214 lines
8.7 KiB
PHP
214 lines
8.7 KiB
PHP
<?php
|
|
session_start();
|
|
require '../../../assets/utils/db_auth.php';
|
|
|
|
// ─── Role guard: only owner/admin can manage users ────────────────────────
|
|
$sth = $pdo1->prepare("
|
|
SELECT role FROM company_map_user
|
|
WHERE company_id = :company_id AND user_id = :user_id
|
|
LIMIT 1
|
|
");
|
|
$sth->execute([':company_id' => $company_id, ':user_id' => $user_id]);
|
|
db_check($sth, $answer);
|
|
$caller_role = $sth->fetchColumn();
|
|
|
|
if (!in_array($caller_role, ['owner', 'admin'], true)) {
|
|
$answer['message'] = 'You do not have permission to manage users.';
|
|
http_response_code(403);
|
|
exit(json_encode($answer));
|
|
}
|
|
|
|
$action = $data['action'] ?? '';
|
|
|
|
try {
|
|
|
|
// ══════════════════════════════════════════════════════════════════════
|
|
// CREATE — invite a user by email
|
|
// ══════════════════════════════════════════════════════════════════════
|
|
if ($action === 'create') {
|
|
|
|
$invite_email = strtolower(trim($data['invite_email'] ?? ''));
|
|
$invite_role = trim($data['invite_role'] ?? '');
|
|
|
|
if (!filter_var($invite_email, FILTER_VALIDATE_EMAIL)) {
|
|
$answer['message'] = 'Invalid email address.';
|
|
http_response_code(422);
|
|
exit(json_encode($answer));
|
|
}
|
|
|
|
$allowed_roles = ['admin', 'staff', 'viewer'];
|
|
if (!in_array($invite_role, $allowed_roles, true)) {
|
|
$answer['message'] = 'Invalid role selected.';
|
|
http_response_code(422);
|
|
exit(json_encode($answer));
|
|
}
|
|
|
|
// Look up user by email
|
|
$sth = $pdo1->prepare("SELECT user_id, email FROM user WHERE email = :email LIMIT 1");
|
|
$sth->execute([':email' => $invite_email]);
|
|
db_check($sth, $answer);
|
|
$target = $sth->fetch(PDO::FETCH_ASSOC);
|
|
|
|
if (!$target) {
|
|
$answer['message'] = 'No registered account found with that email address.';
|
|
http_response_code(404);
|
|
exit(json_encode($answer));
|
|
}
|
|
|
|
$target_user_id = (int)$target['user_id'];
|
|
|
|
// Prevent inviting self
|
|
if ($target_user_id === (int)$user_id) {
|
|
$answer['message'] = 'You cannot invite yourself.';
|
|
http_response_code(422);
|
|
exit(json_encode($answer));
|
|
}
|
|
|
|
// Check if already mapped to this company
|
|
$sth = $pdo1->prepare("
|
|
SELECT map_id FROM company_map_user
|
|
WHERE company_id = :company_id AND user_id = :user_id
|
|
LIMIT 1
|
|
");
|
|
$sth->execute([':company_id' => $company_id, ':user_id' => $target_user_id]);
|
|
db_check($sth, $answer);
|
|
$existing = $sth->fetch(PDO::FETCH_ASSOC);
|
|
|
|
if ($existing) {
|
|
$answer['message'] = 'This user is already a member of your company.';
|
|
http_response_code(409);
|
|
exit(json_encode($answer));
|
|
}
|
|
|
|
$sth = $pdo1->prepare("
|
|
INSERT INTO company_map_user
|
|
(company_id, user_id, role, created_at)
|
|
VALUES
|
|
(:company_id, :user_id, :role, NOW())
|
|
");
|
|
$sth->execute([
|
|
':company_id' => $company_id,
|
|
':user_id' => $target_user_id,
|
|
':role' => $invite_role,
|
|
]);
|
|
db_check($sth, $answer);
|
|
|
|
$answer['success'] = 1;
|
|
$answer['message'] = htmlspecialchars($target['email']) . ' has been added to your company.';
|
|
|
|
|
|
// ══════════════════════════════════════════════════════════════════════
|
|
// UPDATE — change a user's role
|
|
// ══════════════════════════════════════════════════════════════════════
|
|
} elseif ($action === 'update') {
|
|
|
|
$map_id = (int)($data['map_id'] ?? 0);
|
|
$new_role = trim($data['role'] ?? '');
|
|
|
|
$allowed_roles = ['admin', 'staff', 'viewer'];
|
|
if (!$map_id || !in_array($new_role, $allowed_roles, true)) {
|
|
$answer['message'] = 'Invalid request.';
|
|
http_response_code(422);
|
|
exit(json_encode($answer));
|
|
}
|
|
|
|
// Verify map belongs to this company and is not the owner
|
|
$sth = $pdo1->prepare("
|
|
SELECT role FROM company_map_user
|
|
WHERE map_id = :map_id AND company_id = :company_id
|
|
LIMIT 1
|
|
");
|
|
$sth->execute([':map_id' => $map_id, ':company_id' => $company_id]);
|
|
db_check($sth, $answer);
|
|
$target_role = $sth->fetchColumn();
|
|
|
|
if ($target_role === false) {
|
|
$answer['message'] = 'User not found.';
|
|
http_response_code(404);
|
|
exit(json_encode($answer));
|
|
}
|
|
if ($target_role === 'owner') {
|
|
$answer['message'] = 'Owner role cannot be changed.';
|
|
http_response_code(403);
|
|
exit(json_encode($answer));
|
|
}
|
|
|
|
$sth = $pdo1->prepare("
|
|
UPDATE company_map_user
|
|
SET role = :role
|
|
WHERE map_id = :map_id AND company_id = :company_id
|
|
");
|
|
$sth->execute([
|
|
':role' => $new_role,
|
|
':map_id' => $map_id,
|
|
':company_id' => $company_id,
|
|
]);
|
|
db_check($sth, $answer);
|
|
|
|
$answer['success'] = 1;
|
|
$answer['message'] = 'Role updated successfully.';
|
|
|
|
|
|
// ══════════════════════════════════════════════════════════════════════
|
|
// DELETE — remove user from company
|
|
// ══════════════════════════════════════════════════════════════════════
|
|
} elseif ($action === 'delete') {
|
|
|
|
$map_id = (int)($data['map_id'] ?? 0);
|
|
if (!$map_id) {
|
|
$answer['message'] = 'Invalid request.';
|
|
http_response_code(422);
|
|
exit(json_encode($answer));
|
|
}
|
|
|
|
// Verify map belongs to this company, and isn't the owner
|
|
$sth = $pdo1->prepare("
|
|
SELECT role, user_id FROM company_map_user
|
|
WHERE map_id = :map_id AND company_id = :company_id
|
|
LIMIT 1
|
|
");
|
|
$sth->execute([':map_id' => $map_id, ':company_id' => $company_id]);
|
|
db_check($sth, $answer);
|
|
$row = $sth->fetch(PDO::FETCH_ASSOC);
|
|
|
|
if (!$row) {
|
|
$answer['message'] = 'User not found.';
|
|
http_response_code(404);
|
|
exit(json_encode($answer));
|
|
}
|
|
if ($row['role'] === 'owner') {
|
|
$answer['message'] = 'The owner cannot be removed.';
|
|
http_response_code(403);
|
|
exit(json_encode($answer));
|
|
}
|
|
// Prevent removing yourself
|
|
if ((int)$row['user_id'] === (int)$user_id) {
|
|
$answer['message'] = 'You cannot remove yourself.';
|
|
http_response_code(403);
|
|
exit(json_encode($answer));
|
|
}
|
|
|
|
// Hard delete — just remove the row
|
|
$sth = $pdo1->prepare("
|
|
DELETE FROM company_map_user
|
|
WHERE map_id = :map_id AND company_id = :company_id
|
|
");
|
|
$sth->execute([':map_id' => $map_id, ':company_id' => $company_id]);
|
|
db_check($sth, $answer);
|
|
|
|
$answer['success'] = 1;
|
|
$answer['message'] = 'User has been removed from this company.';
|
|
|
|
|
|
} else {
|
|
$answer['message'] = 'Unknown action.';
|
|
http_response_code(400);
|
|
}
|
|
|
|
} catch (Exception $e) {
|
|
$answer['message'] = 'An error occurred. Please try again.';
|
|
http_response_code(500);
|
|
}
|
|
|
|
exit(json_encode($answer));
|
|
?>
|