finalize logo
This commit is contained in:
@@ -1,4 +1,4 @@
|
|||||||
# TRx WMS
|
# TR3 WMS
|
||||||
|
|
||||||
A multi-tenant Warehouse Management System (WMS) built with PHP, MySQL, and vanilla JavaScript. Designed for small-to-medium operations that need barcode-driven stock control, lot/serial traceability, and multi-warehouse support — accessible from any browser without installing a native app.
|
A multi-tenant Warehouse Management System (WMS) built with PHP, MySQL, and vanilla JavaScript. Designed for small-to-medium operations that need barcode-driven stock control, lot/serial traceability, and multi-warehouse support — accessible from any browser without installing a native app.
|
||||||
|
|
||||||
@@ -64,7 +64,7 @@ A multi-tenant Warehouse Management System (WMS) built with PHP, MySQL, and vani
|
|||||||
### Security
|
### Security
|
||||||
- Session-based authentication with TOTP-style OTP validation on every API request
|
- Session-based authentication with TOTP-style OTP validation on every API request
|
||||||
- CSRF token enforcement on all POST requests
|
- CSRF token enforcement on all POST requests
|
||||||
- Role-based access control: `owner`, `admin`, `staff`, `viewer`; enforced in many write APIs with `require_role()` and mirrored in page/sidebar UI (see `docs/ROLES.md`)
|
- Role-based access control: `owner`, `admin`, `staff`, `viewer`; enforced in protected write APIs with `require_role()` and mirrored in page/sidebar UI (see `docs/ROLES.md`)
|
||||||
- Passwords hashed; profile picture uploads sandboxed to `uploads/profile/`
|
- Passwords hashed; profile picture uploads sandboxed to `uploads/profile/`
|
||||||
|
|
||||||
---
|
---
|
||||||
@@ -73,11 +73,12 @@ A multi-tenant Warehouse Management System (WMS) built with PHP, MySQL, and vani
|
|||||||
|
|
||||||
| Layer | Technology |
|
| Layer | Technology |
|
||||||
|-------|-----------|
|
|-------|-----------|
|
||||||
| Backend | PHP 8.x, Apache |
|
| Backend | PHP 8.x, Apache, Composer |
|
||||||
| Databases | MySQL — `wms` (system/auth), `wms2` (operational data) |
|
| Databases | MySQL — `wms` (system/auth), `wms2` (operational data) |
|
||||||
| Frontend | Bootstrap 5, jQuery, Flatpickr, ApexCharts, JsBarcode, Html5Qrcode |
|
| Frontend | Bootstrap 5, jQuery, Flatpickr, ApexCharts, JsBarcode, Html5Qrcode |
|
||||||
| Build | Vite (`npm run dev` / `npm run build`) |
|
| Build | Vite (`npm run dev` / `npm run build`) |
|
||||||
| Auth | Session + HMAC-SHA1 OTP + CSRF tokens |
|
| Auth | Session + HMAC-SHA1 OTP + CSRF tokens |
|
||||||
|
| Tests | PHPUnit 10 integration tests under `tests/` |
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
@@ -105,6 +106,10 @@ app/
|
|||||||
## Local Development
|
## Local Development
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
|
# PHP dependencies / integration tests
|
||||||
|
composer install
|
||||||
|
vendor/bin/phpunit
|
||||||
|
|
||||||
# Front-end assets (Vite)
|
# Front-end assets (Vite)
|
||||||
npm run dev
|
npm run dev
|
||||||
npm run build
|
npm run build
|
||||||
@@ -118,6 +123,8 @@ mysql -uroot -p2618 wms2 < migration.sql
|
|||||||
|
|
||||||
App is served by Apache at `http://localhost/wms/app/`.
|
App is served by Apache at `http://localhost/wms/app/`.
|
||||||
|
|
||||||
|
The PHPUnit suite uses real local `wms` and `wms2` databases and fixture IDs defined in `tests/bootstrap.php`; run it only against a development database.
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
## Documentation
|
## Documentation
|
||||||
@@ -134,5 +141,6 @@ App is served by Apache at `http://localhost/wms/app/`.
|
|||||||
| `docs/STOCK.md` | Stock ledger, approval flow, rack lifecycle, StockManager/WarehouseManager |
|
| `docs/STOCK.md` | Stock ledger, approval flow, rack lifecycle, StockManager/WarehouseManager |
|
||||||
| `docs/SCANNER.md` | scanner.js internals, device support, integrating scanning into new pages |
|
| `docs/SCANNER.md` | scanner.js internals, device support, integrating scanning into new pages |
|
||||||
| `docs/CONTRIBUTING.md` | Patterns for adding new APIs, pages, modules, settings, and schema changes |
|
| `docs/CONTRIBUTING.md` | Patterns for adding new APIs, pages, modules, settings, and schema changes |
|
||||||
|
| `docs/V2PLAN.md` | Planned supervisor role and warehouse-scoped access design |
|
||||||
|
|
||||||
Security hardening note: protected API engines must include `assets/utils/db_auth.php`, must reject unauthenticated sessions server-side, and must define role requirements with `require_role()` where the action is not viewer-safe.
|
Security hardening note: protected API engines must include `assets/utils/db_auth.php`, must reject unauthenticated sessions server-side, and must define role requirements with `require_role()` where the action is not viewer-safe.
|
||||||
|
|||||||
Binary file not shown.
|
After Width: | Height: | Size: 2.2 KiB |
Binary file not shown.
|
Before Width: | Height: | Size: 813 KiB After Width: | Height: | Size: 644 KiB |
@@ -16,8 +16,8 @@ header('Referrer-Policy: strict-origin-when-cross-origin');
|
|||||||
<meta name="csrf-token" content="<?= htmlspecialchars($_SESSION['csrf_token'] ?? '') ?>">
|
<meta name="csrf-token" content="<?= htmlspecialchars($_SESSION['csrf_token'] ?? '') ?>">
|
||||||
<meta name="viewport" content="width=device-width, initial-scale=1">
|
<meta name="viewport" content="width=device-width, initial-scale=1">
|
||||||
<link rel="apple-touch-icon" sizes="180x180" href="<?php echo $server_url?>assets/images/favicon.png">
|
<link rel="apple-touch-icon" sizes="180x180" href="<?php echo $server_url?>assets/images/favicon.png">
|
||||||
<link rel="icon" type="image/png" sizes="32x32" href="<?php echo $server_url?>assets/images/favicon.png">
|
<link rel="icon" type="image/png" sizes="32x32" href="<?php echo $server_url?>assets/images/favicon32.png">
|
||||||
<link rel="icon" type="image/png" sizes="16x16" href="<?php echo $server_url?>assets/images/favicon.png">
|
<link rel="icon" type="image/png" sizes="16x16" href="<?php echo $server_url?>assets/images/favicon32.png">
|
||||||
<link rel="manifest" href="<?php echo $server_url?>assets/site.webmanifest">
|
<link rel="manifest" href="<?php echo $server_url?>assets/site.webmanifest">
|
||||||
|
|
||||||
<!-- jquery -->
|
<!-- jquery -->
|
||||||
|
|||||||
@@ -10,7 +10,7 @@
|
|||||||
<a href="<?php echo $server_url?>index.php" class="d-inline-flex">
|
<a href="<?php echo $server_url?>index.php" class="d-inline-flex">
|
||||||
<img src="<?php echo $server_url?>assets/images/favicon.png" alt="" width="40"/>
|
<img src="<?php echo $server_url?>assets/images/favicon.png" alt="" width="40"/>
|
||||||
<span class="logo-text ms-2">
|
<span class="logo-text ms-2">
|
||||||
<img src="<?php echo $server_url?>assets/images/logo.png" alt="" height="40"/>
|
<img src="<?php echo $server_url?>assets/images/logo.png" alt="" height="40" style="padding: 5px 0;"/>
|
||||||
</span>
|
</span>
|
||||||
</a>
|
</a>
|
||||||
</div>
|
</div>
|
||||||
|
|||||||
@@ -10,7 +10,7 @@
|
|||||||
<a href="<?php echo $server_url?>index.php" class="d-inline-flex">
|
<a href="<?php echo $server_url?>index.php" class="d-inline-flex">
|
||||||
<img src="<?php echo $server_url?>assets/images/favicon.png" alt="" width="40"/>
|
<img src="<?php echo $server_url?>assets/images/favicon.png" alt="" width="40"/>
|
||||||
<span class="logo-text ms-2">
|
<span class="logo-text ms-2">
|
||||||
<img src="<?php echo $server_url?>assets/images/logo.png" alt="" height="40"/>
|
<img src="<?php echo $server_url?>assets/images/logo.png" alt="" height="40" style="padding: 5px 0;"/>
|
||||||
</span>
|
</span>
|
||||||
</a>
|
</a>
|
||||||
</div>
|
</div>
|
||||||
|
|||||||
@@ -8,7 +8,7 @@
|
|||||||
<a href="index.html" class="d-inline-flex">
|
<a href="index.html" class="d-inline-flex">
|
||||||
<img src="<?php echo $server_url?>assets/images/favicon.png" alt="" width="40"/>
|
<img src="<?php echo $server_url?>assets/images/favicon.png" alt="" width="40"/>
|
||||||
<span class="logo-text ms-2">
|
<span class="logo-text ms-2">
|
||||||
<img src="<?php echo $server_url?>assets/images/logo.png" alt="" height="40"/>
|
<img src="<?php echo $server_url?>assets/images/logo.png" alt="" height="40" style="padding: 5px 0;"/>
|
||||||
</span>
|
</span>
|
||||||
</a>
|
</a>
|
||||||
</div>
|
</div>
|
||||||
|
|||||||
Reference in New Issue
Block a user