```bash
+# PHP dependencies / integration tests
+composer install
+vendor/bin/phpunit
+
# Front-end assets (Vite)
npm run dev
npm run build
@@ -118,6 +123,8 @@ mysql -uroot -p2618 wms2 < migration.sql
App is served by Apache at `http://localhost/wms/app/`.
+The PHPUnit suite uses real local `wms` and `wms2` databases and fixture IDs defined in `tests/bootstrap.php`; run it only against a development database.
+
---
## Documentation
@@ -134,5 +141,6 @@ App is served by Apache at `http://localhost/wms/app/`.
| `docs/STOCK.md` | Stock ledger, approval flow, rack lifecycle, StockManager/WarehouseManager |
| `docs/SCANNER.md` | scanner.js internals, device support, integrating scanning into new pages |
| `docs/CONTRIBUTING.md` | Patterns for adding new APIs, pages, modules, settings, and schema changes |
+| `docs/V2PLAN.md` | Planned supervisor role and warehouse-scoped access design |
Security hardening note: protected API engines must include `assets/utils/db_auth.php`, must reject unauthenticated sessions server-side, and must define role requirements with `require_role()` where the action is not viewer-safe.
diff --git a/app/assets/images/favicon32.png b/app/assets/images/favicon32.png
new file mode 100644
index 0000000..9b38900
Binary files /dev/null and b/app/assets/images/favicon32.png differ
diff --git a/app/assets/images/logo.png b/app/assets/images/logo.png
index 92d9a6c..fbbc113 100644
Binary files a/app/assets/images/logo.png and b/app/assets/images/logo.png differ
diff --git a/app/include_header.php b/app/include_header.php
index 18442e2..d24a5d5 100644
--- a/app/include_header.php
+++ b/app/include_header.php
@@ -16,8 +16,8 @@ header('Referrer-Policy: strict-origin-when-cross-origin');
-
-
+
+
diff --git a/app/include_master_sidebar.php b/app/include_master_sidebar.php
index 43ad758..2dbd3f3 100644
--- a/app/include_master_sidebar.php
+++ b/app/include_master_sidebar.php
@@ -10,7 +10,7 @@
-
+
diff --git a/app/include_setting_sidebar.php b/app/include_setting_sidebar.php
index f652c1f..69f77fd 100644
--- a/app/include_setting_sidebar.php
+++ b/app/include_setting_sidebar.php
@@ -10,7 +10,7 @@
-
+
diff --git a/app/include_sidebar.php b/app/include_sidebar.php
index e13730a..b760cd6 100644
--- a/app/include_sidebar.php
+++ b/app/include_sidebar.php
@@ -8,7 +8,7 @@
-
+