diff --git a/README.md b/README.md index 3a571e1..4c9593a 100755 --- a/README.md +++ b/README.md @@ -1,4 +1,4 @@ -# TRx WMS +# TR3 WMS A multi-tenant Warehouse Management System (WMS) built with PHP, MySQL, and vanilla JavaScript. Designed for small-to-medium operations that need barcode-driven stock control, lot/serial traceability, and multi-warehouse support — accessible from any browser without installing a native app. @@ -64,7 +64,7 @@ A multi-tenant Warehouse Management System (WMS) built with PHP, MySQL, and vani ### Security - Session-based authentication with TOTP-style OTP validation on every API request - CSRF token enforcement on all POST requests -- Role-based access control: `owner`, `admin`, `staff`, `viewer`; enforced in many write APIs with `require_role()` and mirrored in page/sidebar UI (see `docs/ROLES.md`) +- Role-based access control: `owner`, `admin`, `staff`, `viewer`; enforced in protected write APIs with `require_role()` and mirrored in page/sidebar UI (see `docs/ROLES.md`) - Passwords hashed; profile picture uploads sandboxed to `uploads/profile/` --- @@ -73,11 +73,12 @@ A multi-tenant Warehouse Management System (WMS) built with PHP, MySQL, and vani | Layer | Technology | |-------|-----------| -| Backend | PHP 8.x, Apache | +| Backend | PHP 8.x, Apache, Composer | | Databases | MySQL — `wms` (system/auth), `wms2` (operational data) | | Frontend | Bootstrap 5, jQuery, Flatpickr, ApexCharts, JsBarcode, Html5Qrcode | | Build | Vite (`npm run dev` / `npm run build`) | | Auth | Session + HMAC-SHA1 OTP + CSRF tokens | +| Tests | PHPUnit 10 integration tests under `tests/` | --- @@ -105,6 +106,10 @@ app/ ## Local Development ```bash +# PHP dependencies / integration tests +composer install +vendor/bin/phpunit + # Front-end assets (Vite) npm run dev npm run build @@ -118,6 +123,8 @@ mysql -uroot -p2618 wms2 < migration.sql App is served by Apache at `http://localhost/wms/app/`. +The PHPUnit suite uses real local `wms` and `wms2` databases and fixture IDs defined in `tests/bootstrap.php`; run it only against a development database. + --- ## Documentation @@ -134,5 +141,6 @@ App is served by Apache at `http://localhost/wms/app/`. | `docs/STOCK.md` | Stock ledger, approval flow, rack lifecycle, StockManager/WarehouseManager | | `docs/SCANNER.md` | scanner.js internals, device support, integrating scanning into new pages | | `docs/CONTRIBUTING.md` | Patterns for adding new APIs, pages, modules, settings, and schema changes | +| `docs/V2PLAN.md` | Planned supervisor role and warehouse-scoped access design | Security hardening note: protected API engines must include `assets/utils/db_auth.php`, must reject unauthenticated sessions server-side, and must define role requirements with `require_role()` where the action is not viewer-safe. diff --git a/app/assets/images/favicon32.png b/app/assets/images/favicon32.png new file mode 100644 index 0000000..9b38900 Binary files /dev/null and b/app/assets/images/favicon32.png differ diff --git a/app/assets/images/logo.png b/app/assets/images/logo.png index 92d9a6c..fbbc113 100644 Binary files a/app/assets/images/logo.png and b/app/assets/images/logo.png differ diff --git a/app/include_header.php b/app/include_header.php index 18442e2..d24a5d5 100644 --- a/app/include_header.php +++ b/app/include_header.php @@ -16,8 +16,8 @@ header('Referrer-Policy: strict-origin-when-cross-origin'); - - + + diff --git a/app/include_master_sidebar.php b/app/include_master_sidebar.php index 43ad758..2dbd3f3 100644 --- a/app/include_master_sidebar.php +++ b/app/include_master_sidebar.php @@ -10,7 +10,7 @@ - + diff --git a/app/include_setting_sidebar.php b/app/include_setting_sidebar.php index f652c1f..69f77fd 100644 --- a/app/include_setting_sidebar.php +++ b/app/include_setting_sidebar.php @@ -10,7 +10,7 @@ - + diff --git a/app/include_sidebar.php b/app/include_sidebar.php index e13730a..b760cd6 100644 --- a/app/include_sidebar.php +++ b/app/include_sidebar.php @@ -8,7 +8,7 @@ - +