pdo = $pdo; $this->companyId = $company_id; } public function getProfile(): array { $sth = $this->pdo->prepare( "SELECT company_id, channel_name, company_name, company_name2, company_logo, company_seal, branch, branch_no, fiscal_year, fx, address, address2, tax_id, prompt_pay, entrepreneur, email, phone, fax, website, facebook_page FROM company_list WHERE company_id = :company_id LIMIT 1" ); $sth->execute([':company_id' => $this->companyId]); $company = $sth->fetch(PDO::FETCH_ASSOC); if (!$company) { throw new Exception('Company not found.'); } return $company; } public function handleImageSlot( string $slot, string $action, string $current, string $upload_dir, string $prefix ): string { if ($action === 'keep') { return $current; } if ($action === 'remove') { if ($current && file_exists($upload_dir . $current)) { unlink($upload_dir . $current); } return ''; } if ($action === 'replace' && !empty($_FILES[$slot]['tmp_name'])) { $file = $_FILES[$slot]; if ($file['error'] !== UPLOAD_ERR_OK) { throw new RuntimeException("Upload error on {$slot}: code {$file['error']}."); } if ($file['size'] > self::MAX_SIZE) { throw new RuntimeException('File too large. Maximum size is 2 MB.'); } $finfo = finfo_open(FILEINFO_MIME_TYPE); $mime = finfo_file($finfo, $file['tmp_name']); finfo_close($finfo); if (!in_array($mime, self::ALLOWED_MIME, true)) { throw new RuntimeException('Invalid file type. Only JPEG, PNG, GIF, WEBP allowed.'); } $ext = strtolower(pathinfo($file['name'], PATHINFO_EXTENSION)); if (!in_array($ext, self::ALLOWED_EXT, true)) { throw new RuntimeException('Invalid file extension. Only jpg, png, gif, webp allowed.'); } if ($current && file_exists($upload_dir . $current)) { unlink($upload_dir . $current); } $filename = $prefix . uniqid() . '.' . $ext; if (!move_uploaded_file($file['tmp_name'], $upload_dir . $filename)) { throw new RuntimeException("Failed to save {$slot}."); } return $filename; } return $current; } public function saveProfile(array $data, string $company_logo, string $company_seal): void { $channel = preg_replace('/[^a-z0-9\-_]/', '', strtolower(trim($data['channel_name'] ?? ''))); $sth = $this->pdo->prepare( "UPDATE company_list SET channel_name = :channel_name, company_name = :company_name, company_name2 = :company_name2, company_logo = :company_logo, company_seal = :company_seal, branch = :branch, branch_no = :branch_no, fiscal_year = :fiscal_year, fx = :fx, address = :address, address2 = :address2, tax_id = :tax_id, prompt_pay = :prompt_pay, entrepreneur = :entrepreneur, email = :email, phone = :phone, fax = :fax, website = :website, facebook_page = :facebook_page WHERE company_id = :company_id" ); $sth->execute([ ':channel_name' => $channel, ':company_name' => trim($data['company_name'] ?? ''), ':company_name2' => trim($data['company_name2'] ?? ''), ':company_logo' => $company_logo, ':company_seal' => $company_seal, ':branch' => trim($data['branch'] ?? 'สำนักงานใหญ่'), ':branch_no' => trim($data['branch_no'] ?? ''), ':fiscal_year' => trim($data['fiscal_year'] ?? ''), ':fx' => trim($data['fx'] ?? 'thb'), ':address' => trim($data['address'] ?? ''), ':address2' => trim($data['address2'] ?? ''), ':tax_id' => trim($data['tax_id'] ?? ''), ':prompt_pay' => trim($data['prompt_pay'] ?? ''), ':entrepreneur' => trim($data['entrepreneur'] ?? ''), ':email' => trim($data['email'] ?? ''), ':phone' => trim($data['phone'] ?? ''), ':fax' => trim($data['fax'] ?? ''), ':website' => trim($data['website'] ?? ''), ':facebook_page' => trim($data['facebook_page'] ?? ''), ':company_id' => $this->companyId, ]); } } ?>