Compare commits
4
Commits
6765054950
...
2f290ddb26
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
2f290ddb26 | ||
|
|
5d021d7683 | ||
|
|
5ee0c8d41b | ||
|
|
c3113bc70d |
@@ -99,7 +99,7 @@ class CompanyProfileManager
|
|||||||
|
|
||||||
public function saveProfile(array $data, string $company_logo, string $company_seal): void
|
public function saveProfile(array $data, string $company_logo, string $company_seal): void
|
||||||
{
|
{
|
||||||
$channel = strtolower(preg_replace('/[^a-z0-9\-_]/', '', $data['channel_name'] ?? ''));
|
$channel = preg_replace('/[^a-z0-9\-_]/', '', strtolower(trim($data['channel_name'] ?? '')));
|
||||||
|
|
||||||
$sth = $this->pdo->prepare(
|
$sth = $this->pdo->prepare(
|
||||||
"UPDATE company_list SET
|
"UPDATE company_list SET
|
||||||
|
|||||||
@@ -27,6 +27,11 @@ class db_statement extends PDOStatement {
|
|||||||
$this->pdo = $pdo;
|
$this->pdo = $pdo;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// PDOStatement::execute() is declared ?array $params = null : bool. This
|
||||||
|
// override deliberately accepts a looser signature so callers may pass
|
||||||
|
// positional arguments (see func_get_args() below), so the tightened return
|
||||||
|
// type is opted out of rather than the call sites being changed.
|
||||||
|
#[\ReturnTypeWillChange]
|
||||||
public function execute($args = null) {
|
public function execute($args = null) {
|
||||||
// Perform logging here. PDO object is accessible
|
// Perform logging here. PDO object is accessible
|
||||||
// from $this->pdo.
|
// from $this->pdo.
|
||||||
|
|||||||
@@ -1,4 +1,23 @@
|
|||||||
<?php
|
<?php
|
||||||
|
// Output buffering must be active before the first byte of HTML below, so that
|
||||||
|
// header() calls made later in the page still work — notably the
|
||||||
|
// not-logged-in redirect in include_topbar.php, which runs *after* this file
|
||||||
|
// has already emitted <!DOCTYPE html>. Without a buffer that redirect depends
|
||||||
|
// entirely on php.ini's output_buffering: it is on for the dev stack but off
|
||||||
|
// in production, where every protected page answered 200 with a half-rendered
|
||||||
|
// body instead of sending the browser to the login form. session.php starts a
|
||||||
|
// buffer for the same reason.
|
||||||
|
if (ob_get_level() === 0) {
|
||||||
|
ob_start();
|
||||||
|
}
|
||||||
|
|
||||||
|
// Never render PHP notices/warnings into the page: they leak absolute server
|
||||||
|
// paths to anonymous visitors and corrupt the markup. Errors still reach the
|
||||||
|
// server log. This mirrors the policy db_auth.php already applies to the JSON
|
||||||
|
// API routes, and keeps the app safe even where php.ini has display_errors on.
|
||||||
|
ini_set('display_errors', '0');
|
||||||
|
ini_set('log_errors', '1');
|
||||||
|
|
||||||
// Security headers — emitted before any HTML output.
|
// Security headers — emitted before any HTML output.
|
||||||
header('X-Content-Type-Options: nosniff');
|
header('X-Content-Type-Options: nosniff');
|
||||||
header('X-Frame-Options: SAMEORIGIN');
|
header('X-Frame-Options: SAMEORIGIN');
|
||||||
|
|||||||
@@ -8,6 +8,11 @@ require_once __DIR__ . '/assets/utils/classes/UsageGuard.php';
|
|||||||
// login_company_id is only written by login_confirm.php after OTP is verified —
|
// login_company_id is only written by login_confirm.php after OTP is verified —
|
||||||
// using it (not "otp") ensures half-logged-in sessions are also redirected.
|
// using it (not "otp") ensures half-logged-in sessions are also redirected.
|
||||||
if(empty($_SESSION["login_company_id"])){
|
if(empty($_SESSION["login_company_id"])){
|
||||||
|
// Discard the markup include_header.php has already buffered so the browser
|
||||||
|
// receives a clean redirect rather than a partially rendered page body.
|
||||||
|
while (ob_get_level() > 0) {
|
||||||
|
ob_end_clean();
|
||||||
|
}
|
||||||
header('Location: '.$server_url.'login/index.php');
|
header('Location: '.$server_url.'login/index.php');
|
||||||
exit;
|
exit;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -97,9 +97,9 @@ try {
|
|||||||
$company_name = trim($data['company_name'] ?? '');
|
$company_name = trim($data['company_name'] ?? '');
|
||||||
$company_name2 = trim($data['company_name2'] ?? '');
|
$company_name2 = trim($data['company_name2'] ?? '');
|
||||||
|
|
||||||
// channel_name is the URL slug / identifier — strip everything except
|
// channel_name is the URL slug / identifier — lowercase first, then strip
|
||||||
// lowercase letters, digits, hyphens, and underscores.
|
// everything except lowercase letters, digits, hyphens, and underscores.
|
||||||
$channel_name = strtolower(preg_replace('/[^a-z0-9\-_]/', '', $data['channel_name'] ?? ''));
|
$channel_name = preg_replace('/[^a-z0-9\-_]/', '', strtolower(trim($data['channel_name'] ?? '')));
|
||||||
|
|
||||||
$branch = trim($data['branch'] ?? 'สำนักงานใหญ่');
|
$branch = trim($data['branch'] ?? 'สำนักงานใหญ่');
|
||||||
$branch_no = trim($data['branch_no'] ?? '00000');
|
$branch_no = trim($data['branch_no'] ?? '00000');
|
||||||
|
|||||||
@@ -48,7 +48,8 @@
|
|||||||
</div>
|
</div>
|
||||||
<div class="col-md-6">
|
<div class="col-md-6">
|
||||||
<label class="form-label">Channel Name <span class="text-danger">*</span></label>
|
<label class="form-label">Channel Name <span class="text-danger">*</span></label>
|
||||||
<input type="text" class="form-control" id="channel_name" placeholder="e.g. my-shop">
|
<input type="text" class="form-control" id="channel_name" placeholder="e.g. my-shop"
|
||||||
|
oninput="this.value=this.value.toLowerCase().replace(/[^a-z0-9_-]/g,'')">
|
||||||
<div class="form-text">Unique identifier. Lowercase, no spaces.</div>
|
<div class="form-text">Unique identifier. Lowercase, no spaces.</div>
|
||||||
</div>
|
</div>
|
||||||
<div class="col-md-3">
|
<div class="col-md-3">
|
||||||
|
|||||||
@@ -2,6 +2,12 @@
|
|||||||
// app/session.php
|
// app/session.php
|
||||||
ob_start(); // ensure output buffering is on regardless of php.ini — prevents stray output from corrupting JSON API responses
|
ob_start(); // ensure output buffering is on regardless of php.ini — prevents stray output from corrupting JSON API responses
|
||||||
|
|
||||||
|
// The buffer is still flushed, so notices would still land in front of the JSON
|
||||||
|
// body and break the client's parse ("Server error occurred."). The login API
|
||||||
|
// engines load this file instead of db_auth.php, so apply the same policy here.
|
||||||
|
ini_set('display_errors', '0');
|
||||||
|
ini_set('log_errors', '1');
|
||||||
|
|
||||||
if (session_status() === PHP_SESSION_NONE) {
|
if (session_status() === PHP_SESSION_NONE) {
|
||||||
|
|
||||||
// Derive cookie path dynamically from the current script location.
|
// Derive cookie path dynamically from the current script location.
|
||||||
|
|||||||
@@ -121,7 +121,8 @@
|
|||||||
|
|
||||||
<div class="col-md-6 mb-3">
|
<div class="col-md-6 mb-3">
|
||||||
<label class="form-label">Nickname / Channel Name</label>
|
<label class="form-label">Nickname / Channel Name</label>
|
||||||
<input type="text" class="form-control" id="channel_name" placeholder="e.g. my-shop">
|
<input type="text" class="form-control" id="channel_name" placeholder="e.g. my-shop"
|
||||||
|
oninput="this.value=this.value.toLowerCase().replace(/[^a-z0-9_-]/g,'')">
|
||||||
<div class="form-text">Unique identifier. Lowercase, no spaces.</div>
|
<div class="form-text">Unique identifier. Lowercase, no spaces.</div>
|
||||||
</div>
|
</div>
|
||||||
<div class="col-md-3 mb-3">
|
<div class="col-md-3 mb-3">
|
||||||
|
|||||||
Reference in New Issue
Block a user