Commit Graph
9 Commits
Author SHA1 Message Date
nok b2c437426b fix login and configurations 2026-08-03 11:17:41 +07:00
Thanakorn S 8f57ab5570 Change 'Rack' to 'Bin' 2026-05-27 17:14:53 +07:00
Thanakorn SandClaude Sonnet 4.6 b4b1f5cbec Security hardening: invited user onboarding flow (C1–N7)
- C1: verify.php now filters license='owner' — invite tokens no longer accepted
- C1: onboarding API rejects non-owner sessions
- C2: Existing-user invite requires explicit acceptance via accept_invite.php
- C2: New accept_invite.php page and API engine added
- C2: inviteUser() generates token + expiry for existing users; resendInvite() handles active users
- C3: session_regenerate_id(true) before writing invite session keys on both invite pages
- C4: invited_onboarding API wraps activation in transaction with SELECT FOR UPDATE; rowCount check added; SQLSTATE 23000 caught cleanly
- C5: inviteUser() and resendInvite() two-table writes wrapped in transactions
- M2: removeUser() wrapped in transaction with FOR UPDATE; clears default_company on active user removal
- M4: Logged-in user guard added to invited_onboarding.php and accept_invite.php
- M5: manage_users.php uses $server_url instead of HTTP_HOST for invite URLs
- M6: Username regex enforces 3-32 chars; reserved name blocklist added
- N5: searchUsers() changed from LIKE fuzzy search to exact email match only
- N7: resendInvite() rate-limited to once per 60s via invite_resent_at column
- Schema: company_map_user gains invite_expires_at and invite_resent_at columns

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-26 10:18:40 +07:00
Thanakorn S 1904fea84c document number sequence 2026-05-26 08:19:40 +07:00
Thanakorn S ba96de50a1 stock aggregate table 2026-05-25 13:30:10 +07:00
Thanakorn S 293097363b login/ block concurrent login, allow single factor authen for staff and viewer 2026-05-25 09:43:30 +07:00
Thanakorn SandClaude Sonnet 4.6 fdf6292466 add setup.php — one-shot production database setup script
Creates wms + wms2 databases and all 54 tables from scratch using
CREATE TABLE IF NOT EXISTS. Reads credentials from app/config.php.
Safe to re-run (idempotent). CLI-only guard prevents web access.
Dynamic td_stock_<warehouse_id> tables are excluded — the app creates
them automatically on first warehouse use.

Run: php setup.php

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-21 15:21:36 +07:00
Thanakorn S 7396db6ffc accounting workflows 2026-05-20 10:17:02 +07:00
Thanakorn S 836093c0a9 automate setup process 2026-05-12 14:34:55 +07:00