Files
wms-app/docs/reviewed
Thanakorn SandClaude Sonnet 4.6 cb36d3b8fd Document lifecycle review: spec updates and C2/M9 code fixes
Spec (docs/reviewed/document-lifecycle.md):
- C1: Correct GlManager::delete() description — reversal entry, not hard delete
- C3: Clarify PO status 2/3 are derived (receipt_status), never stored
- C4: Add invoice status=2 (Paid/Settled) to status table
- C5: Add full Receipt/Payment Billing Note lifecycle section
- C6: Add Quotation status table and transition rules
- C7: Document soft-delete tombstone mechanism (company_id negation)

Code (InvoiceManager.php):
- C2: voidInvoice() now blocks on active credit notes, posted receipt
  billing notes, and posted payment billing notes in addition to the
  existing receipt/payment checks
- M9: softDelete() skips assertPostingWindow for draft invoices (status=0)
  since drafts have no GL entry and no accounting impact

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-26 16:23:46 +07:00
..
2026-05-26 13:10:54 +07:00

MN3 WMS Feature Documentation

This folder documents the main product features discovered from the current PHP codebase.

The app is split into three operating areas:

  • WMS: warehouse operations, stock movement, sales and purchase workflows.
  • Accounting: revenue, expense, finance, journals, batch GL posting, and financial reports.
  • Master Data: shared setup for products, locations, contacts, chart of accounts, departments, formulas, and posting rules.

Documents

Architecture

Cross-Cutting Specs

  • Running Number — document number format, sequences, manual entry, gap policy
  • Session Concurrency — single-session enforcement, heartbeat, PHP GC stale detection, single-factor auth
  • Live Dashboard — real-time Socket.IO events, section reload map, flash card effect
  • Role Guards — CRUD access matrix per role
  • Soft Delete — mechanism, downstream blocks, stock/GL side effects, deletion order

Core Architecture

The UI is mostly PHP pages under app/, with AJAX endpoints under each module's api/engine or api/engine_report folder.

Common backend behavior is concentrated in manager classes:

  • app/assets/utils/classes/*Manager.php handles WMS, document, contact, product, finance, and report logic.
  • app/assets/utils/classes_ac/* handles accounting setup, GL posting, financial statements, posting windows, and tax reports.
  • app/assets/js/custom.js contains shared AJAX, pagination, account autocomplete, locks, batch processing, and display formatting helpers.

Cross-Cutting Rules

  • Company scoping is applied through company_id from the authenticated session.
  • Most write APIs load app/assets/utils/db_auth.php, which validates session, OTP freshness, CSRF token, and request payload.
  • Role checks use require_role() where a route is limited to owners/admins.
  • Audit logs are stored as JSON in many business tables through the $logging object from db_auth.php.
  • Numeric display uses shared frontend formatting to suppress floating point noise and avoid scientific notation in the UI.