Files
wms-app/app/login/api/engine/reset_password_otp.php
T
Thanakorn SandClaude Sonnet 4.6 b07882e3f4 code audit fixes: require_once, issue flow, role guards
- Upgraded all plain `require` to `require_once` across 172 api/engine
  and api/engine_report files to prevent class-redeclaration errors
- Added issue button, issue_invoice() with GL toastr, and delete_invoice()
  to expense/manage_purchase_invoice.php, bringing it in line with
  po/manage_purchase_invoice.php
- Added can_delete role guard (admin/owner only) to trash icons on
  revenue/invoice.php and expense/purchase_invoice.php, matching the
  existing pattern in finance/receipt.php and finance/payment.php

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-23 17:06:08 +07:00

19 lines
563 B
PHP

<?php
require_once '../../../session.php';
define('UNAUTHENTICATED_ROUTE', true);
require_once '../../../assets/utils/db_auth.php';
if (empty($_SESSION['reset_user_id'])) {
http_response_code(400);
$answer['message'] = 'No active reset request. Please request a new OTP.';
exit(json_encode($answer));
}
$user_id = (int)$_SESSION['reset_user_id'];
require_once '../../../assets/utils/classes/PasswordResetManager.php';
$manager = new PasswordResetManager($pdo1, $pdo2, $include_url, $SMTP, $pinkey);
$manager->handleConfirmReset($user_id, $data);