MAX_SIZE) { throw new RuntimeException('File too large. Maximum size is 2 MB.'); } $finfo = finfo_open(FILEINFO_MIME_TYPE); $mime = finfo_file($finfo, $file['tmp_name']); finfo_close($finfo); if (!in_array($mime, ALLOWED_MIME, true)) { throw new RuntimeException('Invalid file type. Only JPEG, PNG, GIF, WEBP allowed.'); } $ext = strtolower(pathinfo($file['name'], PATHINFO_EXTENSION)); if (!in_array($ext, ALLOWED_EXT, true)) { throw new RuntimeException('Invalid file extension. Only jpg, png, gif, webp allowed.'); } // Delete old file first if ($current && file_exists($upload_dir . $current)) { unlink($upload_dir . $current); } $filename = $prefix . uniqid() . '.' . $ext; if (!move_uploaded_file($file['tmp_name'], $upload_dir . $filename)) { throw new RuntimeException("Failed to save {$slot}."); } return $filename; } return $current; // fallback } try { // ── Fetch current image filenames from DB ───────────────────────────── $sth = $pdo1->prepare( 'SELECT company_logo, company_seal FROM company_list WHERE company_id = :id LIMIT 1' ); $sth->execute([':id' => $company_id]); db_check($sth, $answer); $current = $sth->fetch(PDO::FETCH_ASSOC); if (!$current) { $answer['message'] = 'Company not found.'; http_response_code(404); exit(json_encode($answer)); } // ── Upload directory ────────────────────────────────────────────────── $upload_dir = $include_url . 'uploads/company/'; if (!is_dir($upload_dir)) { mkdir($upload_dir, 0755, true); } // ── Process images ──────────────────────────────────────────────────── $logo_action = $data['logo_action'] ?? 'keep'; $seal_action = $data['seal_action'] ?? 'keep'; $new_logo = handle_image_slot('company_logo', $logo_action, $current['company_logo'] ?? '', $upload_dir, 'logo_'); $new_seal = handle_image_slot('company_seal', $seal_action, $current['company_seal'] ?? '', $upload_dir, 'seal_'); // ── Text field sanitisation ─────────────────────────────────────────── $channel = strtolower(preg_replace('/[^a-z0-9\-_]/', '', $data['channel_name'] ?? '')); // ── UPDATE company_list ─────────────────────────────────────────────── $sth = $pdo1->prepare(" UPDATE company_list SET channel_name = :channel_name, company_name = :company_name, company_name2 = :company_name2, company_logo = :company_logo, company_seal = :company_seal, branch = :branch, branch_no = :branch_no, fiscal_year = :fiscal_year, fx = :fx, address = :address, address2 = :address2, tax_id = :tax_id, prompt_pay = :prompt_pay, entrepreneur = :entrepreneur, email = :email, phone = :phone, fax = :fax, website = :website, facebook_page = :facebook_page WHERE company_id = :company_id "); $sth->execute([ ':channel_name' => $channel, ':company_name' => trim($data['company_name'] ?? ''), ':company_name2' => trim($data['company_name2'] ?? ''), ':company_logo' => $new_logo, ':company_seal' => $new_seal, ':branch' => trim($data['branch'] ?? 'สำนักงานใหญ่'), ':branch_no' => trim($data['branch_no'] ?? ''), ':fiscal_year' => trim($data['fiscal_year'] ?? ''), ':fx' => trim($data['fx'] ?? 'thb'), ':address' => trim($data['address'] ?? ''), ':address2' => trim($data['address2'] ?? ''), ':tax_id' => trim($data['tax_id'] ?? ''), ':prompt_pay' => trim($data['prompt_pay'] ?? ''), ':entrepreneur' => trim($data['entrepreneur'] ?? ''), ':email' => trim($data['email'] ?? ''), ':phone' => trim($data['phone'] ?? ''), ':fax' => trim($data['fax'] ?? ''), ':website' => trim($data['website'] ?? ''), ':facebook_page' => trim($data['facebook_page'] ?? ''), ':company_id' => $company_id, ]); db_check($sth, $answer); $answer['success'] = 1; $answer['message'] = 'Company profile saved.'; // Return new filenames only if they changed so client can refresh previews if ($logo_action !== 'keep') $answer['company_logo'] = $new_logo; if ($seal_action !== 'keep') $answer['company_seal'] = $new_seal; } catch (RuntimeException $e) { $answer['message'] = $e->getMessage(); http_response_code(422); } catch (Exception $e) { $answer['message'] = 'Failed to save company profile.'; http_response_code(500); } exit(json_encode($answer)); ?>