38 lines
1.5 KiB
PHP
38 lines
1.5 KiB
PHP
<?php
|
|
/**
|
|
* app_access.php — which app (WMS / Accounting) a script belongs to, and whether
|
|
* the signed-in user's app_access allows it.
|
|
*
|
|
* app_access used to only choose which menus the topbar drew; a WMS-only user
|
|
* could still open the accounting pages and call their APIs directly. db_auth.php
|
|
* (API engines) and include_topbar.php (pages) now both enforce it through here.
|
|
*/
|
|
|
|
// Accounting endpoints the WMS screens also call (master-data lookups, the
|
|
// batch operation lock, and the GL panel on purchase invoices).
|
|
const APP_ACCESS_SHARED_ACCOUNTING = [
|
|
'accounting/api/engine/account.php',
|
|
'accounting/api/engine/account_formula.php',
|
|
'accounting/api/engine/department.php',
|
|
'accounting/api/engine/acquire_op_lock.php',
|
|
'accounting/api/engine/release_op_lock.php',
|
|
'accounting/api/engine/get_gl_by_source.php',
|
|
];
|
|
|
|
/** The app a script under app/ belongs to: 'accounting', or null for WMS/shared. */
|
|
function app_access_app_for(string $script_name): ?string {
|
|
$path = str_replace('\\', '/', $script_name);
|
|
$pos = strpos($path, '/app/');
|
|
if ($pos === false) return null;
|
|
$rel = substr($path, $pos + 5);
|
|
|
|
if (in_array($rel, APP_ACCESS_SHARED_ACCOUNTING, true)) return null;
|
|
if (preg_match('#^(accounting|ac_dashboard|revenue|expense|finance|journal)/#', $rel)) return 'accounting';
|
|
return null;
|
|
}
|
|
|
|
/** Whether an app_access value ('wms', 'accounting', 'all') includes $app. */
|
|
function app_access_allows(string $access, string $app): bool {
|
|
return $access === 'all' || $access === $app;
|
|
}
|