Spec (docs/reviewed/document-lifecycle.md): - C1: Correct GlManager::delete() description — reversal entry, not hard delete - C3: Clarify PO status 2/3 are derived (receipt_status), never stored - C4: Add invoice status=2 (Paid/Settled) to status table - C5: Add full Receipt/Payment Billing Note lifecycle section - C6: Add Quotation status table and transition rules - C7: Document soft-delete tombstone mechanism (company_id negation) Code (InvoiceManager.php): - C2: voidInvoice() now blocks on active credit notes, posted receipt billing notes, and posted payment billing notes in addition to the existing receipt/payment checks - M9: softDelete() skips assertPostingWindow for draft invoices (status=0) since drafts have no GL entry and no accounting impact Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
MN3 WMS Feature Documentation
This folder documents the main product features discovered from the current PHP codebase.
The app is split into three operating areas:
- WMS: warehouse operations, stock movement, sales and purchase workflows.
- Accounting: revenue, expense, finance, journals, batch GL posting, and financial reports.
- Master Data: shared setup for products, locations, contacts, chart of accounts, departments, formulas, and posting rules.
Documents
- Coverage Matrix — codebase surface mapped to documentation status
- WMS Features
- Accounting Features
- Master Data Features
- System And Settings Features
- Runtime Architecture
- Setup And Landing Pages
- Helper Endpoint Contracts
- Document Lifecycle And Status
- Transaction Limits — package tiers, daily/weekly quotas, report gating
Architecture
- Architecture coverage is currently split between System And Settings Features, Accounting Features, and Coverage Matrix.
Cross-Cutting Specs
- Running Number — document number format, sequences, manual entry, gap policy
- Session Concurrency — single-session enforcement, heartbeat, PHP GC stale detection, single-factor auth
- Live Dashboard — real-time Socket.IO events, section reload map, flash card effect
- Role Guards — CRUD access matrix per role
- Soft Delete — mechanism, downstream blocks, stock/GL side effects, deletion order
Core Architecture
The UI is mostly PHP pages under app/, with AJAX endpoints under each module's api/engine or api/engine_report folder.
Common backend behavior is concentrated in manager classes:
app/assets/utils/classes/*Manager.phphandles WMS, document, contact, product, finance, and report logic.app/assets/utils/classes_ac/*handles accounting setup, GL posting, financial statements, posting windows, and tax reports.app/assets/js/custom.jscontains shared AJAX, pagination, account autocomplete, locks, batch processing, and display formatting helpers.
Cross-Cutting Rules
- Company scoping is applied through
company_idfrom the authenticated session. - Most write APIs load
app/assets/utils/db_auth.php, which validates session, OTP freshness, CSRF token, and request payload. - Role checks use
require_role()where a route is limited to owners/admins. - Audit logs are stored as JSON in many business tables through the
$loggingobject fromdb_auth.php. - Numeric display uses shared frontend formatting to suppress floating point noise and avoid scientific notation in the UI.