If session_token is set and session_last_seen is within the last hour,
the incoming login is rejected with a clear message. Stale sessions
(idle > 1 h) and explicit logouts (token = NULL via back.php) still allow
re-login normally.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- Upgraded all plain `require` to `require_once` across 172 api/engine
and api/engine_report files to prevent class-redeclaration errors
- Added issue button, issue_invoice() with GL toastr, and delete_invoice()
to expense/manage_purchase_invoice.php, bringing it in line with
po/manage_purchase_invoice.php
- Added can_delete role guard (admin/owner only) to trash icons on
revenue/invoice.php and expense/purchase_invoice.php, matching the
existing pattern in finance/receipt.php and finance/payment.php
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>