Commit Graph
39 Commits
Author SHA1 Message Date
Thanakorn S a0677d6d8d Classe methods: remove reducdancy 2026-05-29 08:56:58 +07:00
Thanakorn S 9a50238347 Scope stock table access by company warehouses 2026-05-28 15:36:49 +07:00
Thanakorn SandClaude Sonnet 4.6 5df67367fa Fix incomplete Rack→Bin rename: missing file renames, stale UI labels, ReportManager property bug
- Rename rack_log.php → bin_log.php and rack_occupancy.php → bin_occupancy.php
  (occupy_rack.php was already calling bin_*.php, causing 404 on every load)
- Fix occupy_rack.php: page title, stat card label (add id="stat_label_bins"),
  section headings, and <th> column headers still read "Rack/Racks"
- Fix ReportManager: constructor wrote to $this->companyId (dynamic property)
  instead of the declared $this->company_id, causing all queries to filter on
  company_id = 0 under strict PHP 8.2+ property semantics

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-28 09:53:19 +07:00
Thanakorn S 8f57ab5570 Change 'Rack' to 'Bin' 2026-05-27 17:14:53 +07:00
Thanakorn SandClaude Sonnet 4.6 dfeb57533a Master data review: spec updates and C1/C2/M3-M6 fixes
Spec (docs/reviewing/master-data.md):
- M1: Remove margin from stored product fields (it's a derived frontend value)
- M2: Clarify posting window only restricts transaction dates, not master data
- M5: Document AccountFormulaManager::delete() as archive, not physical delete

Code:
- C1: Fix CompanySettingManager property typo (company_id → companyId) —
  prevented PHP 8.4 dynamic property fatal on all posting window operations
- C2: Fix WarehouseManager::deleteWarehouse() guard — was comparing
  warehouse_name (string) against warehouse id column (no-op); now correctly
  blocks on storage rows and active stock rows
- M3: Remove hard-delete of td_rack_log in deleteStorage() — retain rack
  history consistent with soft-delete philosophy elsewhere
- M4: Add reference guards to ChartOfAccounts::delete() (blocks on GL items,
  formula items, product account mappings) and DepartmentManager::delete()
  (blocks on GL items)
- M6: Fix CompanySettingManager::handle() partial update — only upsert keys
  present in the request, not all allowed keys defaulted

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-26 17:33:58 +07:00
Thanakorn SandClaude Sonnet 4.6 cb36d3b8fd Document lifecycle review: spec updates and C2/M9 code fixes
Spec (docs/reviewed/document-lifecycle.md):
- C1: Correct GlManager::delete() description — reversal entry, not hard delete
- C3: Clarify PO status 2/3 are derived (receipt_status), never stored
- C4: Add invoice status=2 (Paid/Settled) to status table
- C5: Add full Receipt/Payment Billing Note lifecycle section
- C6: Add Quotation status table and transition rules
- C7: Document soft-delete tombstone mechanism (company_id negation)

Code (InvoiceManager.php):
- C2: voidInvoice() now blocks on active credit notes, posted receipt
  billing notes, and posted payment billing notes in addition to the
  existing receipt/payment checks
- M9: softDelete() skips assertPostingWindow for draft invoices (status=0)
  since drafts have no GL entry and no accounting impact

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-26 16:23:46 +07:00
Thanakorn SandClaude Sonnet 4.6 b4b1f5cbec Security hardening: invited user onboarding flow (C1–N7)
- C1: verify.php now filters license='owner' — invite tokens no longer accepted
- C1: onboarding API rejects non-owner sessions
- C2: Existing-user invite requires explicit acceptance via accept_invite.php
- C2: New accept_invite.php page and API engine added
- C2: inviteUser() generates token + expiry for existing users; resendInvite() handles active users
- C3: session_regenerate_id(true) before writing invite session keys on both invite pages
- C4: invited_onboarding API wraps activation in transaction with SELECT FOR UPDATE; rowCount check added; SQLSTATE 23000 caught cleanly
- C5: inviteUser() and resendInvite() two-table writes wrapped in transactions
- M2: removeUser() wrapped in transaction with FOR UPDATE; clears default_company on active user removal
- M4: Logged-in user guard added to invited_onboarding.php and accept_invite.php
- M5: manage_users.php uses $server_url instead of HTTP_HOST for invite URLs
- M6: Username regex enforces 3-32 chars; reserved name blocklist added
- N5: searchUsers() changed from LIKE fuzzy search to exact email match only
- N7: resendInvite() rate-limited to once per 60s via invite_resent_at column
- Schema: company_map_user gains invite_expires_at and invite_resent_at columns

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-26 10:18:40 +07:00
Thanakorn S 1904fea84c document number sequence 2026-05-26 08:19:40 +07:00
Thanakorn S 4f884177a5 Seal live dashboard event gaps 2026-05-25 17:02:52 +07:00
Thanakorn S ba96de50a1 stock aggregate table 2026-05-25 13:30:10 +07:00
Thanakorn S 293097363b login/ block concurrent login, allow single factor authen for staff and viewer 2026-05-25 09:43:30 +07:00
Thanakorn S 2410f7bade softDelete features 2026-05-22 14:07:22 +07:00
Thanakorn S e36d304521 use roles guards 2026-05-22 08:45:35 +07:00
Thanakorn SandClaude Sonnet 4.6 94032dd65b fix StockManager lot/serial coercion + add document flow test suite
- StockManager: coerce lot_number/serial_number to trimmed string (fixes
  Array-to-string warnings); validate quantity > 0 on insert; tighten
  transfer pair lookup to match in/out side by column value
- PostingWindowGuard: strip time component from datetime strings before
  date-format validation
- docs/tests/doc_flow_test.php: 32-assertion document flow suite covering
  Stock In create + approve, Sales Order draft/confirm, Invoice from Order
  (with duplicate-block check), PO create/confirm, Quotation create, and
  usage increment wiring check; all 32/32 PASS against wms_codex_test

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-21 14:20:41 +07:00
Thanakorn S 6eeebfeacb 1) user invitation 2) app access control 3) txn quota guard 2026-05-21 11:42:47 +07:00
Thanakorn S 7396db6ffc accounting workflows 2026-05-20 10:17:02 +07:00
Thanakorn S 04a683bd02 accounting modules 2026-05-13 15:11:24 +07:00
Thanakorn S 5c6a478b40 Final prep for production 2026-05-12 13:55:39 +07:00
Thanakorn S adfd5ef017 stockmovement: add summary views 2026-05-11 16:55:23 +07:00
Thanakorn S 304848d3f4 Naming consistance and SESSION issue 2026-05-08 12:04:10 +07:00
Thanakorn S 0d2fa3e3bd encapsulate setting api [OOP] 2026-05-07 08:56:40 +07:00
Thanakorn S 47cc2819d3 encapsulate Barcode Operations [OOP] 2026-05-07 08:41:08 +07:00
Thanakorn S ada701bd53 Barcode Operations 2026-05-06 15:27:52 +07:00
Thanakorn S d8131a01b7 cost/price/margin 2026-05-06 09:37:28 +07:00
Thanakorn S 6501d326ca [test] contact to setting modules 2026-05-06 08:58:09 +07:00
Thanakorn S 414f1cd81d warehouse layers [switchable] 2026-05-04 13:43:32 +07:00
Thanakorn S a90975d9f1 Orders: order, return, invoice 2026-05-02 16:49:21 +07:00
Thanakorn S ac4fd9a5ad implement JS password scoring, td_stock approve logicc 2026-04-30 15:14:42 +07:00
Thanakorn S db5c47b6ca Reports 2026-04-29 17:04:11 +07:00
Thanakorn S f6dc9a3278 modify classed and comments 2026-04-29 14:21:09 +07:00
Thanakorn S 2061624641 [OOP] contact,inventory,ics,dashboard 2026-04-28 15:44:57 +07:00
Thanakorn S 3d3b497c08 ReportManager Class 2026-04-28 14:35:42 +07:00
Thanakorn S d8c55d278a app settings 2026-04-27 10:50:31 +07:00
Thanakorn S 76b9b2a2cb reports 2026-04-25 16:02:55 +07:00
Thanakorn S 3cc5baba3f Lot, Serial, ExpiryDate 2026-04-25 14:37:00 +07:00
Thanakorn S 92d116fd21 remove actions and data integrity 2026-04-24 14:25:39 +07:00
Thanakorn S a75e180686 generic API response + ICS: warehouse_balance md_rack update 2026-04-23 16:06:19 +07:00
Thanakorn S ed23c269ea warehouse capacity and occupancy 2026-04-23 08:24:30 +07:00
Thanakorn S 35dd1a9fce more OOP and restructure utils 2026-04-22 15:55:18 +07:00