prepare( "SELECT cl.company_id, cl.channel_name, cl.company_name, cl.branch, cmu.role FROM company_map_user cmu JOIN company_list cl ON cl.company_id = cmu.company_id WHERE cmu.user_id = :user_id ORDER BY cl.company_name ASC" ); $sth->execute([':user_id' => $user_id]); $companies = $sth->fetchAll(PDO::FETCH_ASSOC); $answer['success'] = 1; $answer['output'] = $companies; $answer['current'] = (int) $_SESSION['login_company_id']; exit(json_encode($answer)); } // ── UPDATE: switch to a different company ───────────────────────────────────── if ($action === 'update') { $target_company_id = (int)($data['company_id'] ?? 0); if (!$target_company_id) { http_response_code(400); $answer['message'] = 'Invalid company.'; exit(json_encode($answer)); } // Verify user actually belongs to the requested company $sth = $pdo1->prepare( "SELECT company_id FROM company_map_user WHERE company_id = :company_id AND user_id = :user_id LIMIT 1" ); $sth->execute([':company_id' => $target_company_id, ':user_id' => $user_id]); if (!$sth->fetch()) { http_response_code(403); $answer['message'] = 'You do not have access to this company.'; exit(json_encode($answer)); } $_SESSION['login_company_id'] = $target_company_id; $answer['success'] = 1; $answer['message'] = 'Switched successfully.'; exit(json_encode($answer)); } http_response_code(400); $answer['message'] = 'Invalid action.'; exit(json_encode($answer));