<><><><><><><> MAIN CONFIG <><><><><><><><>// if(true){ $base_url = "/your-app-folder/"; // e.g. "/wms-app/" — folder name under web root $server_url = $base_url."app/"; $include_url = $_SERVER['DOCUMENT_ROOT'].$server_url; $db_server = "localhost"; // Use a dedicated account with only SELECT, INSERT, UPDATE, DELETE, CREATE, // INDEX, CREATE TEMPORARY TABLES, LOCK TABLES, EXECUTE on wms and wms2 — // never root (docker/php/provision.php shows the grants). $db_user = "wms_app"; $db_pass = "YOUR_DB_PASSWORD"; $db_type = "mysql"; $db_database = "wms"; $db_database2 = "wms2"; $db_server2 = (!empty($db_server2))?$db_server2:$db_server; $db_user2 = (!empty($db_user2))?$db_user2:$db_user; $db_pass2 = (!empty($db_pass2))?$db_pass2:$db_pass; $db_type2 = (!empty($db_type2))?$db_type2:$db_type; $time_zone = "Asia/Bangkok"; } // ── Real-time Node.js server ───────────────────────────────────────────────── // Base URL the browser uses to reach nodejs/server.js (Socket.IO). Must match // PORT in nodejs/.env. if (!defined('NODE_PUBLIC_URL')) { define('NODE_PUBLIC_URL', 'http://localhost:3000'); } // Server-to-server calls (PHP → Node /emit, and Node scheduler → PHP cron // endpoints) authenticate with this shared secret — must match EMIT_SECRET // in nodejs/.env exactly. if (!defined('NODE_EMIT_URL')) { define('NODE_EMIT_URL', 'http://127.0.0.1:3000/emit'); } if (!defined('NODE_EMIT_SECRET')) { define('NODE_EMIT_SECRET', 'YOUR_NODE_EMIT_SECRET'); // must match nodejs/.env EMIT_SECRET } // ── Login OTP ──────────────────────────────────────────────────────────────── // Email OTP on sign-in. OFF BY DEFAULT: only the boolean true turns it on — // anything else, the constant being absent included, leaves sign-in password // only (logged as OTP_BYPASSED, shown on the login page and top bar). Turn it // on only with working SMTP. Password-reset OTPs are not affected. if (!defined('OTP_REQUIRED')) { define('OTP_REQUIRED', false); } // ── App registry ───────────────────────────────────────────────────────────── // Apps a user can be given access to, as shown on Setting → Users Access. Keys // must match the user.app_access enum ('wms', 'accounting'). If this is left // out, assets/utils/app_registry.php supplies the same default. $app_registry = [ 'wms' => ['label' => 'WMS', 'icon' => 'ti-box', 'color' => 'bg-label-primary'], 'accounting' => ['label' => 'Accounting', 'icon' => 'ti-calculator', 'color' => 'bg-label-success'], ]; // ── Usage packages ─────────────────────────────────────────────────────────── // Keyed by company_list.package (defaults to 'starter'). Read by UsageGuard to // enforce daily/weekly action limits and which features lock once exceeded. $packages = [ 'starter' => [ 'daily_limit' => 30, 'weekly_limit' => 100, 'lock_on_limit' => ['dashboard'], ], ]; // Key for stored SMTP passwords (assets/utils/secret_box.php): a long random // string, e.g. `openssl rand -hex 32`. Keep it stable across deploys — changing it // makes saved SMTP passwords unreadable. Never commit the real value. if (!defined('APP_SECRET_KEY')) { define('APP_SECRET_KEY', 'YOUR_APP_SECRET_KEY'); } // Legacy fixed key: only used to read SMTP passwords saved before APP_SECRET_KEY. $pinkey = "wms"; $SMTP = []; $SMTP['server'] = "smtp.gmail.com"; $SMTP['username'] = "YOUR_EMAIL@gmail.com"; $SMTP['port'] = "587"; $SMTP['password'] = "YOUR_GMAIL_APP_PASSWORD"; // Gmail app password, not your login password $method = "AES-256-CBC"; $iv = "1234567890123456"; // Must be exactly 16 bytes $SMTP['password'] = openssl_encrypt($SMTP['password'], $method, $pinkey, 0, $iv);