6 Commits
Author SHA1 Message Date
Thanakorn SandClaude Sonnet 4.6 b07882e3f4 code audit fixes: require_once, issue flow, role guards
- Upgraded all plain `require` to `require_once` across 172 api/engine
  and api/engine_report files to prevent class-redeclaration errors
- Added issue button, issue_invoice() with GL toastr, and delete_invoice()
  to expense/manage_purchase_invoice.php, bringing it in line with
  po/manage_purchase_invoice.php
- Added can_delete role guard (admin/owner only) to trash icons on
  revenue/invoice.php and expense/purchase_invoice.php, matching the
  existing pattern in finance/receipt.php and finance/payment.php

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-23 17:06:08 +07:00
Thanakorn S e36d304521 use roles guards 2026-05-22 08:45:35 +07:00
Thanakorn S 7396db6ffc accounting workflows 2026-05-20 10:17:02 +07:00
Thanakorn S a75d37e841 closing security gap [ignore guarding change for now] 2026-05-07 10:29:14 +07:00
Thanakorn S a24930f684 centralize roles guards 2026-05-07 09:26:39 +07:00
Thanakorn S d8c55d278a app settings 2026-04-27 10:50:31 +07:00