Login , Register ,and onboarding
This commit is contained in:
@@ -0,0 +1,144 @@
|
||||
<?php
|
||||
session_start();
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
|
||||
// ─── Role guard: only owner/admin ────────────────────────────────────────
|
||||
$sth = $pdo1->prepare("
|
||||
SELECT role FROM company_map_user
|
||||
WHERE company_id = :company_id AND user_id = :user_id
|
||||
LIMIT 1
|
||||
");
|
||||
$sth->execute([':company_id' => $company_id, ':user_id' => $user_id]);
|
||||
db_check($sth, $answer);
|
||||
|
||||
if (!in_array($sth->fetchColumn(), ['owner', 'admin'], true)) {
|
||||
$answer['message'] = 'You do not have permission to change SMTP settings.';
|
||||
http_response_code(403);
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
|
||||
// ─── Encrypt password — same method/key/iv as config.php ─────────────────
|
||||
function encrypt_password(string $plain): string {
|
||||
global $pinkey, $method, $iv;
|
||||
return openssl_encrypt($plain, $method, $pinkey, 0, $iv);
|
||||
}
|
||||
|
||||
try {
|
||||
|
||||
$server = trim($data['smtp_host'] ?? '');
|
||||
$port = trim($data['smtp_port'] ?? '587');
|
||||
$username = trim($data['smtp_username'] ?? '');
|
||||
$raw_pass = $data['smtp_password'] ?? ''; // blank = keep current
|
||||
$from_name = trim($data['smtp_from_name'] ?? '');
|
||||
$from_email = trim($data['smtp_from_email'] ?? '');
|
||||
$encryption = trim($data['smtp_encryption'] ?? 'tls');
|
||||
|
||||
if (!$server || !$username) {
|
||||
$answer['message'] = 'SMTP host and username are required.';
|
||||
http_response_code(422);
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
|
||||
if (!in_array($port, ['25', '465', '587'], true)) $port = '587';
|
||||
if (!in_array($encryption, ['tls', 'ssl', 'none'], true)) $encryption = 'tls';
|
||||
|
||||
// Check if row already exists (uses pdo1 — company_smtp lives in wms2)
|
||||
$sth = $pdo1->prepare("
|
||||
SELECT smtp_id FROM company_smtp
|
||||
WHERE company_id = :company_id LIMIT 1
|
||||
");
|
||||
$sth->execute([':company_id' => $company_id]);
|
||||
db_check($sth, $answer);
|
||||
$existing_id = $sth->fetchColumn();
|
||||
|
||||
if ($existing_id) {
|
||||
|
||||
if ($raw_pass !== '') {
|
||||
$sth = $pdo1->prepare("
|
||||
UPDATE company_smtp SET
|
||||
server = :server,
|
||||
port = :port,
|
||||
username = :username,
|
||||
password = :password,
|
||||
from_name = :from_name,
|
||||
from_email = :from_email,
|
||||
encryption = :encryption,
|
||||
updated_at = NOW()
|
||||
WHERE smtp_id = :smtp_id
|
||||
");
|
||||
$sth->execute([
|
||||
':server' => $server,
|
||||
':port' => $port,
|
||||
':username' => $username,
|
||||
':password' => encrypt_password($raw_pass),
|
||||
':from_name' => $from_name,
|
||||
':from_email' => $from_email,
|
||||
':encryption' => $encryption,
|
||||
':smtp_id' => $existing_id,
|
||||
]);
|
||||
} else {
|
||||
// Keep existing password — don't touch it
|
||||
$sth = $pdo1->prepare("
|
||||
UPDATE company_smtp SET
|
||||
server = :server,
|
||||
port = :port,
|
||||
username = :username,
|
||||
from_name = :from_name,
|
||||
from_email = :from_email,
|
||||
encryption = :encryption,
|
||||
updated_at = NOW()
|
||||
WHERE smtp_id = :smtp_id
|
||||
");
|
||||
$sth->execute([
|
||||
':server' => $server,
|
||||
':port' => $port,
|
||||
':username' => $username,
|
||||
':from_name' => $from_name,
|
||||
':from_email' => $from_email,
|
||||
':encryption' => $encryption,
|
||||
':smtp_id' => $existing_id,
|
||||
]);
|
||||
}
|
||||
|
||||
} else {
|
||||
|
||||
// New record — password required
|
||||
if ($raw_pass === '') {
|
||||
$answer['message'] = 'Password is required for a new SMTP configuration.';
|
||||
http_response_code(422);
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
|
||||
$sth = $pdo1->prepare("
|
||||
INSERT INTO company_smtp
|
||||
(company_id, server, port, username, password,
|
||||
from_name, from_email, encryption, updated_at)
|
||||
VALUES
|
||||
(:company_id, :server, :port, :username, :password,
|
||||
:from_name, :from_email, :encryption, NOW())
|
||||
");
|
||||
$sth->execute([
|
||||
':company_id' => $company_id,
|
||||
':server' => $server,
|
||||
':port' => $port,
|
||||
':username' => $username,
|
||||
':password' => encrypt_password($raw_pass),
|
||||
':from_name' => $from_name,
|
||||
':from_email' => $from_email,
|
||||
':encryption' => $encryption,
|
||||
]);
|
||||
|
||||
}
|
||||
|
||||
db_check($sth, $answer);
|
||||
|
||||
$answer['success'] = 1;
|
||||
$answer['message'] = 'SMTP settings saved.';
|
||||
|
||||
} catch (Exception $e) {
|
||||
$answer['message'] = 'Failed to save SMTP settings.';
|
||||
http_response_code(500);
|
||||
}
|
||||
|
||||
exit(json_encode($answer));
|
||||
?>
|
||||
@@ -0,0 +1,214 @@
|
||||
<?php
|
||||
session_start();
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
|
||||
// ─── Role guard: only owner/admin can manage users ────────────────────────
|
||||
$sth = $pdo1->prepare("
|
||||
SELECT role FROM company_map_user
|
||||
WHERE company_id = :company_id AND user_id = :user_id
|
||||
LIMIT 1
|
||||
");
|
||||
$sth->execute([':company_id' => $company_id, ':user_id' => $user_id]);
|
||||
db_check($sth, $answer);
|
||||
$caller_role = $sth->fetchColumn();
|
||||
|
||||
if (!in_array($caller_role, ['owner', 'admin'], true)) {
|
||||
$answer['message'] = 'You do not have permission to manage users.';
|
||||
http_response_code(403);
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
|
||||
$action = $data['action'] ?? '';
|
||||
|
||||
try {
|
||||
|
||||
// ══════════════════════════════════════════════════════════════════════
|
||||
// CREATE — invite a user by email
|
||||
// ══════════════════════════════════════════════════════════════════════
|
||||
if ($action === 'create') {
|
||||
|
||||
$invite_email = strtolower(trim($data['invite_email'] ?? ''));
|
||||
$invite_role = trim($data['invite_role'] ?? '');
|
||||
|
||||
if (!filter_var($invite_email, FILTER_VALIDATE_EMAIL)) {
|
||||
$answer['message'] = 'Invalid email address.';
|
||||
http_response_code(422);
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
|
||||
$allowed_roles = ['admin', 'staff', 'viewer'];
|
||||
if (!in_array($invite_role, $allowed_roles, true)) {
|
||||
$answer['message'] = 'Invalid role selected.';
|
||||
http_response_code(422);
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
|
||||
// Look up user by email
|
||||
$sth = $pdo1->prepare("SELECT user_id, email FROM user WHERE email = :email LIMIT 1");
|
||||
$sth->execute([':email' => $invite_email]);
|
||||
db_check($sth, $answer);
|
||||
$target = $sth->fetch(PDO::FETCH_ASSOC);
|
||||
|
||||
if (!$target) {
|
||||
$answer['message'] = 'No registered account found with that email address.';
|
||||
http_response_code(404);
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
|
||||
$target_user_id = (int)$target['user_id'];
|
||||
|
||||
// Prevent inviting self
|
||||
if ($target_user_id === (int)$user_id) {
|
||||
$answer['message'] = 'You cannot invite yourself.';
|
||||
http_response_code(422);
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
|
||||
// Check if already mapped to this company
|
||||
$sth = $pdo1->prepare("
|
||||
SELECT map_id FROM company_map_user
|
||||
WHERE company_id = :company_id AND user_id = :user_id
|
||||
LIMIT 1
|
||||
");
|
||||
$sth->execute([':company_id' => $company_id, ':user_id' => $target_user_id]);
|
||||
db_check($sth, $answer);
|
||||
$existing = $sth->fetch(PDO::FETCH_ASSOC);
|
||||
|
||||
if ($existing) {
|
||||
$answer['message'] = 'This user is already a member of your company.';
|
||||
http_response_code(409);
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
|
||||
$sth = $pdo1->prepare("
|
||||
INSERT INTO company_map_user
|
||||
(company_id, user_id, role, created_at)
|
||||
VALUES
|
||||
(:company_id, :user_id, :role, NOW())
|
||||
");
|
||||
$sth->execute([
|
||||
':company_id' => $company_id,
|
||||
':user_id' => $target_user_id,
|
||||
':role' => $invite_role,
|
||||
]);
|
||||
db_check($sth, $answer);
|
||||
|
||||
$answer['success'] = 1;
|
||||
$answer['message'] = htmlspecialchars($target['email']) . ' has been added to your company.';
|
||||
|
||||
|
||||
// ══════════════════════════════════════════════════════════════════════
|
||||
// UPDATE — change a user's role
|
||||
// ══════════════════════════════════════════════════════════════════════
|
||||
} elseif ($action === 'update') {
|
||||
|
||||
$map_id = (int)($data['map_id'] ?? 0);
|
||||
$new_role = trim($data['role'] ?? '');
|
||||
|
||||
$allowed_roles = ['admin', 'staff', 'viewer'];
|
||||
if (!$map_id || !in_array($new_role, $allowed_roles, true)) {
|
||||
$answer['message'] = 'Invalid request.';
|
||||
http_response_code(422);
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
|
||||
// Verify map belongs to this company and is not the owner
|
||||
$sth = $pdo1->prepare("
|
||||
SELECT role FROM company_map_user
|
||||
WHERE map_id = :map_id AND company_id = :company_id
|
||||
LIMIT 1
|
||||
");
|
||||
$sth->execute([':map_id' => $map_id, ':company_id' => $company_id]);
|
||||
db_check($sth, $answer);
|
||||
$target_role = $sth->fetchColumn();
|
||||
|
||||
if ($target_role === false) {
|
||||
$answer['message'] = 'User not found.';
|
||||
http_response_code(404);
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
if ($target_role === 'owner') {
|
||||
$answer['message'] = 'Owner role cannot be changed.';
|
||||
http_response_code(403);
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
|
||||
$sth = $pdo1->prepare("
|
||||
UPDATE company_map_user
|
||||
SET role = :role
|
||||
WHERE map_id = :map_id AND company_id = :company_id
|
||||
");
|
||||
$sth->execute([
|
||||
':role' => $new_role,
|
||||
':map_id' => $map_id,
|
||||
':company_id' => $company_id,
|
||||
]);
|
||||
db_check($sth, $answer);
|
||||
|
||||
$answer['success'] = 1;
|
||||
$answer['message'] = 'Role updated successfully.';
|
||||
|
||||
|
||||
// ══════════════════════════════════════════════════════════════════════
|
||||
// DELETE — remove user from company
|
||||
// ══════════════════════════════════════════════════════════════════════
|
||||
} elseif ($action === 'delete') {
|
||||
|
||||
$map_id = (int)($data['map_id'] ?? 0);
|
||||
if (!$map_id) {
|
||||
$answer['message'] = 'Invalid request.';
|
||||
http_response_code(422);
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
|
||||
// Verify map belongs to this company, and isn't the owner
|
||||
$sth = $pdo1->prepare("
|
||||
SELECT role, user_id FROM company_map_user
|
||||
WHERE map_id = :map_id AND company_id = :company_id
|
||||
LIMIT 1
|
||||
");
|
||||
$sth->execute([':map_id' => $map_id, ':company_id' => $company_id]);
|
||||
db_check($sth, $answer);
|
||||
$row = $sth->fetch(PDO::FETCH_ASSOC);
|
||||
|
||||
if (!$row) {
|
||||
$answer['message'] = 'User not found.';
|
||||
http_response_code(404);
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
if ($row['role'] === 'owner') {
|
||||
$answer['message'] = 'The owner cannot be removed.';
|
||||
http_response_code(403);
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
// Prevent removing yourself
|
||||
if ((int)$row['user_id'] === (int)$user_id) {
|
||||
$answer['message'] = 'You cannot remove yourself.';
|
||||
http_response_code(403);
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
|
||||
// Hard delete — just remove the row
|
||||
$sth = $pdo1->prepare("
|
||||
DELETE FROM company_map_user
|
||||
WHERE map_id = :map_id AND company_id = :company_id
|
||||
");
|
||||
$sth->execute([':map_id' => $map_id, ':company_id' => $company_id]);
|
||||
db_check($sth, $answer);
|
||||
|
||||
$answer['success'] = 1;
|
||||
$answer['message'] = 'User has been removed from this company.';
|
||||
|
||||
|
||||
} else {
|
||||
$answer['message'] = 'Unknown action.';
|
||||
http_response_code(400);
|
||||
}
|
||||
|
||||
} catch (Exception $e) {
|
||||
$answer['message'] = 'An error occurred. Please try again.';
|
||||
http_response_code(500);
|
||||
}
|
||||
|
||||
exit(json_encode($answer));
|
||||
?>
|
||||
@@ -0,0 +1,33 @@
|
||||
<?php
|
||||
session_start();
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
|
||||
try {
|
||||
|
||||
$sth = $pdo1->prepare("
|
||||
SELECT
|
||||
server,
|
||||
port,
|
||||
username,
|
||||
from_name,
|
||||
from_email,
|
||||
encryption
|
||||
FROM company_smtp
|
||||
WHERE company_id = :company_id
|
||||
LIMIT 1
|
||||
");
|
||||
$sth->execute([':company_id' => $company_id]);
|
||||
db_check($sth, $answer);
|
||||
|
||||
$row = $sth->fetch(PDO::FETCH_ASSOC);
|
||||
|
||||
$answer['success'] = 1;
|
||||
$answer['output'] = $row ?: null; // null = not configured yet
|
||||
|
||||
} catch (Exception $e) {
|
||||
$answer['message'] = $e->getMessage();
|
||||
http_response_code(500);
|
||||
}
|
||||
|
||||
exit(json_encode($answer));
|
||||
?>
|
||||
@@ -0,0 +1,38 @@
|
||||
<?php
|
||||
session_start();
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
|
||||
try {
|
||||
|
||||
// Fetch all users mapped to this company, joined with user profile
|
||||
$sth = $pdo1->prepare("
|
||||
SELECT
|
||||
m.map_id,
|
||||
m.role,
|
||||
m.created_at,
|
||||
u.user_id,
|
||||
u.username,
|
||||
u.name,
|
||||
u.surname,
|
||||
u.email,
|
||||
u.profile_picture
|
||||
FROM company_map_user m
|
||||
JOIN user u ON u.user_id = m.user_id
|
||||
WHERE m.company_id = :company_id
|
||||
ORDER BY
|
||||
FIELD(m.role, 'owner', 'admin', 'staff', 'viewer'),
|
||||
u.name ASC
|
||||
");
|
||||
$sth->execute([':company_id' => $company_id]);
|
||||
db_check($sth, $answer);
|
||||
|
||||
$answer['success'] = 1;
|
||||
$answer['output'] = $sth->fetchAll(PDO::FETCH_ASSOC);
|
||||
|
||||
} catch (Exception $e) {
|
||||
$answer['message'] = 'Failed to load users.';
|
||||
http_response_code(500);
|
||||
}
|
||||
|
||||
exit(json_encode($answer));
|
||||
?>
|
||||
@@ -0,0 +1,50 @@
|
||||
<?php
|
||||
session_start();
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
|
||||
try {
|
||||
|
||||
$keyword = trim($data['keyword'] ?? '');
|
||||
|
||||
if ($keyword === '') {
|
||||
$answer['success'] = 1;
|
||||
$answer['result'] = [];
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
|
||||
$like = '%' . $keyword . '%';
|
||||
|
||||
// Search users by email NOT already active/pending in this company
|
||||
$sth = $pdo1->prepare("
|
||||
SELECT
|
||||
u.user_id,
|
||||
u.username,
|
||||
u.name,
|
||||
u.surname,
|
||||
u.email
|
||||
FROM user u
|
||||
WHERE
|
||||
u.email LIKE :kw
|
||||
AND u.user_id NOT IN (
|
||||
SELECT user_id FROM company_map_user
|
||||
WHERE company_id = :company_id
|
||||
)
|
||||
ORDER BY u.email ASC
|
||||
LIMIT 10
|
||||
");
|
||||
$sth->execute([
|
||||
':kw' => $like,
|
||||
':company_id' => $company_id,
|
||||
]);
|
||||
db_check($sth, $answer);
|
||||
|
||||
$answer['success'] = 1;
|
||||
$answer['result'] = $sth->fetchAll(PDO::FETCH_ASSOC);
|
||||
|
||||
} catch (Exception $e) {
|
||||
$answer['message'] = 'Search failed.';
|
||||
http_response_code(500);
|
||||
}
|
||||
|
||||
exit(json_encode($answer));
|
||||
?>
|
||||
@@ -0,0 +1,55 @@
|
||||
<?php
|
||||
session_start();
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
|
||||
try {
|
||||
|
||||
$to = trim($data['test_email'] ?? '');
|
||||
|
||||
if (!filter_var($to, FILTER_VALIDATE_EMAIL)) {
|
||||
$answer['message'] = 'Invalid recipient email address.';
|
||||
http_response_code(422);
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
|
||||
// Fetch from_name / channel_name for the sender display
|
||||
$sth = $pdo1->prepare("
|
||||
SELECT from_name FROM company_smtp
|
||||
WHERE company_id = :company_id LIMIT 1
|
||||
");
|
||||
$sth->execute([':company_id' => $company_id]);
|
||||
db_check($sth, $answer);
|
||||
$row = $sth->fetch(PDO::FETCH_ASSOC);
|
||||
|
||||
if (!$row) {
|
||||
$answer['message'] = 'No SMTP configuration found. Please save your settings first.';
|
||||
http_response_code(422);
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
|
||||
$channel_name = $row['from_name'] ?: 'WMS System';
|
||||
|
||||
// Use existing mailer — it reads company_smtp via pdo1 automatically
|
||||
require_once $include_url . 'assets/utils/module/mailer.php';
|
||||
|
||||
$mailer = new mailer(['pdo1' => $pdo1]);
|
||||
$mailer->send_email([
|
||||
'company_id' => $company_id,
|
||||
'smtp' => [], // empty = mailer reads from company_smtp
|
||||
'to' => $to,
|
||||
'subject' => 'SMTP Test — WMS',
|
||||
'message' => "This is a test email from your WMS SMTP configuration.\n\nIf you received this, your SMTP settings are working correctly.",
|
||||
'channel_name' => $channel_name,
|
||||
'key' => $pinkey,
|
||||
]);
|
||||
|
||||
$answer['success'] = 1;
|
||||
$answer['message'] = 'Test email sent to ' . htmlspecialchars($to) . '.';
|
||||
|
||||
} catch (Exception $e) {
|
||||
$answer['message'] = 'Failed to send test email: ' . $e->getMessage();
|
||||
http_response_code(500);
|
||||
}
|
||||
|
||||
exit(json_encode($answer));
|
||||
?>
|
||||
Reference in New Issue
Block a user