5 Commits
Author SHA1 Message Date
Thanakorn f11af6e949 Self-host front-end libraries, minimal sign-in header and CSP
- sign-in pages load only what they use (include_login_header.php, ajax_core.js)
- every library, font and data file served from assets/vendor with pinned
  versions (VERSIONS.json); no CDN at runtime
- Content-Security-Policy on app, sign-in and landing pages
- remove httpbin Dropzone target and source-map references
2026-09-24 14:53:41 +07:00
Thanakorn e579dd596c Start every session through session.php; idle timeout, app access and auth status codes 2026-09-24 14:30:35 +07:00
Thanakorn S 4bb378a905 accounting Reports 2026-05-23 15:07:11 +07:00
Thanakorn S 7396db6ffc accounting workflows 2026-05-20 10:17:02 +07:00
Thanakorn S 04a683bd02 accounting modules 2026-05-13 15:11:24 +07:00