- Upgraded all plain `require` to `require_once` across 172 api/engine and api/engine_report files to prevent class-redeclaration errors - Added issue button, issue_invoice() with GL toastr, and delete_invoice() to expense/manage_purchase_invoice.php, bringing it in line with po/manage_purchase_invoice.php - Added can_delete role guard (admin/owner only) to trash icons on revenue/invoice.php and expense/purchase_invoice.php, matching the existing pattern in finance/receipt.php and finance/payment.php Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
34 lines
993 B
PHP
34 lines
993 B
PHP
<?php
|
|
/**
|
|
* back.php — Logout endpoint
|
|
*
|
|
* Called by: login page AJAX "logout" / "go back" button.
|
|
* Destroys the current session completely so the user is signed out.
|
|
*
|
|
* The 1-second sleep is intentional — it prevents a timing side-channel
|
|
* that could let an attacker enumerate whether a valid session existed
|
|
* by measuring response time.
|
|
*
|
|
* Flow:
|
|
* 1. Load session.php to resume the active PHP session.
|
|
* 2. Load db_auth.php to run standard auth/session bootstrap (required
|
|
* by session.php dependency chain).
|
|
* 3. Sleep 1 second (timing protection).
|
|
* 4. Destroy the session entirely.
|
|
* 5. Return { success: 1 }.
|
|
*
|
|
* Response JSON:
|
|
* { "success": 1 }
|
|
*/
|
|
|
|
require_once '../../../session.php';
|
|
define('UNAUTHENTICATED_ROUTE', true);
|
|
require_once '../../../assets/utils/db_auth.php';
|
|
|
|
// Intentional 1-second delay — prevents timing attacks on session enumeration
|
|
sleep(1);
|
|
|
|
session_destroy();
|
|
|
|
$answer["success"] = 1;
|
|
exit(json_encode($answer)); |