174 lines
7.7 KiB
PHP
174 lines
7.7 KiB
PHP
<?php
|
|
require '../../../session.php';
|
|
require '../../../config.php';
|
|
require '../../../dbconn.php';
|
|
require '../../../assets/utils/db_helpers.php';
|
|
|
|
header('Content-Type: application/json; charset=utf-8');
|
|
|
|
$answer = ['success' => 0, 'message' => ''];
|
|
|
|
// ─── Must come from onboarding session ───────────────────────
|
|
if (empty($_SESSION['onboarding_user_id'])) {
|
|
$answer['message'] = 'Invalid session. Please verify your email first.';
|
|
http_response_code(403);
|
|
exit(json_encode($answer));
|
|
}
|
|
|
|
$user_id = (int)$_SESSION['onboarding_user_id'];
|
|
|
|
// ─── CSRF ─────────────────────────────────────────────────────
|
|
if ($_SERVER['REQUEST_METHOD'] === 'POST') {
|
|
$csrf = $_SERVER['HTTP_X_CSRF_TOKEN'] ?? '';
|
|
if (empty($csrf) || $csrf !== ($_SESSION['csrf_token'] ?? '')) {
|
|
http_response_code(403);
|
|
exit(json_encode(['message' => 'Invalid request.']));
|
|
}
|
|
}
|
|
|
|
$data = json_decode($_POST['json'] ?? '{}', true) ?: [];
|
|
|
|
try {
|
|
|
|
$company_name = trim($data['company_name'] ?? '');
|
|
$company_name2 = trim($data['company_name2'] ?? '');
|
|
$channel_name = strtolower(preg_replace('/[^a-z0-9\-_]/', '', $data['channel_name'] ?? ''));
|
|
$branch = trim($data['branch'] ?? 'สำนักงานใหญ่');
|
|
$branch_no = trim($data['branch_no'] ?? '00000');
|
|
$email = trim($data['email'] ?? '');
|
|
$phone = trim($data['phone'] ?? '');
|
|
|
|
if (!$company_name || !$channel_name) {
|
|
$answer['message'] = 'Company name and channel name are required.';
|
|
http_response_code(422);
|
|
exit(json_encode($answer));
|
|
}
|
|
|
|
// ── SMTP fields required ──────────────────────────────────
|
|
$smtp_host = trim($data['smtp_host'] ?? '');
|
|
$smtp_username = trim($data['smtp_username'] ?? '');
|
|
$smtp_password = $data['smtp_password'] ?? '';
|
|
|
|
if (!$smtp_host || !$smtp_username || !$smtp_password) {
|
|
$answer['message'] = 'SMTP configuration is required. Please fill in all SMTP fields.';
|
|
http_response_code(422);
|
|
exit(json_encode($answer));
|
|
}
|
|
|
|
$smtp_port = trim($data['smtp_port'] ?? '587');
|
|
|
|
|
|
$smtp_encryption = trim($data['smtp_encryption'] ?? 'tls');
|
|
|
|
if (!in_array($smtp_port, ['25', '465', '587'], true)) $smtp_port = '587';
|
|
if (!in_array($smtp_encryption, ['tls', 'ssl', 'none'], true)) $smtp_encryption = 'tls';
|
|
|
|
// ── Silent SMTP test — before touching the DB ─────────────
|
|
// Build a temporary config using the encrypted password
|
|
$encrypted_pass = openssl_encrypt($smtp_password, $method, $pinkey, 0, $iv);
|
|
|
|
$smtp_config = [
|
|
'server' => $smtp_host,
|
|
'port' => $smtp_port,
|
|
'username' => $smtp_username,
|
|
'password' => $encrypted_pass,
|
|
'from_name' => $company_name ?: $smtp_username,
|
|
'from_email' => $email ?: $smtp_username,
|
|
'encryption' => $smtp_encryption,
|
|
];
|
|
|
|
require_once $include_url . 'assets/utils/module/mailer.php';
|
|
|
|
$mailer = new mailer(['pdo1' => $pdo1]);
|
|
$mailer->send_email([
|
|
'company_id' => 0,
|
|
'smtp' => $smtp_config,
|
|
'to' => $_SESSION['onboarding_email'] ?? $smtp_username,
|
|
'subject' => 'WMS — SMTP Verification',
|
|
'message' => "Your SMTP is working correctly.\n\nSetup is now complete.",
|
|
'channel_name' => $company_name ?: 'WMS',
|
|
'key' => $pinkey,
|
|
]);
|
|
// if mailer fails it exits with its own error JSON — nothing below runs
|
|
|
|
// ── Duplicate channel name ────────────────────────────────
|
|
$sth = $pdo1->prepare('SELECT company_id FROM company_list WHERE channel_name = :c LIMIT 1');
|
|
$sth->execute([':c' => $channel_name]);
|
|
db_check($sth, $answer);
|
|
if ($sth->fetchColumn()) {
|
|
$answer['message'] = 'Channel name is already taken. Please choose another.';
|
|
http_response_code(409);
|
|
exit(json_encode($answer));
|
|
}
|
|
|
|
// ── Insert company ────────────────────────────────────────
|
|
$sth = $pdo1->prepare("
|
|
INSERT INTO company_list
|
|
(channel_name, company_name, company_name2, branch, branch_no, email, phone, fx)
|
|
VALUES
|
|
(:channel_name, :company_name, :company_name2, :branch, :branch_no, :email, :phone, 'thb')
|
|
");
|
|
$sth->execute([
|
|
':channel_name' => $channel_name,
|
|
':company_name' => $company_name,
|
|
':company_name2' => $company_name2,
|
|
':branch' => $branch,
|
|
':branch_no' => $branch_no,
|
|
':email' => $email,
|
|
':phone' => $phone,
|
|
]);
|
|
db_check($sth, $answer);
|
|
$company_id = (int)$pdo1->lastInsertId();
|
|
|
|
// ── Map user as owner ─────────────────────────────────────
|
|
$sth = $pdo1->prepare("
|
|
INSERT INTO company_map_user (company_id, user_id, role, created_at)
|
|
VALUES (:company_id, :user_id, 'owner', NOW())
|
|
");
|
|
$sth->execute([':company_id' => $company_id, ':user_id' => $user_id]);
|
|
db_check($sth, $answer);
|
|
|
|
// ── Set as default company for this user ──────────────────
|
|
$sth = $pdo1->prepare("UPDATE user SET default_company = :c, `status` = 'active' WHERE user_id = :u");
|
|
$sth->execute([':c' => $company_id, ':u' => $user_id]);
|
|
db_check($sth, $answer);
|
|
|
|
// ── Save SMTP ─────────────────────────────────────────────
|
|
$sth = $pdo1->prepare("
|
|
INSERT INTO company_smtp
|
|
(company_id, server, port, username, password,
|
|
from_name, from_email, encryption, updated_at)
|
|
VALUES
|
|
(:company_id, :server, :port, :username, :password,
|
|
:from_name, :from_email, :encryption, NOW())
|
|
");
|
|
$sth->execute([
|
|
':company_id' => $company_id,
|
|
':server' => $smtp_host,
|
|
':port' => $smtp_port,
|
|
':username' => $smtp_username,
|
|
':password' => $encrypted_pass,
|
|
':from_name' => $company_name,
|
|
':from_email' => $email ?: $smtp_username,
|
|
':encryption' => $smtp_encryption,
|
|
]);
|
|
db_check($sth, $answer);
|
|
|
|
// ── Clear onboarding session ──────────────────────────────
|
|
unset(
|
|
$_SESSION['onboarding_user_id'],
|
|
$_SESSION['onboarding_name'],
|
|
$_SESSION['onboarding_email']
|
|
);
|
|
|
|
$answer['success'] = 1;
|
|
$answer['message'] = 'Setup complete.';
|
|
|
|
} catch (Exception $e) {
|
|
error_log('[onboarding] ' . $e->getMessage());
|
|
$answer['message'] = 'Setup failed. Please try again.';
|
|
http_response_code(500);
|
|
}
|
|
|
|
exit(json_encode($answer));
|
|
?>
|