finalize logo

This commit is contained in:
Thanakorn S
2026-05-08 16:19:56 +07:00
parent 304848d3f4
commit d57a361aa6
7 changed files with 16 additions and 8 deletions
+11 -3
View File
@@ -1,4 +1,4 @@
# TRx WMS
# TR3 WMS
A multi-tenant Warehouse Management System (WMS) built with PHP, MySQL, and vanilla JavaScript. Designed for small-to-medium operations that need barcode-driven stock control, lot/serial traceability, and multi-warehouse support — accessible from any browser without installing a native app.
@@ -64,7 +64,7 @@ A multi-tenant Warehouse Management System (WMS) built with PHP, MySQL, and vani
### Security
- Session-based authentication with TOTP-style OTP validation on every API request
- CSRF token enforcement on all POST requests
- Role-based access control: `owner`, `admin`, `staff`, `viewer`; enforced in many write APIs with `require_role()` and mirrored in page/sidebar UI (see `docs/ROLES.md`)
- Role-based access control: `owner`, `admin`, `staff`, `viewer`; enforced in protected write APIs with `require_role()` and mirrored in page/sidebar UI (see `docs/ROLES.md`)
- Passwords hashed; profile picture uploads sandboxed to `uploads/profile/`
---
@@ -73,11 +73,12 @@ A multi-tenant Warehouse Management System (WMS) built with PHP, MySQL, and vani
| Layer | Technology |
|-------|-----------|
| Backend | PHP 8.x, Apache |
| Backend | PHP 8.x, Apache, Composer |
| Databases | MySQL — `wms` (system/auth), `wms2` (operational data) |
| Frontend | Bootstrap 5, jQuery, Flatpickr, ApexCharts, JsBarcode, Html5Qrcode |
| Build | Vite (`npm run dev` / `npm run build`) |
| Auth | Session + HMAC-SHA1 OTP + CSRF tokens |
| Tests | PHPUnit 10 integration tests under `tests/` |
---
@@ -105,6 +106,10 @@ app/
## Local Development
```bash
# PHP dependencies / integration tests
composer install
vendor/bin/phpunit
# Front-end assets (Vite)
npm run dev
npm run build
@@ -118,6 +123,8 @@ mysql -uroot -p2618 wms2 < migration.sql
App is served by Apache at `http://localhost/wms/app/`.
The PHPUnit suite uses real local `wms` and `wms2` databases and fixture IDs defined in `tests/bootstrap.php`; run it only against a development database.
---
## Documentation
@@ -134,5 +141,6 @@ App is served by Apache at `http://localhost/wms/app/`.
| `docs/STOCK.md` | Stock ledger, approval flow, rack lifecycle, StockManager/WarehouseManager |
| `docs/SCANNER.md` | scanner.js internals, device support, integrating scanning into new pages |
| `docs/CONTRIBUTING.md` | Patterns for adding new APIs, pages, modules, settings, and schema changes |
| `docs/V2PLAN.md` | Planned supervisor role and warehouse-scoped access design |
Security hardening note: protected API engines must include `assets/utils/db_auth.php`, must reject unauthenticated sessions server-side, and must define role requirements with `require_role()` where the action is not viewer-safe.