Commit Graph
23 Commits
Author SHA1 Message Date
Thanakorn S 8f57ab5570 Change 'Rack' to 'Bin' 2026-05-27 17:14:53 +07:00
Thanakorn SandClaude Sonnet 4.6 b4b1f5cbec Security hardening: invited user onboarding flow (C1–N7)
- C1: verify.php now filters license='owner' — invite tokens no longer accepted
- C1: onboarding API rejects non-owner sessions
- C2: Existing-user invite requires explicit acceptance via accept_invite.php
- C2: New accept_invite.php page and API engine added
- C2: inviteUser() generates token + expiry for existing users; resendInvite() handles active users
- C3: session_regenerate_id(true) before writing invite session keys on both invite pages
- C4: invited_onboarding API wraps activation in transaction with SELECT FOR UPDATE; rowCount check added; SQLSTATE 23000 caught cleanly
- C5: inviteUser() and resendInvite() two-table writes wrapped in transactions
- M2: removeUser() wrapped in transaction with FOR UPDATE; clears default_company on active user removal
- M4: Logged-in user guard added to invited_onboarding.php and accept_invite.php
- M5: manage_users.php uses $server_url instead of HTTP_HOST for invite URLs
- M6: Username regex enforces 3-32 chars; reserved name blocklist added
- N5: searchUsers() changed from LIKE fuzzy search to exact email match only
- N7: resendInvite() rate-limited to once per 60s via invite_resent_at column
- Schema: company_map_user gains invite_expires_at and invite_resent_at columns

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-26 10:18:40 +07:00
Thanakorn S 4733c78ac6 Close login gap 2026-05-25 15:34:12 +07:00
Thanakorn S ba96de50a1 stock aggregate table 2026-05-25 13:30:10 +07:00
Thanakorn S 293097363b login/ block concurrent login, allow single factor authen for staff and viewer 2026-05-25 09:43:30 +07:00
Thanakorn SandClaude Sonnet 4.6 b07882e3f4 code audit fixes: require_once, issue flow, role guards
- Upgraded all plain `require` to `require_once` across 172 api/engine
  and api/engine_report files to prevent class-redeclaration errors
- Added issue button, issue_invoice() with GL toastr, and delete_invoice()
  to expense/manage_purchase_invoice.php, bringing it in line with
  po/manage_purchase_invoice.php
- Added can_delete role guard (admin/owner only) to trash icons on
  revenue/invoice.php and expense/purchase_invoice.php, matching the
  existing pattern in finance/receipt.php and finance/payment.php

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-23 17:06:08 +07:00
Thanakorn S b76dc679af fix onboarding bugs 2026-05-21 16:51:19 +07:00
Thanakorn S 6eeebfeacb 1) user invitation 2) app access control 3) txn quota guard 2026-05-21 11:42:47 +07:00
Thanakorn S 8ec2e89f79 merge accounting app and solve conflict 2026-05-20 13:22:17 +07:00
Thanakorn S 91f8bb854f review code pattern consistency 2026-05-20 13:07:57 +07:00
Thanakorn S c7b6791e3a revert 2026-05-13 16:22:31 +07:00
Thanakorn S 47ccd7585b debug server error 2026-05-13 16:19:04 +07:00
Thanakorn S 4433ef184e fix registration 2026-05-13 16:15:19 +07:00
Thanakorn S 04a683bd02 accounting modules 2026-05-13 15:11:24 +07:00
Thanakorn S 79e66bd354 add forget password 2026-05-12 17:19:22 +07:00
Thanakorn S 7a87909392 web app security fix 2026-05-11 13:49:44 +07:00
Thanakorn S a75d37e841 closing security gap [ignore guarding change for now] 2026-05-07 10:29:14 +07:00
Thanakorn S 2eb6a1a315 roles guard + docs + logo 2026-05-06 16:37:20 +07:00
Thanakorn S ac4fd9a5ad implement JS password scoring, td_stock approve logicc 2026-04-30 15:14:42 +07:00
Thanakorn S f6dc9a3278 modify classed and comments 2026-04-29 14:21:09 +07:00
Thanakorn S d8fd30c961 Login , Register ,and onboarding 2026-04-28 11:59:49 +07:00
Thanakorn S 7cb78d013b Complete security audit fixes 2026-03-09 14:31:39 +07:00
Thanakorn S 9a50080ae5 init wms 2026-02-19 14:48:40 +07:00