1, // auto-approve by default ]; public function __construct(PDO $pdo, int $companyId) { $this->pdo = $pdo; $this->companyId = $companyId; } // ───────────────────────────────────────────────────────────── // Public API // ───────────────────────────────────────────────────────────── /** * Return the value for a single key, or the default if not configured. * * @param string $key Setting key. * @return mixed Stored value cast to int, or the default. */ public function get(string $key): mixed { $sth = $this->pdo->prepare( "SELECT value FROM company_setting WHERE company_id = :company_id AND setting_key = :setting_key LIMIT 1" ); $sth->execute([':company_id' => $this->companyId, ':setting_key' => $key]); $row = $sth->fetch(PDO::FETCH_ASSOC); if ($row === false) { return self::DEFAULTS[$key] ?? null; } // Cast numeric-looking values to int for clean comparisons return is_numeric($row['value']) ? (int)$row['value'] : $row['value']; } /** * Return all settings for this company, merged with defaults. * * @return array Associative array of key => value. */ public function getAll(): array { $sth = $this->pdo->prepare( "SELECT setting_key, value FROM company_setting WHERE company_id = :company_id" ); $sth->execute([':company_id' => $this->companyId]); $rows = $sth->fetchAll(PDO::FETCH_KEY_PAIR); // Merge stored values over defaults, cast numeric values $result = self::DEFAULTS; foreach ($rows as $k => $v) { $result[$k] = is_numeric($v) ? (int)$v : $v; } return $result; } /** * Upsert a single setting value. * * @param string $key * @param mixed $value */ public function set(string $key, mixed $value): void { // Fetch existing log to append to it $sth = $this->pdo->prepare( "SELECT log FROM company_setting WHERE company_id = :company_id AND setting_key = :setting_key LIMIT 1" ); $sth->execute([':company_id' => $this->companyId, ':setting_key' => $key]); $existing_log = json_decode($sth->fetchColumn() ?: '[]', true) ?: []; $existing_log[] = [ 'user_id' => $_SESSION['login_user_id'] ?? null, 'dt' => date('Y-m-d H:i:s'), 'value' => $value, ]; $this->pdo->prepare( "INSERT INTO company_setting (company_id, setting_key, value, log, updated_at) VALUES (:company_id, :setting_key, :value, :log, NOW()) ON DUPLICATE KEY UPDATE value = VALUES(value), log = VALUES(log), updated_at = NOW()" )->execute([ ':company_id' => $this->companyId, ':setting_key' => $key, ':value' => $value, ':log' => json_encode($existing_log), ]); } /** * HTTP handler — read or update settings via AJAX. * * action: 'read' → return all settings * action: 'update' → upsert one or more keys from $data * * @param array $data Request data array. */ public function handle(array $data): void { $action = $data['action'] ?? ''; if ($action === 'read') { echo json_encode(['success' => 1, 'output' => $this->getAll()]); exit; } if ($action === 'update') { $allowed = array_keys(self::DEFAULTS); foreach ($allowed as $key) { $this->set($key, $data[$key] ?? self::DEFAULTS[$key]); } echo json_encode(['success' => 1, 'message' => 'Settings saved.']); exit; } http_response_code(400); echo json_encode(['success' => 0, 'message' => 'Invalid action.']); exit; } }