0, 'message' => 'ID and action required'])); } // Load current status $sth = $pdo2->prepare("SELECT status FROM ac_quotation WHERE id = :id AND company_id = :cid LIMIT 1"); $sth->execute([':id' => $id, ':cid' => $company_id]); $row = $sth->fetch(PDO::FETCH_ASSOC); if (!$row) { exit(json_encode(['success' => 0, 'message' => 'Not found'])); } $cur = (int)$row['status']; $transitions = [ 'send' => ['from' => [0], 'to' => 1, 'label' => 'Sent'], 'accept' => ['from' => [1], 'to' => 2, 'label' => 'Accepted'], 'reject' => ['from' => [1], 'to' => 3, 'label' => 'Rejected'], 'reopen' => ['from' => [1,2,3],'to' => 0, 'label' => 'Draft'], 'cancel' => ['from' => [0,1], 'to' => -1,'label' => 'Cancelled'], ]; if (!isset($transitions[$action])) { exit(json_encode(['success' => 0, 'message' => 'Invalid action'])); } $t = $transitions[$action]; if (!in_array($cur, $t['from'], true)) { exit(json_encode(['success' => 0, 'message' => 'Transition not allowed from current status'])); } $sth = $pdo2->prepare("UPDATE ac_quotation SET status = :status WHERE id = :id AND company_id = :cid"); $sth->execute([':status' => $t['to'], ':id' => $id, ':cid' => $company_id]); $answer['success'] = 1; $answer['message'] = 'Status updated to ' . $t['label']; exit(json_encode($answer));