Commit Graph
93 Commits
Author SHA1 Message Date
Thanakorn S bbe89b0380 notify node: userIDguard 2026-05-27 13:12:18 +07:00
Thanakorn S 714b70d552 NODEJS cron fix 2026-05-27 12:05:29 +07:00
Thanakorn S f3c0e3c876 fix NodeJS cron 2026-05-27 11:56:40 +07:00
Thanakorn S a6651c41b9 cron low stock - overdue invoice 2026-05-27 11:45:48 +07:00
Thanakorn S 458a883810 CORS whitelist for NodeJS 2026-05-27 11:26:40 +07:00
Thanakorn S 5221b3a1a1 nodejs status check 2026-05-27 11:18:09 +07:00
Thanakorn S 418dbf9ba6 autostart node process 2026-05-27 11:07:30 +07:00
Thanakorn S 99ae35dc98 all .md reviewed - fix remaining gaps 2026-05-27 10:42:44 +07:00
Thanakorn S 1f371c6f94 add missing roleGuards 2026-05-27 09:19:52 +07:00
Thanakorn SandClaude Sonnet 4.6 d7f104ff25 Stop tracking docs/ — already in .gitignore
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-27 08:15:29 +07:00
Thanakorn SandClaude Sonnet 4.6 dfeb57533a Master data review: spec updates and C1/C2/M3-M6 fixes
Spec (docs/reviewing/master-data.md):
- M1: Remove margin from stored product fields (it's a derived frontend value)
- M2: Clarify posting window only restricts transaction dates, not master data
- M5: Document AccountFormulaManager::delete() as archive, not physical delete

Code:
- C1: Fix CompanySettingManager property typo (company_id → companyId) —
  prevented PHP 8.4 dynamic property fatal on all posting window operations
- C2: Fix WarehouseManager::deleteWarehouse() guard — was comparing
  warehouse_name (string) against warehouse id column (no-op); now correctly
  blocks on storage rows and active stock rows
- M3: Remove hard-delete of td_rack_log in deleteStorage() — retain rack
  history consistent with soft-delete philosophy elsewhere
- M4: Add reference guards to ChartOfAccounts::delete() (blocks on GL items,
  formula items, product account mappings) and DepartmentManager::delete()
  (blocks on GL items)
- M6: Fix CompanySettingManager::handle() partial update — only upsert keys
  present in the request, not all allowed keys defaulted

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-26 17:33:58 +07:00
Thanakorn SandClaude Sonnet 4.6 cb36d3b8fd Document lifecycle review: spec updates and C2/M9 code fixes
Spec (docs/reviewed/document-lifecycle.md):
- C1: Correct GlManager::delete() description — reversal entry, not hard delete
- C3: Clarify PO status 2/3 are derived (receipt_status), never stored
- C4: Add invoice status=2 (Paid/Settled) to status table
- C5: Add full Receipt/Payment Billing Note lifecycle section
- C6: Add Quotation status table and transition rules
- C7: Document soft-delete tombstone mechanism (company_id negation)

Code (InvoiceManager.php):
- C2: voidInvoice() now blocks on active credit notes, posted receipt
  billing notes, and posted payment billing notes in addition to the
  existing receipt/payment checks
- M9: softDelete() skips assertPostingWindow for draft invoices (status=0)
  since drafts have no GL entry and no accounting impact

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-26 16:23:46 +07:00
Thanakorn S 5687b562fb system notification 2026-05-26 13:26:57 +07:00
Thanakorn S d93abb0b81 Seal transaction limit coverage gaps 2026-05-26 13:10:54 +07:00
Thanakorn SandClaude Sonnet 4.6 b4b1f5cbec Security hardening: invited user onboarding flow (C1–N7)
- C1: verify.php now filters license='owner' — invite tokens no longer accepted
- C1: onboarding API rejects non-owner sessions
- C2: Existing-user invite requires explicit acceptance via accept_invite.php
- C2: New accept_invite.php page and API engine added
- C2: inviteUser() generates token + expiry for existing users; resendInvite() handles active users
- C3: session_regenerate_id(true) before writing invite session keys on both invite pages
- C4: invited_onboarding API wraps activation in transaction with SELECT FOR UPDATE; rowCount check added; SQLSTATE 23000 caught cleanly
- C5: inviteUser() and resendInvite() two-table writes wrapped in transactions
- M2: removeUser() wrapped in transaction with FOR UPDATE; clears default_company on active user removal
- M4: Logged-in user guard added to invited_onboarding.php and accept_invite.php
- M5: manage_users.php uses $server_url instead of HTTP_HOST for invite URLs
- M6: Username regex enforces 3-32 chars; reserved name blocklist added
- N5: searchUsers() changed from LIKE fuzzy search to exact email match only
- N7: resendInvite() rate-limited to once per 60s via invite_resent_at column
- Schema: company_map_user gains invite_expires_at and invite_resent_at columns

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-26 10:18:40 +07:00
Thanakorn S 1904fea84c document number sequence 2026-05-26 08:19:40 +07:00
Thanakorn S 4f884177a5 Seal live dashboard event gaps 2026-05-25 17:02:52 +07:00
Thanakorn S 4733c78ac6 Close login gap 2026-05-25 15:34:12 +07:00
Thanakorn S 9b41c0a73a PHP event trigger by NodeJS [stock dashboard] 2026-05-25 14:33:36 +07:00
Thanakorn S ba96de50a1 stock aggregate table 2026-05-25 13:30:10 +07:00
Thanakorn S 293097363b login/ block concurrent login, allow single factor authen for staff and viewer 2026-05-25 09:43:30 +07:00
Thanakorn SandClaude Sonnet 4.6 b07882e3f4 code audit fixes: require_once, issue flow, role guards
- Upgraded all plain `require` to `require_once` across 172 api/engine
  and api/engine_report files to prevent class-redeclaration errors
- Added issue button, issue_invoice() with GL toastr, and delete_invoice()
  to expense/manage_purchase_invoice.php, bringing it in line with
  po/manage_purchase_invoice.php
- Added can_delete role guard (admin/owner only) to trash icons on
  revenue/invoice.php and expense/purchase_invoice.php, matching the
  existing pattern in finance/receipt.php and finance/payment.php

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-23 17:06:08 +07:00
Thanakorn S eddb10aa22 automate and view gl entries 2026-05-23 16:46:35 +07:00
Thanakorn S 363da054e0 batch journal entries 2026-05-23 15:55:22 +07:00
Thanakorn S 65e9c1668d accounting Reports 2026-05-23 15:07:11 +07:00
Thanakorn S f4ef776e9c fix file path 2026-05-23 13:11:22 +07:00
Thanakorn S 59037b5158 fix file path 2026-05-23 13:09:18 +07:00
Thanakorn S f5ea74e134 gl aggregate table (ETL), cronjob by NODEJS 2026-05-23 10:52:27 +07:00
Thanakorn S 9c275eb358 NODE JS introduction: socket polling 2026-05-22 17:01:59 +07:00
Thanakorn S 2410f7bade softDelete features 2026-05-22 14:07:22 +07:00
Thanakorn S f04554793e users app access badge 2026-05-22 13:21:46 +07:00
Thanakorn S ba8e275426 user badge 2026-05-22 10:42:01 +07:00
Thanakorn S e36d304521 use roles guards 2026-05-22 08:45:35 +07:00
Thanakorn S b76dc679af fix onboarding bugs 2026-05-21 16:51:19 +07:00
Thanakorn SandClaude Sonnet 4.6 fdf6292466 add setup.php — one-shot production database setup script
Creates wms + wms2 databases and all 54 tables from scratch using
CREATE TABLE IF NOT EXISTS. Reads credentials from app/config.php.
Safe to re-run (idempotent). CLI-only guard prevents web access.
Dynamic td_stock_<warehouse_id> tables are excluded — the app creates
them automatically on first warehouse use.

Run: php setup.php

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-21 15:21:36 +07:00
Thanakorn SandClaude Sonnet 4.6 94032dd65b fix StockManager lot/serial coercion + add document flow test suite
- StockManager: coerce lot_number/serial_number to trimmed string (fixes
  Array-to-string warnings); validate quantity > 0 on insert; tighten
  transfer pair lookup to match in/out side by column value
- PostingWindowGuard: strip time component from datetime strings before
  date-format validation
- docs/tests/doc_flow_test.php: 32-assertion document flow suite covering
  Stock In create + approve, Sales Order draft/confirm, Invoice from Order
  (with duplicate-block check), PO create/confirm, Quotation create, and
  usage increment wiring check; all 32/32 PASS against wms_codex_test

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-21 14:20:41 +07:00
Thanakorn S 6eeebfeacb 1) user invitation 2) app access control 3) txn quota guard 2026-05-21 11:42:47 +07:00
Thanakorn S 8ec2e89f79 merge accounting app and solve conflict 2026-05-20 13:22:17 +07:00
Thanakorn S 91f8bb854f review code pattern consistency 2026-05-20 13:07:57 +07:00
Thanakorn S 7396db6ffc accounting workflows 2026-05-20 10:17:02 +07:00
Thanakorn S bf3be28f79 JSON output 2026-05-13 16:41:28 +07:00
Thanakorn S 8cf1d9344c fix db_auth 2026-05-13 16:28:38 +07:00
Thanakorn S c7b6791e3a revert 2026-05-13 16:22:31 +07:00
Thanakorn S 47ccd7585b debug server error 2026-05-13 16:19:04 +07:00
Thanakorn S 4433ef184e fix registration 2026-05-13 16:15:19 +07:00
Thanakorn S 04a683bd02 accounting modules 2026-05-13 15:11:24 +07:00
Thanakorn S 511360faa2 dashboart stats: as of date 2026-05-13 09:49:15 +07:00
Thanakorn S 3614b72924 populate test data 2026-05-13 09:28:06 +07:00
Thanakorn S 79e66bd354 add forget password 2026-05-12 17:19:22 +07:00
Thanakorn S 8f1c5c49fd fix onboarding 2026-05-12 17:02:13 +07:00