Login , Register ,and onboarding
This commit is contained in:
@@ -0,0 +1,144 @@
|
||||
<?php
|
||||
session_start();
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
|
||||
// ─── Role guard: only owner/admin ────────────────────────────────────────
|
||||
$sth = $pdo1->prepare("
|
||||
SELECT role FROM company_map_user
|
||||
WHERE company_id = :company_id AND user_id = :user_id
|
||||
LIMIT 1
|
||||
");
|
||||
$sth->execute([':company_id' => $company_id, ':user_id' => $user_id]);
|
||||
db_check($sth, $answer);
|
||||
|
||||
if (!in_array($sth->fetchColumn(), ['owner', 'admin'], true)) {
|
||||
$answer['message'] = 'You do not have permission to change SMTP settings.';
|
||||
http_response_code(403);
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
|
||||
// ─── Encrypt password — same method/key/iv as config.php ─────────────────
|
||||
function encrypt_password(string $plain): string {
|
||||
global $pinkey, $method, $iv;
|
||||
return openssl_encrypt($plain, $method, $pinkey, 0, $iv);
|
||||
}
|
||||
|
||||
try {
|
||||
|
||||
$server = trim($data['smtp_host'] ?? '');
|
||||
$port = trim($data['smtp_port'] ?? '587');
|
||||
$username = trim($data['smtp_username'] ?? '');
|
||||
$raw_pass = $data['smtp_password'] ?? ''; // blank = keep current
|
||||
$from_name = trim($data['smtp_from_name'] ?? '');
|
||||
$from_email = trim($data['smtp_from_email'] ?? '');
|
||||
$encryption = trim($data['smtp_encryption'] ?? 'tls');
|
||||
|
||||
if (!$server || !$username) {
|
||||
$answer['message'] = 'SMTP host and username are required.';
|
||||
http_response_code(422);
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
|
||||
if (!in_array($port, ['25', '465', '587'], true)) $port = '587';
|
||||
if (!in_array($encryption, ['tls', 'ssl', 'none'], true)) $encryption = 'tls';
|
||||
|
||||
// Check if row already exists (uses pdo1 — company_smtp lives in wms2)
|
||||
$sth = $pdo1->prepare("
|
||||
SELECT smtp_id FROM company_smtp
|
||||
WHERE company_id = :company_id LIMIT 1
|
||||
");
|
||||
$sth->execute([':company_id' => $company_id]);
|
||||
db_check($sth, $answer);
|
||||
$existing_id = $sth->fetchColumn();
|
||||
|
||||
if ($existing_id) {
|
||||
|
||||
if ($raw_pass !== '') {
|
||||
$sth = $pdo1->prepare("
|
||||
UPDATE company_smtp SET
|
||||
server = :server,
|
||||
port = :port,
|
||||
username = :username,
|
||||
password = :password,
|
||||
from_name = :from_name,
|
||||
from_email = :from_email,
|
||||
encryption = :encryption,
|
||||
updated_at = NOW()
|
||||
WHERE smtp_id = :smtp_id
|
||||
");
|
||||
$sth->execute([
|
||||
':server' => $server,
|
||||
':port' => $port,
|
||||
':username' => $username,
|
||||
':password' => encrypt_password($raw_pass),
|
||||
':from_name' => $from_name,
|
||||
':from_email' => $from_email,
|
||||
':encryption' => $encryption,
|
||||
':smtp_id' => $existing_id,
|
||||
]);
|
||||
} else {
|
||||
// Keep existing password — don't touch it
|
||||
$sth = $pdo1->prepare("
|
||||
UPDATE company_smtp SET
|
||||
server = :server,
|
||||
port = :port,
|
||||
username = :username,
|
||||
from_name = :from_name,
|
||||
from_email = :from_email,
|
||||
encryption = :encryption,
|
||||
updated_at = NOW()
|
||||
WHERE smtp_id = :smtp_id
|
||||
");
|
||||
$sth->execute([
|
||||
':server' => $server,
|
||||
':port' => $port,
|
||||
':username' => $username,
|
||||
':from_name' => $from_name,
|
||||
':from_email' => $from_email,
|
||||
':encryption' => $encryption,
|
||||
':smtp_id' => $existing_id,
|
||||
]);
|
||||
}
|
||||
|
||||
} else {
|
||||
|
||||
// New record — password required
|
||||
if ($raw_pass === '') {
|
||||
$answer['message'] = 'Password is required for a new SMTP configuration.';
|
||||
http_response_code(422);
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
|
||||
$sth = $pdo1->prepare("
|
||||
INSERT INTO company_smtp
|
||||
(company_id, server, port, username, password,
|
||||
from_name, from_email, encryption, updated_at)
|
||||
VALUES
|
||||
(:company_id, :server, :port, :username, :password,
|
||||
:from_name, :from_email, :encryption, NOW())
|
||||
");
|
||||
$sth->execute([
|
||||
':company_id' => $company_id,
|
||||
':server' => $server,
|
||||
':port' => $port,
|
||||
':username' => $username,
|
||||
':password' => encrypt_password($raw_pass),
|
||||
':from_name' => $from_name,
|
||||
':from_email' => $from_email,
|
||||
':encryption' => $encryption,
|
||||
]);
|
||||
|
||||
}
|
||||
|
||||
db_check($sth, $answer);
|
||||
|
||||
$answer['success'] = 1;
|
||||
$answer['message'] = 'SMTP settings saved.';
|
||||
|
||||
} catch (Exception $e) {
|
||||
$answer['message'] = 'Failed to save SMTP settings.';
|
||||
http_response_code(500);
|
||||
}
|
||||
|
||||
exit(json_encode($answer));
|
||||
?>
|
||||
Reference in New Issue
Block a user