app settings

This commit is contained in:
Thanakorn S
2026-04-27 10:50:31 +07:00
parent 76b9b2a2cb
commit d8c55d278a
3128 changed files with 630683 additions and 138 deletions
+164
View File
@@ -0,0 +1,164 @@
<?php
session_start();
require '../../../assets/utils/db_auth.php';
require '../../../assets/utils/classes/FileUploader.php';
// ─── Allowed upload MIME types ────────────────────────────────────────────
const ALLOWED_MIME = ['image/jpeg', 'image/png', 'image/gif', 'image/webp'];
const MAX_SIZE = 2 * 1024 * 1024; // 2 MB
// ─── Helper: handle one image slot ────────────────────────────────────────
function handle_image_slot(
string $slot, // 'company_logo' | 'company_seal'
string $action, // 'keep' | 'replace' | 'remove'
string $current, // current filename from DB
string $upload_dir, // absolute path to uploads/company/
string $prefix // filename prefix 'logo_' | 'seal_'
): ?string {
// 'keep' → return current unchanged
if ($action === 'keep') return $current;
// 'remove' → delete file, return ''
if ($action === 'remove') {
if ($current && file_exists($upload_dir . $current)) {
unlink($upload_dir . $current);
}
return '';
}
// 'replace' → validate + save new file
if ($action === 'replace' && !empty($_FILES[$slot]['tmp_name'])) {
$file = $_FILES[$slot];
if ($file['error'] !== UPLOAD_ERR_OK) {
throw new RuntimeException("Upload error on {$slot}: code {$file['error']}.");
}
if ($file['size'] > MAX_SIZE) {
throw new RuntimeException('File too large. Maximum size is 2 MB.');
}
$finfo = finfo_open(FILEINFO_MIME_TYPE);
$mime = finfo_file($finfo, $file['tmp_name']);
finfo_close($finfo);
if (!in_array($mime, ALLOWED_MIME, true)) {
throw new RuntimeException('Invalid file type. Only JPEG, PNG, GIF, WEBP allowed.');
}
// Delete old file first
if ($current && file_exists($upload_dir . $current)) {
unlink($upload_dir . $current);
}
$ext = pathinfo($file['name'], PATHINFO_EXTENSION);
$filename = $prefix . uniqid() . '.' . strtolower($ext);
if (!move_uploaded_file($file['tmp_name'], $upload_dir . $filename)) {
throw new RuntimeException("Failed to save {$slot}.");
}
return $filename;
}
return $current; // fallback
}
try {
// ── Fetch current image filenames from DB ─────────────────────────────
$sth = $pdo1->prepare(
'SELECT company_logo, company_seal FROM company_list WHERE company_id = :id LIMIT 1'
);
$sth->execute([':id' => $company_id]);
db_check($sth, $answer);
$current = $sth->fetch(PDO::FETCH_ASSOC);
if (!$current) {
$answer['message'] = 'Company not found.';
http_response_code(404);
exit(json_encode($answer));
}
// ── Upload directory ──────────────────────────────────────────────────
$upload_dir = $include_url . 'uploads/company/';
if (!is_dir($upload_dir)) {
mkdir($upload_dir, 0755, true);
}
// ── Process images ────────────────────────────────────────────────────
$logo_action = $data['logo_action'] ?? 'keep';
$seal_action = $data['seal_action'] ?? 'keep';
$new_logo = handle_image_slot('company_logo', $logo_action, $current['company_logo'] ?? '', $upload_dir, 'logo_');
$new_seal = handle_image_slot('company_seal', $seal_action, $current['company_seal'] ?? '', $upload_dir, 'seal_');
// ── Text field sanitisation ───────────────────────────────────────────
$channel = strtolower(preg_replace('/[^a-z0-9\-_]/', '', $data['channel_name'] ?? ''));
// ── UPDATE company_list ───────────────────────────────────────────────
$sth = $pdo1->prepare("
UPDATE company_list SET
channel_name = :channel_name,
company_name = :company_name,
company_name2 = :company_name2,
company_logo = :company_logo,
company_seal = :company_seal,
branch = :branch,
branch_no = :branch_no,
fiscal_year = :fiscal_year,
fx = :fx,
address = :address,
address2 = :address2,
tax_id = :tax_id,
prompt_pay = :prompt_pay,
entrepreneur = :entrepreneur,
email = :email,
phone = :phone,
fax = :fax,
website = :website,
facebook_page = :facebook_page
WHERE company_id = :company_id
");
$sth->execute([
':channel_name' => $channel,
':company_name' => trim($data['company_name'] ?? ''),
':company_name2' => trim($data['company_name2'] ?? ''),
':company_logo' => $new_logo,
':company_seal' => $new_seal,
':branch' => trim($data['branch'] ?? 'สำนักงานใหญ่'),
':branch_no' => trim($data['branch_no'] ?? ''),
':fiscal_year' => trim($data['fiscal_year'] ?? ''),
':fx' => trim($data['fx'] ?? 'thb'),
':address' => trim($data['address'] ?? ''),
':address2' => trim($data['address2'] ?? ''),
':tax_id' => trim($data['tax_id'] ?? ''),
':prompt_pay' => trim($data['prompt_pay'] ?? ''),
':entrepreneur' => trim($data['entrepreneur'] ?? ''),
':email' => trim($data['email'] ?? ''),
':phone' => trim($data['phone'] ?? ''),
':fax' => trim($data['fax'] ?? ''),
':website' => trim($data['website'] ?? ''),
':facebook_page' => trim($data['facebook_page'] ?? ''),
':company_id' => $company_id,
]);
db_check($sth, $answer);
$answer['success'] = 1;
$answer['message'] = 'Company profile saved.';
// Return new filenames only if they changed so client can refresh previews
if ($logo_action !== 'keep') $answer['company_logo'] = $new_logo;
if ($seal_action !== 'keep') $answer['company_seal'] = $new_seal;
} catch (RuntimeException $e) {
$answer['message'] = $e->getMessage();
http_response_code(422);
} catch (Exception $e) {
$answer['message'] = 'Failed to save company profile.';
http_response_code(500);
}
exit(json_encode($answer));
?>