Start every session through session.php; idle timeout, app access and auth status codes
This commit is contained in:
@@ -0,0 +1,37 @@
|
||||
<?php
|
||||
/**
|
||||
* app_access.php — which app (WMS / Accounting) a script belongs to, and whether
|
||||
* the signed-in user's app_access allows it.
|
||||
*
|
||||
* app_access used to only choose which menus the topbar drew; a WMS-only user
|
||||
* could still open the accounting pages and call their APIs directly. db_auth.php
|
||||
* (API engines) and include_topbar.php (pages) now both enforce it through here.
|
||||
*/
|
||||
|
||||
// Accounting endpoints the WMS screens also call (master-data lookups, the
|
||||
// batch operation lock, and the GL panel on purchase invoices).
|
||||
const APP_ACCESS_SHARED_ACCOUNTING = [
|
||||
'accounting/api/engine/account.php',
|
||||
'accounting/api/engine/account_formula.php',
|
||||
'accounting/api/engine/department.php',
|
||||
'accounting/api/engine/acquire_op_lock.php',
|
||||
'accounting/api/engine/release_op_lock.php',
|
||||
'accounting/api/engine/get_gl_by_source.php',
|
||||
];
|
||||
|
||||
/** The app a script under app/ belongs to: 'accounting', or null for WMS/shared. */
|
||||
function app_access_app_for(string $script_name): ?string {
|
||||
$path = str_replace('\\', '/', $script_name);
|
||||
$pos = strpos($path, '/app/');
|
||||
if ($pos === false) return null;
|
||||
$rel = substr($path, $pos + 5);
|
||||
|
||||
if (in_array($rel, APP_ACCESS_SHARED_ACCOUNTING, true)) return null;
|
||||
if (preg_match('#^(accounting|ac_dashboard|revenue|expense|finance|journal)/#', $rel)) return 'accounting';
|
||||
return null;
|
||||
}
|
||||
|
||||
/** Whether an app_access value ('wms', 'accounting', 'all') includes $app. */
|
||||
function app_access_allows(string $access, string $app): bool {
|
||||
return $access === 'all' || $access === $app;
|
||||
}
|
||||
Reference in New Issue
Block a user