app settings
This commit is contained in:
@@ -0,0 +1,7 @@
|
||||
<?php
|
||||
session_start();
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
require '../../../assets/utils/classes/PasswordManager.php';
|
||||
|
||||
$pm = new PasswordManager($pdo1, $include_url);
|
||||
$pm->handleChange($user_id, $data);
|
||||
@@ -0,0 +1,7 @@
|
||||
<?php
|
||||
session_start();
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
require '../../../assets/utils/classes/PasswordManager.php';
|
||||
|
||||
$pm = new PasswordManager($pdo1, $include_url);
|
||||
$pm->handleCheck($data);
|
||||
@@ -0,0 +1,164 @@
|
||||
<?php
|
||||
session_start();
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
require '../../../assets/utils/classes/FileUploader.php';
|
||||
|
||||
// ─── Allowed upload MIME types ────────────────────────────────────────────
|
||||
const ALLOWED_MIME = ['image/jpeg', 'image/png', 'image/gif', 'image/webp'];
|
||||
const MAX_SIZE = 2 * 1024 * 1024; // 2 MB
|
||||
|
||||
// ─── Helper: handle one image slot ────────────────────────────────────────
|
||||
function handle_image_slot(
|
||||
string $slot, // 'company_logo' | 'company_seal'
|
||||
string $action, // 'keep' | 'replace' | 'remove'
|
||||
string $current, // current filename from DB
|
||||
string $upload_dir, // absolute path to uploads/company/
|
||||
string $prefix // filename prefix 'logo_' | 'seal_'
|
||||
): ?string {
|
||||
// 'keep' → return current unchanged
|
||||
if ($action === 'keep') return $current;
|
||||
|
||||
// 'remove' → delete file, return ''
|
||||
if ($action === 'remove') {
|
||||
if ($current && file_exists($upload_dir . $current)) {
|
||||
unlink($upload_dir . $current);
|
||||
}
|
||||
return '';
|
||||
}
|
||||
|
||||
// 'replace' → validate + save new file
|
||||
if ($action === 'replace' && !empty($_FILES[$slot]['tmp_name'])) {
|
||||
|
||||
$file = $_FILES[$slot];
|
||||
|
||||
if ($file['error'] !== UPLOAD_ERR_OK) {
|
||||
throw new RuntimeException("Upload error on {$slot}: code {$file['error']}.");
|
||||
}
|
||||
if ($file['size'] > MAX_SIZE) {
|
||||
throw new RuntimeException('File too large. Maximum size is 2 MB.');
|
||||
}
|
||||
|
||||
$finfo = finfo_open(FILEINFO_MIME_TYPE);
|
||||
$mime = finfo_file($finfo, $file['tmp_name']);
|
||||
finfo_close($finfo);
|
||||
|
||||
if (!in_array($mime, ALLOWED_MIME, true)) {
|
||||
throw new RuntimeException('Invalid file type. Only JPEG, PNG, GIF, WEBP allowed.');
|
||||
}
|
||||
|
||||
// Delete old file first
|
||||
if ($current && file_exists($upload_dir . $current)) {
|
||||
unlink($upload_dir . $current);
|
||||
}
|
||||
|
||||
$ext = pathinfo($file['name'], PATHINFO_EXTENSION);
|
||||
$filename = $prefix . uniqid() . '.' . strtolower($ext);
|
||||
|
||||
if (!move_uploaded_file($file['tmp_name'], $upload_dir . $filename)) {
|
||||
throw new RuntimeException("Failed to save {$slot}.");
|
||||
}
|
||||
|
||||
return $filename;
|
||||
}
|
||||
|
||||
return $current; // fallback
|
||||
}
|
||||
|
||||
try {
|
||||
|
||||
// ── Fetch current image filenames from DB ─────────────────────────────
|
||||
$sth = $pdo1->prepare(
|
||||
'SELECT company_logo, company_seal FROM company_list WHERE company_id = :id LIMIT 1'
|
||||
);
|
||||
$sth->execute([':id' => $company_id]);
|
||||
db_check($sth, $answer);
|
||||
$current = $sth->fetch(PDO::FETCH_ASSOC);
|
||||
|
||||
if (!$current) {
|
||||
$answer['message'] = 'Company not found.';
|
||||
http_response_code(404);
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
|
||||
// ── Upload directory ──────────────────────────────────────────────────
|
||||
$upload_dir = $include_url . 'uploads/company/';
|
||||
if (!is_dir($upload_dir)) {
|
||||
mkdir($upload_dir, 0755, true);
|
||||
}
|
||||
|
||||
// ── Process images ────────────────────────────────────────────────────
|
||||
$logo_action = $data['logo_action'] ?? 'keep';
|
||||
$seal_action = $data['seal_action'] ?? 'keep';
|
||||
|
||||
$new_logo = handle_image_slot('company_logo', $logo_action, $current['company_logo'] ?? '', $upload_dir, 'logo_');
|
||||
$new_seal = handle_image_slot('company_seal', $seal_action, $current['company_seal'] ?? '', $upload_dir, 'seal_');
|
||||
|
||||
// ── Text field sanitisation ───────────────────────────────────────────
|
||||
$channel = strtolower(preg_replace('/[^a-z0-9\-_]/', '', $data['channel_name'] ?? ''));
|
||||
|
||||
// ── UPDATE company_list ───────────────────────────────────────────────
|
||||
$sth = $pdo1->prepare("
|
||||
UPDATE company_list SET
|
||||
channel_name = :channel_name,
|
||||
company_name = :company_name,
|
||||
company_name2 = :company_name2,
|
||||
company_logo = :company_logo,
|
||||
company_seal = :company_seal,
|
||||
branch = :branch,
|
||||
branch_no = :branch_no,
|
||||
fiscal_year = :fiscal_year,
|
||||
fx = :fx,
|
||||
address = :address,
|
||||
address2 = :address2,
|
||||
tax_id = :tax_id,
|
||||
prompt_pay = :prompt_pay,
|
||||
entrepreneur = :entrepreneur,
|
||||
email = :email,
|
||||
phone = :phone,
|
||||
fax = :fax,
|
||||
website = :website,
|
||||
facebook_page = :facebook_page
|
||||
WHERE company_id = :company_id
|
||||
");
|
||||
|
||||
$sth->execute([
|
||||
':channel_name' => $channel,
|
||||
':company_name' => trim($data['company_name'] ?? ''),
|
||||
':company_name2' => trim($data['company_name2'] ?? ''),
|
||||
':company_logo' => $new_logo,
|
||||
':company_seal' => $new_seal,
|
||||
':branch' => trim($data['branch'] ?? 'สำนักงานใหญ่'),
|
||||
':branch_no' => trim($data['branch_no'] ?? ''),
|
||||
':fiscal_year' => trim($data['fiscal_year'] ?? ''),
|
||||
':fx' => trim($data['fx'] ?? 'thb'),
|
||||
':address' => trim($data['address'] ?? ''),
|
||||
':address2' => trim($data['address2'] ?? ''),
|
||||
':tax_id' => trim($data['tax_id'] ?? ''),
|
||||
':prompt_pay' => trim($data['prompt_pay'] ?? ''),
|
||||
':entrepreneur' => trim($data['entrepreneur'] ?? ''),
|
||||
':email' => trim($data['email'] ?? ''),
|
||||
':phone' => trim($data['phone'] ?? ''),
|
||||
':fax' => trim($data['fax'] ?? ''),
|
||||
':website' => trim($data['website'] ?? ''),
|
||||
':facebook_page' => trim($data['facebook_page'] ?? ''),
|
||||
':company_id' => $company_id,
|
||||
]);
|
||||
db_check($sth, $answer);
|
||||
|
||||
$answer['success'] = 1;
|
||||
$answer['message'] = 'Company profile saved.';
|
||||
|
||||
// Return new filenames only if they changed so client can refresh previews
|
||||
if ($logo_action !== 'keep') $answer['company_logo'] = $new_logo;
|
||||
if ($seal_action !== 'keep') $answer['company_seal'] = $new_seal;
|
||||
|
||||
} catch (RuntimeException $e) {
|
||||
$answer['message'] = $e->getMessage();
|
||||
http_response_code(422);
|
||||
} catch (Exception $e) {
|
||||
$answer['message'] = 'Failed to save company profile.';
|
||||
http_response_code(500);
|
||||
}
|
||||
|
||||
exit(json_encode($answer));
|
||||
?>
|
||||
@@ -0,0 +1,75 @@
|
||||
<?php
|
||||
session_start();
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
require '../../../assets/utils/classes/FileUploader.php';
|
||||
|
||||
try {
|
||||
|
||||
// ── Fetch current picture filename from DB ────────────────
|
||||
$sth = $pdo1->prepare(
|
||||
'SELECT profile_picture FROM user WHERE user_id = :user_id LIMIT 1'
|
||||
);
|
||||
$sth->execute([':user_id' => $user_id]);
|
||||
$current_picture = $sth->fetchColumn() ?: '';
|
||||
|
||||
// ── Handle new picture upload ─────────────────────────────
|
||||
$db_picture = $current_picture;
|
||||
|
||||
if (!empty($_FILES['profile_picture']['name'])) {
|
||||
|
||||
// Remove old file if exists
|
||||
if (!empty($current_picture)) {
|
||||
$old_path = $include_url . 'uploads/profile/' . $current_picture;
|
||||
if (file_exists($old_path)) unlink($old_path);
|
||||
}
|
||||
|
||||
$uploader = new FileUploader($include_url . 'uploads/profile/');
|
||||
$errors = $uploader->upload('profile_picture');
|
||||
|
||||
if (!empty($errors)) {
|
||||
$answer['message'] = $errors[0];
|
||||
http_response_code(400);
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
|
||||
$db_picture = $uploader->getUploadedFiles()[0] ?? '';
|
||||
}
|
||||
|
||||
// ── Update user record ────────────────────────────────────
|
||||
$sth = $pdo1->prepare(
|
||||
"UPDATE user SET
|
||||
name = :name,
|
||||
surname = :surname,
|
||||
email = :email,
|
||||
phone = :phone,
|
||||
country = :country,
|
||||
address = :address,
|
||||
profile_picture = :profile_picture
|
||||
WHERE user_id = :user_id"
|
||||
);
|
||||
$sth->execute([
|
||||
':name' => trim($data['name'] ?? ''),
|
||||
':surname' => trim($data['surname'] ?? ''),
|
||||
':email' => trim($data['email'] ?? ''),
|
||||
':phone' => trim($data['phone'] ?? ''),
|
||||
':country' => trim($data['country'] ?? ''),
|
||||
':address' => trim($data['address'] ?? ''),
|
||||
':profile_picture' => $db_picture,
|
||||
':user_id' => $user_id,
|
||||
]);
|
||||
db_check($sth, $answer);
|
||||
|
||||
// ── Refresh session ───────────────────────────────────────
|
||||
$_SESSION['login_name'] = trim($data['name'] ?? '');
|
||||
$_SESSION['login_surname'] = trim($data['surname'] ?? '');
|
||||
|
||||
$answer['success'] = 1;
|
||||
$answer['message'] = 'Profile updated.';
|
||||
$answer['profile_picture'] = $db_picture;
|
||||
|
||||
} catch (Exception $e) {
|
||||
$answer['message'] = 'Failed to update profile.';
|
||||
http_response_code(500);
|
||||
}
|
||||
|
||||
exit(json_encode($answer));
|
||||
@@ -0,0 +1,7 @@
|
||||
<?php
|
||||
session_start();
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
require '../../../assets/utils/classes/PasswordResetManager.php';
|
||||
|
||||
$prm = new PasswordResetManager($pdo1, $pdo2, $include_url, $SMTP, $pinkey);
|
||||
$prm->handleRequestOtp($user_id, $company_id);
|
||||
@@ -0,0 +1,7 @@
|
||||
<?php
|
||||
session_start();
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
require '../../../assets/utils/classes/PasswordResetManager.php';
|
||||
|
||||
$prm = new PasswordResetManager($pdo1, $pdo2, $include_url, $SMTP, $pinkey);
|
||||
$prm->handleConfirmReset($user_id, $data);
|
||||
@@ -0,0 +1,42 @@
|
||||
<?php
|
||||
session_start();
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
|
||||
try {
|
||||
|
||||
$sth = $pdo1->prepare("
|
||||
SELECT
|
||||
company_id, channel_name,
|
||||
company_name, company_name2,
|
||||
company_logo, company_seal,
|
||||
branch, branch_no,
|
||||
fiscal_year, fx,
|
||||
address, address2,
|
||||
tax_id, prompt_pay, entrepreneur,
|
||||
email, phone, fax,
|
||||
website, facebook_page
|
||||
FROM company_list
|
||||
WHERE company_id = :company_id
|
||||
LIMIT 1
|
||||
");
|
||||
$sth->execute([':company_id' => $company_id]);
|
||||
db_check($sth, $answer);
|
||||
|
||||
$company = $sth->fetch(PDO::FETCH_ASSOC);
|
||||
|
||||
if (!$company) {
|
||||
$answer['message'] = 'Company not found.';
|
||||
http_response_code(404);
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
|
||||
$answer['success'] = 1;
|
||||
$answer['output'] = $company;
|
||||
|
||||
} catch (Exception $e) {
|
||||
$answer['message'] = 'Failed to load company profile.';
|
||||
http_response_code(500);
|
||||
}
|
||||
|
||||
exit(json_encode($answer));
|
||||
?>
|
||||
@@ -0,0 +1,33 @@
|
||||
<?php
|
||||
session_start();
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
|
||||
try {
|
||||
|
||||
$sth = $pdo1->prepare(
|
||||
"SELECT user_id, username, name, surname,
|
||||
email, phone, country, address, profile_picture
|
||||
FROM user
|
||||
WHERE user_id = :user_id
|
||||
LIMIT 1"
|
||||
);
|
||||
$sth->execute([':user_id' => $user_id]);
|
||||
db_check($sth, $answer);
|
||||
|
||||
$user = $sth->fetch(PDO::FETCH_ASSOC);
|
||||
|
||||
if (!$user) {
|
||||
$answer['message'] = 'User not found.';
|
||||
http_response_code(404);
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
|
||||
$answer['success'] = 1;
|
||||
$answer['output'] = $user;
|
||||
|
||||
} catch (Exception $e) {
|
||||
$answer['message'] = 'Failed to load profile.';
|
||||
http_response_code(500);
|
||||
}
|
||||
|
||||
exit(json_encode($answer));
|
||||
Reference in New Issue
Block a user