- Upgraded all plain `require` to `require_once` across 172 api/engine and api/engine_report files to prevent class-redeclaration errors - Added issue button, issue_invoice() with GL toastr, and delete_invoice() to expense/manage_purchase_invoice.php, bringing it in line with po/manage_purchase_invoice.php - Added can_delete role guard (admin/owner only) to trash icons on revenue/invoice.php and expense/purchase_invoice.php, matching the existing pattern in finance/receipt.php and finance/payment.php Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
35 lines
1020 B
PHP
35 lines
1020 B
PHP
<?php
|
|
|
|
require_once '../../../session.php';
|
|
define('UNAUTHENTICATED_ROUTE', true);
|
|
require_once '../../../assets/utils/db_auth.php';
|
|
|
|
// Resolve user by username or email
|
|
$identifier = strtolower(trim($data['identifier'] ?? ''));
|
|
|
|
if (!$identifier) {
|
|
http_response_code(422);
|
|
$answer['message'] = 'Please enter your username or email.';
|
|
exit(json_encode($answer));
|
|
}
|
|
|
|
$sth = $pdo1->prepare(
|
|
"SELECT user_id, default_company FROM user WHERE username = :i OR email = :i LIMIT 1"
|
|
);
|
|
$sth->execute([':i' => $identifier]);
|
|
$user = $sth->fetch(PDO::FETCH_ASSOC);
|
|
|
|
if (!$user) {
|
|
http_response_code(404);
|
|
$answer['message'] = 'No account found with that username or email.';
|
|
exit(json_encode($answer));
|
|
}
|
|
|
|
$user_id = (int)$user['user_id'];
|
|
$company_id = (int)($user['default_company'] ?? 0);
|
|
|
|
require_once '../../../assets/utils/classes/PasswordResetManager.php';
|
|
|
|
$manager = new PasswordResetManager($pdo1, $pdo2, $include_url, $SMTP, $pinkey);
|
|
$manager->handleRequestOtp($user_id, $company_id);
|