finalize logo
This commit is contained in:
@@ -1,4 +1,4 @@
|
||||
# TRx WMS
|
||||
# TR3 WMS
|
||||
|
||||
A multi-tenant Warehouse Management System (WMS) built with PHP, MySQL, and vanilla JavaScript. Designed for small-to-medium operations that need barcode-driven stock control, lot/serial traceability, and multi-warehouse support — accessible from any browser without installing a native app.
|
||||
|
||||
@@ -64,7 +64,7 @@ A multi-tenant Warehouse Management System (WMS) built with PHP, MySQL, and vani
|
||||
### Security
|
||||
- Session-based authentication with TOTP-style OTP validation on every API request
|
||||
- CSRF token enforcement on all POST requests
|
||||
- Role-based access control: `owner`, `admin`, `staff`, `viewer`; enforced in many write APIs with `require_role()` and mirrored in page/sidebar UI (see `docs/ROLES.md`)
|
||||
- Role-based access control: `owner`, `admin`, `staff`, `viewer`; enforced in protected write APIs with `require_role()` and mirrored in page/sidebar UI (see `docs/ROLES.md`)
|
||||
- Passwords hashed; profile picture uploads sandboxed to `uploads/profile/`
|
||||
|
||||
---
|
||||
@@ -73,11 +73,12 @@ A multi-tenant Warehouse Management System (WMS) built with PHP, MySQL, and vani
|
||||
|
||||
| Layer | Technology |
|
||||
|-------|-----------|
|
||||
| Backend | PHP 8.x, Apache |
|
||||
| Backend | PHP 8.x, Apache, Composer |
|
||||
| Databases | MySQL — `wms` (system/auth), `wms2` (operational data) |
|
||||
| Frontend | Bootstrap 5, jQuery, Flatpickr, ApexCharts, JsBarcode, Html5Qrcode |
|
||||
| Build | Vite (`npm run dev` / `npm run build`) |
|
||||
| Auth | Session + HMAC-SHA1 OTP + CSRF tokens |
|
||||
| Tests | PHPUnit 10 integration tests under `tests/` |
|
||||
|
||||
---
|
||||
|
||||
@@ -105,6 +106,10 @@ app/
|
||||
## Local Development
|
||||
|
||||
```bash
|
||||
# PHP dependencies / integration tests
|
||||
composer install
|
||||
vendor/bin/phpunit
|
||||
|
||||
# Front-end assets (Vite)
|
||||
npm run dev
|
||||
npm run build
|
||||
@@ -118,6 +123,8 @@ mysql -uroot -p2618 wms2 < migration.sql
|
||||
|
||||
App is served by Apache at `http://localhost/wms/app/`.
|
||||
|
||||
The PHPUnit suite uses real local `wms` and `wms2` databases and fixture IDs defined in `tests/bootstrap.php`; run it only against a development database.
|
||||
|
||||
---
|
||||
|
||||
## Documentation
|
||||
@@ -134,5 +141,6 @@ App is served by Apache at `http://localhost/wms/app/`.
|
||||
| `docs/STOCK.md` | Stock ledger, approval flow, rack lifecycle, StockManager/WarehouseManager |
|
||||
| `docs/SCANNER.md` | scanner.js internals, device support, integrating scanning into new pages |
|
||||
| `docs/CONTRIBUTING.md` | Patterns for adding new APIs, pages, modules, settings, and schema changes |
|
||||
| `docs/V2PLAN.md` | Planned supervisor role and warehouse-scoped access design |
|
||||
|
||||
Security hardening note: protected API engines must include `assets/utils/db_auth.php`, must reject unauthenticated sessions server-side, and must define role requirements with `require_role()` where the action is not viewer-safe.
|
||||
|
||||
Reference in New Issue
Block a user