# MN3 WMS Feature Documentation This folder documents the main product features discovered from the current PHP codebase. The app is split into three operating areas: - WMS: warehouse operations, stock movement, sales and purchase workflows. - Accounting: revenue, expense, finance, journals, batch GL posting, and financial reports. - Master Data: shared setup for products, locations, contacts, chart of accounts, departments, formulas, and posting rules. ## Documents - [Coverage Matrix](coverage-matrix.md) — codebase surface mapped to documentation status - [WMS Features](../reviewing/wms.md) - [Accounting Features](../reviewing/accounting.md) - [Master Data Features](../reviewing/master-data.md) - [System And Settings Features](../reviewing/system-settings.md) - [Runtime Architecture](../reviewing/runtime-architecture.md) - [Setup And Landing Pages](../reviewing/setup-landing.md) - [Helper Endpoint Contracts](../reviewing/helper-endpoints.md) - [Document Lifecycle And Status](../reviewing/document-lifecycle.md) - [Transaction Limits](../reviewing/transaction-limits.md) — package tiers, daily/weekly quotas, report gating ## Architecture - Architecture coverage is currently split between [System And Settings Features](../reviewing/system-settings.md), [Accounting Features](../reviewing/accounting.md), and [Coverage Matrix](coverage-matrix.md). ## Cross-Cutting Specs - [Running Number](running-number.md) — document number format, sequences, manual entry, gap policy - [Session Concurrency](session-concurrency.md) — single-session enforcement, heartbeat, PHP GC stale detection, single-factor auth - [Live Dashboard](live-dashboard.md) — real-time Socket.IO events, section reload map, flash card effect - [Role Guards](role-guards.md) — CRUD access matrix per role - [Soft Delete](soft-delete.md) — mechanism, downstream blocks, stock/GL side effects, deletion order ## Core Architecture The UI is mostly PHP pages under `app/`, with AJAX endpoints under each module's `api/engine` or `api/engine_report` folder. Common backend behavior is concentrated in manager classes: - `app/assets/utils/classes/*Manager.php` handles WMS, document, contact, product, finance, and report logic. - `app/assets/utils/classes_ac/*` handles accounting setup, GL posting, financial statements, posting windows, and tax reports. - `app/assets/js/custom.js` contains shared AJAX, pagination, account autocomplete, locks, batch processing, and display formatting helpers. ## Cross-Cutting Rules - Company scoping is applied through `company_id` from the authenticated session. - Most write APIs load `app/assets/utils/db_auth.php`, which validates session, OTP freshness, CSRF token, and request payload. - Role checks use `require_role()` where a route is limited to owners/admins. - Audit logs are stored as JSON in many business tables through the `$logging` object from `db_auth.php`. - Numeric display uses shared frontend formatting to suppress floating point noise and avoid scientific notation in the UI.