Fix timestamps, delete requests, invoice dates and GR quantities
Apply the configured timezone to PHP and both DB connections, wrap unwrapped ajax payloads so delete buttons reach their engines, normalise and validate invoice due dates, reject stock quantities below the stored 4dp scale, and list stock movements across all warehouses.
This commit is contained in:
@@ -134,15 +134,17 @@ if (empty($_SESSION['skip_otp'])) {
|
||||
// An explicit logout clears session_token to NULL, so back.php bypasses this.
|
||||
//
|
||||
// The staleness comparison is done entirely in SQL (session_last_seen vs MySQL's
|
||||
// own NOW()), not in PHP. session_last_seen is written with MySQL's NOW(), and
|
||||
// the MySQL server here runs on Asia/Bangkok time while PHP's default timezone is
|
||||
// UTC (config.php's $time_zone is never applied via date_default_timezone_set()).
|
||||
// Pulling the timestamp into PHP and comparing with strtotime()/time() silently
|
||||
// misreads that Bangkok wall-clock string as UTC — 7 hours in the future — which
|
||||
// made idle_seconds permanently negative and this check block every login,
|
||||
// regardless of window size. Comparing inside MySQL sidesteps the mismatch
|
||||
// without touching PHP's global timezone (which would ripple into every other
|
||||
// date()/time() call in the app).
|
||||
// own NOW()), not in PHP, because session_last_seen is written with MySQL's
|
||||
// NOW() and so is best compared against it.
|
||||
//
|
||||
// This originally worked around a timezone mismatch: config.php's $time_zone was
|
||||
// never applied via date_default_timezone_set(), so PHP ran on UTC while the
|
||||
// MySQL server ran on Asia/Bangkok. Pulling the timestamp into PHP and comparing
|
||||
// with strtotime()/time() misread that Bangkok wall-clock string as UTC — 7 hours
|
||||
// in the future — which made idle_seconds permanently negative and blocked every
|
||||
// login. assets/utils/timezone.php now applies $time_zone to PHP and pins both
|
||||
// PDO connections to the same offset, so the mismatch is gone; comparing in SQL
|
||||
// is kept because it is still the most direct way to read a NOW()-written column.
|
||||
define('SESSION_ACTIVE_GRACE_SECONDS', 120);
|
||||
|
||||
$sth_active = $pdo1->prepare(
|
||||
|
||||
Reference in New Issue
Block a user