0, 'message' => '']; // ─── Must come from onboarding session ─────────────────────── if (empty($_SESSION['onboarding_user_id'])) { $answer['message'] = 'Invalid session. Please verify your email first.'; http_response_code(403); exit(json_encode($answer)); } $user_id = (int)$_SESSION['onboarding_user_id']; // ─── CSRF ───────────────────────────────────────────────────── if ($_SERVER['REQUEST_METHOD'] === 'POST') { $csrf = $_SERVER['HTTP_X_CSRF_TOKEN'] ?? ''; if (empty($csrf) || $csrf !== ($_SESSION['csrf_token'] ?? '')) { http_response_code(403); exit(json_encode(['message' => 'Invalid request.'])); } } $data = json_decode($_POST['json'] ?? '{}', true) ?: []; try { $company_name = trim($data['company_name'] ?? ''); $company_name2 = trim($data['company_name2'] ?? ''); $channel_name = strtolower(preg_replace('/[^a-z0-9\-_]/', '', $data['channel_name'] ?? '')); $branch = trim($data['branch'] ?? 'สำนักงานใหญ่'); $branch_no = trim($data['branch_no'] ?? '00000'); $email = trim($data['email'] ?? ''); $phone = trim($data['phone'] ?? ''); if (!$company_name || !$channel_name) { $answer['message'] = 'Company name and channel name are required.'; http_response_code(422); exit(json_encode($answer)); } // ── SMTP fields required ────────────────────────────────── $smtp_host = trim($data['smtp_host'] ?? ''); $smtp_username = trim($data['smtp_username'] ?? ''); $smtp_password = $data['smtp_password'] ?? ''; if (!$smtp_host || !$smtp_username || !$smtp_password) { $answer['message'] = 'SMTP configuration is required. Please fill in all SMTP fields.'; http_response_code(422); exit(json_encode($answer)); } $smtp_port = trim($data['smtp_port'] ?? '587'); $smtp_encryption = trim($data['smtp_encryption'] ?? 'tls'); if (!in_array($smtp_port, ['25', '465', '587'], true)) $smtp_port = '587'; if (!in_array($smtp_encryption, ['tls', 'ssl', 'none'], true)) $smtp_encryption = 'tls'; // ── Silent SMTP test — before touching the DB ───────────── // Build a temporary config using the encrypted password $encrypted_pass = openssl_encrypt($smtp_password, $method, $pinkey, 0, $iv); $smtp_config = [ 'server' => $smtp_host, 'port' => $smtp_port, 'username' => $smtp_username, 'password' => $encrypted_pass, 'from_name' => $company_name ?: $smtp_username, 'from_email' => $email ?: $smtp_username, 'encryption' => $smtp_encryption, ]; require_once $include_url . 'assets/utils/module/mailer.php'; $mailer = new mailer(['pdo1' => $pdo1]); $mailer->send_email([ 'company_id' => 0, 'smtp' => $smtp_config, 'to' => $_SESSION['onboarding_email'] ?? $smtp_username, 'subject' => 'WMS — SMTP Verification', 'message' => "Your SMTP is working correctly.\n\nSetup is now complete.", 'channel_name' => $company_name ?: 'WMS', 'key' => $pinkey, ]); // if mailer fails it exits with its own error JSON — nothing below runs // ── Duplicate channel name ──────────────────────────────── $sth = $pdo1->prepare('SELECT company_id FROM company_list WHERE channel_name = :c LIMIT 1'); $sth->execute([':c' => $channel_name]); db_check($sth, $answer); if ($sth->fetchColumn()) { $answer['message'] = 'Channel name is already taken. Please choose another.'; http_response_code(409); exit(json_encode($answer)); } // ── Insert company ──────────────────────────────────────── $sth = $pdo1->prepare(" INSERT INTO company_list (channel_name, company_name, company_name2, branch, branch_no, email, phone, fx) VALUES (:channel_name, :company_name, :company_name2, :branch, :branch_no, :email, :phone, 'thb') "); $sth->execute([ ':channel_name' => $channel_name, ':company_name' => $company_name, ':company_name2' => $company_name2, ':branch' => $branch, ':branch_no' => $branch_no, ':email' => $email, ':phone' => $phone, ]); db_check($sth, $answer); $company_id = (int)$pdo1->lastInsertId(); // ── Map user as owner ───────────────────────────────────── $sth = $pdo1->prepare(" INSERT INTO company_map_user (company_id, user_id, role, created_at) VALUES (:company_id, :user_id, 'owner', NOW()) "); $sth->execute([':company_id' => $company_id, ':user_id' => $user_id]); db_check($sth, $answer); // ── Set as default company for this user ────────────────── $sth = $pdo1->prepare("UPDATE user SET default_company = :c, `status` = 'active' WHERE user_id = :u"); $sth->execute([':c' => $company_id, ':u' => $user_id]); db_check($sth, $answer); // ── Save SMTP ───────────────────────────────────────────── $sth = $pdo1->prepare(" INSERT INTO company_smtp (company_id, server, port, username, password, from_name, from_email, encryption, updated_at) VALUES (:company_id, :server, :port, :username, :password, :from_name, :from_email, :encryption, NOW()) "); $sth->execute([ ':company_id' => $company_id, ':server' => $smtp_host, ':port' => $smtp_port, ':username' => $smtp_username, ':password' => $encrypted_pass, ':from_name' => $company_name, ':from_email' => $email ?: $smtp_username, ':encryption' => $smtp_encryption, ]); db_check($sth, $answer); // ── Clear onboarding session ────────────────────────────── unset( $_SESSION['onboarding_user_id'], $_SESSION['onboarding_name'], $_SESSION['onboarding_email'] ); $answer['success'] = 1; $answer['message'] = 'Setup complete.'; } catch (Exception $e) { error_log('[onboarding] ' . $e->getMessage()); $answer['message'] = 'Setup failed. Please try again.'; http_response_code(500); } exit(json_encode($answer)); ?>