171 lines
7.7 KiB
PHP
171 lines
7.7 KiB
PHP
<?php
|
|
session_start();
|
|
require '../../../assets/utils/db_auth.php';
|
|
require '../../../assets/utils/classes/FileUploader.php';
|
|
|
|
require_role($user_role, ['owner', 'admin']);
|
|
|
|
// ─── Allowed upload types ─────────────────────────────────────────────────
|
|
const ALLOWED_MIME = ['image/jpeg', 'image/png', 'image/gif', 'image/webp'];
|
|
const ALLOWED_EXT = ['jpg', 'jpeg', 'png', 'gif', 'webp'];
|
|
const MAX_SIZE = 2 * 1024 * 1024; // 2 MB
|
|
|
|
// ─── Helper: handle one image slot ────────────────────────────────────────
|
|
function handle_image_slot(
|
|
string $slot, // 'company_logo' | 'company_seal'
|
|
string $action, // 'keep' | 'replace' | 'remove'
|
|
string $current, // current filename from DB
|
|
string $upload_dir, // absolute path to uploads/company/
|
|
string $prefix // filename prefix 'logo_' | 'seal_'
|
|
): ?string {
|
|
// 'keep' → return current unchanged
|
|
if ($action === 'keep') return $current;
|
|
|
|
// 'remove' → delete file, return ''
|
|
if ($action === 'remove') {
|
|
if ($current && file_exists($upload_dir . $current)) {
|
|
unlink($upload_dir . $current);
|
|
}
|
|
return '';
|
|
}
|
|
|
|
// 'replace' → validate + save new file
|
|
if ($action === 'replace' && !empty($_FILES[$slot]['tmp_name'])) {
|
|
|
|
$file = $_FILES[$slot];
|
|
|
|
if ($file['error'] !== UPLOAD_ERR_OK) {
|
|
throw new RuntimeException("Upload error on {$slot}: code {$file['error']}.");
|
|
}
|
|
if ($file['size'] > MAX_SIZE) {
|
|
throw new RuntimeException('File too large. Maximum size is 2 MB.');
|
|
}
|
|
|
|
$finfo = finfo_open(FILEINFO_MIME_TYPE);
|
|
$mime = finfo_file($finfo, $file['tmp_name']);
|
|
finfo_close($finfo);
|
|
|
|
if (!in_array($mime, ALLOWED_MIME, true)) {
|
|
throw new RuntimeException('Invalid file type. Only JPEG, PNG, GIF, WEBP allowed.');
|
|
}
|
|
|
|
$ext = strtolower(pathinfo($file['name'], PATHINFO_EXTENSION));
|
|
if (!in_array($ext, ALLOWED_EXT, true)) {
|
|
throw new RuntimeException('Invalid file extension. Only jpg, png, gif, webp allowed.');
|
|
}
|
|
|
|
// Delete old file first
|
|
if ($current && file_exists($upload_dir . $current)) {
|
|
unlink($upload_dir . $current);
|
|
}
|
|
|
|
$filename = $prefix . uniqid() . '.' . $ext;
|
|
|
|
if (!move_uploaded_file($file['tmp_name'], $upload_dir . $filename)) {
|
|
throw new RuntimeException("Failed to save {$slot}.");
|
|
}
|
|
|
|
return $filename;
|
|
}
|
|
|
|
return $current; // fallback
|
|
}
|
|
|
|
try {
|
|
|
|
// ── Fetch current image filenames from DB ─────────────────────────────
|
|
$sth = $pdo1->prepare(
|
|
'SELECT company_logo, company_seal FROM company_list WHERE company_id = :id LIMIT 1'
|
|
);
|
|
$sth->execute([':id' => $company_id]);
|
|
db_check($sth, $answer);
|
|
$current = $sth->fetch(PDO::FETCH_ASSOC);
|
|
|
|
if (!$current) {
|
|
$answer['message'] = 'Company not found.';
|
|
http_response_code(404);
|
|
exit(json_encode($answer));
|
|
}
|
|
|
|
// ── Upload directory ──────────────────────────────────────────────────
|
|
$upload_dir = $include_url . 'uploads/company/';
|
|
if (!is_dir($upload_dir)) {
|
|
mkdir($upload_dir, 0755, true);
|
|
}
|
|
|
|
// ── Process images ────────────────────────────────────────────────────
|
|
$logo_action = $data['logo_action'] ?? 'keep';
|
|
$seal_action = $data['seal_action'] ?? 'keep';
|
|
|
|
$new_logo = handle_image_slot('company_logo', $logo_action, $current['company_logo'] ?? '', $upload_dir, 'logo_');
|
|
$new_seal = handle_image_slot('company_seal', $seal_action, $current['company_seal'] ?? '', $upload_dir, 'seal_');
|
|
|
|
// ── Text field sanitisation ───────────────────────────────────────────
|
|
$channel = strtolower(preg_replace('/[^a-z0-9\-_]/', '', $data['channel_name'] ?? ''));
|
|
|
|
// ── UPDATE company_list ───────────────────────────────────────────────
|
|
$sth = $pdo1->prepare("
|
|
UPDATE company_list SET
|
|
channel_name = :channel_name,
|
|
company_name = :company_name,
|
|
company_name2 = :company_name2,
|
|
company_logo = :company_logo,
|
|
company_seal = :company_seal,
|
|
branch = :branch,
|
|
branch_no = :branch_no,
|
|
fiscal_year = :fiscal_year,
|
|
fx = :fx,
|
|
address = :address,
|
|
address2 = :address2,
|
|
tax_id = :tax_id,
|
|
prompt_pay = :prompt_pay,
|
|
entrepreneur = :entrepreneur,
|
|
email = :email,
|
|
phone = :phone,
|
|
fax = :fax,
|
|
website = :website,
|
|
facebook_page = :facebook_page
|
|
WHERE company_id = :company_id
|
|
");
|
|
|
|
$sth->execute([
|
|
':channel_name' => $channel,
|
|
':company_name' => trim($data['company_name'] ?? ''),
|
|
':company_name2' => trim($data['company_name2'] ?? ''),
|
|
':company_logo' => $new_logo,
|
|
':company_seal' => $new_seal,
|
|
':branch' => trim($data['branch'] ?? 'สำนักงานใหญ่'),
|
|
':branch_no' => trim($data['branch_no'] ?? ''),
|
|
':fiscal_year' => trim($data['fiscal_year'] ?? ''),
|
|
':fx' => trim($data['fx'] ?? 'thb'),
|
|
':address' => trim($data['address'] ?? ''),
|
|
':address2' => trim($data['address2'] ?? ''),
|
|
':tax_id' => trim($data['tax_id'] ?? ''),
|
|
':prompt_pay' => trim($data['prompt_pay'] ?? ''),
|
|
':entrepreneur' => trim($data['entrepreneur'] ?? ''),
|
|
':email' => trim($data['email'] ?? ''),
|
|
':phone' => trim($data['phone'] ?? ''),
|
|
':fax' => trim($data['fax'] ?? ''),
|
|
':website' => trim($data['website'] ?? ''),
|
|
':facebook_page' => trim($data['facebook_page'] ?? ''),
|
|
':company_id' => $company_id,
|
|
]);
|
|
db_check($sth, $answer);
|
|
|
|
$answer['success'] = 1;
|
|
$answer['message'] = 'Company profile saved.';
|
|
|
|
// Return new filenames only if they changed so client can refresh previews
|
|
if ($logo_action !== 'keep') $answer['company_logo'] = $new_logo;
|
|
if ($seal_action !== 'keep') $answer['company_seal'] = $new_seal;
|
|
|
|
} catch (RuntimeException $e) {
|
|
$answer['message'] = $e->getMessage();
|
|
http_response_code(422);
|
|
} catch (Exception $e) {
|
|
$answer['message'] = 'Failed to save company profile.';
|
|
http_response_code(500);
|
|
}
|
|
|
|
exit(json_encode($answer));
|
|
?>
|