Commit Graph
6788 Commits
Author SHA1 Message Date
objecttothis 0d4ebca323 Merge branch 'master' into feature-complete-russian-and-azerbaijani-translations 2026-08-31 13:10:38 +04:00
objecttothis 8cfd1a4b1d fix(sales): enforce reports_sales grant on search endpoint (#4673)
- Sales::getSearch now enforces reports_sales grant before running
  search, returns 403 with lang message when missing
- Rename snake_case helpers/methods to camelCase across
  Sales controller, Sale model, and tabular_helper
  (get_sale_data_row -> getSaleDataRow, get_payments_summary ->
  getPaymentsSummary, sales_headers -> salesHeaders, etc.)
- Config/OSPOS: reset DB data cache before checking app_config
  table existence to avoid stale schema cache in tests
- TestDatabaseBootstrapSeeder: expose static reset() so tests can
  rebuild schema once per class instead of only via seeder run()
- SalesControllerTest: bootstrap DB once per class, seed once,
  refresh app settings each setUp, add tests for search endpoint
  authorization (cashier denied, supervisor allowed), move
  createTestItem into shared ItemFixtureTrait

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-08-31 13:08:33 +04:00
objecttothis caa6744f4c Merge branch 'master' into feature-complete-russian-and-azerbaijani-translations 2026-08-28 11:24:38 +04:00
objecttothis d63d31700d Ensure payload data is escaped to prevent XSS (#4664)
fix(barcode): escape payload fields to prevent XSS; PSR-12 refactor

- Apply `esc()` to name, ID, item number, category, and company name in `Barcode_lib` payloads
- Remove redundant `urldecode()` in `Item_kitsController` to prevent triple decoding
- Rename variables and methods to camelCase across barcode, item_kits, and tests
- Add type hint for `$layoutType` parameter in `manageDisplayLayout`
- Add/update unit tests covering escaping and HTTP response assertions

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-08-28 10:08:31 +04:00
objecttothis a35372dbe8 Merge branch 'master' into feature-complete-russian-and-azerbaijani-translations 2026-08-27 13:21:25 +04:00
objecttothis 84bddcdd88 Feature admin account safeguards (#4657)
fix(employees): harden permissions UI and access control

- Prevent admins from removing their own minimum module grants (employees, home, office)
- Add session_status check before session regeneration
- Disable submit button and return no_access view for AJAX requests
- Replace fade class with active-only for Bootstrap compatibility
- Update permission toggle selectors to .module-toggle
- Add error_cannot_remove_own_minimum_grant translations for Armenian, Bulgarian, Georgian, Swedish, and Ukrainian

---------

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-08-27 11:29:32 +04:00
objecttothis 414e9dc909 fix(i18n): refine Azerbaijani translation for "no_reports_to_display" in Reports.php
Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-08-25 18:28:12 +04:00
objecttothis aebe1185f2 fix(i18n): refine phrasing for "change_all_to_serialized" and "change_all_to_unserialized" in Russian translations
- Improved clarity and consistency for serialized item messages in Items.php.

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-08-25 18:26:31 +04:00
objecttothis c3cc3eaf71 Merge branch 'master' into feature-complete-russian-and-azerbaijani-translations 2026-08-25 18:23:21 +04:00
objecttothis 944697e68e fix(i18n): remove period from "definition_successful_adding" message in English
Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-08-25 18:22:28 +04:00
objecttothis 904c136f68 fix(i18n): correct phrasing for "print_delay_autoreturn" in English and Russian translations
- Swapped messages for clarity and consistency in required field and numeric value validations.

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-08-25 17:39:00 +04:00
objecttothis 7f40ce0d2c fix(i18n): improve phrasing for required field messages in Russian translations
- Updated wording in Attributes.php and Suppliers.php to enhance clarity and accuracy in required field messages.

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-08-25 17:35:14 +04:00
objecttothis d45cbc3767 fix(i18n): update Azerbaijani and English translations for "cost" and "cost_price" keys in Reports.php
- Cost is the total cost to purchase the item which includes wholesale, shipping, import duties, etc. Wholesale should not be conflated with cost price because wholesale is only the amount the supplier charges for the item.

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-08-25 17:24:30 +04:00
objecttothis 101a093ba1 fix(i18n): update Azerbaijani translation for "powered_by" key in Common.php
Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-08-25 16:58:01 +04:00
objecttothis 8b0f8533de fix(email): update method call to camelCase for PSR-12 compliance (#4659)
Corrected `check_encryption()` to `checkEncryption()` to align with coding standards.

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-08-24 21:46:12 +04:00
objecttothis 64ca4ef020 fix(i18n): correct Russian translations for attribute-related messages
- Updated wording for "definition_successful_adding" and "definition_successful_updating" in Russian Attributes.php to ensure clarity and accuracy.

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-08-24 17:00:10 +04:00
objecttothis 9d59f8cc7e fix(i18n): correct Azerbaijani and English translations for attribute-related messages
- Updated wording for "definition_successful_adding" and "definition_successful_updating" in Azerbaijani and English to ensure consistency and accuracy.

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-08-24 16:56:35 +04:00
objecttothis 7c8e392021 fix(i18n): address misplaced keys and duplicate entries in Azerbaijani and Russian language files
- Corrected placement of `definition_invalid_group` in Azerbaijani Attributes.php.
- Removed duplicate `toggle_cost_and_profit` key in Azerbaijani and Russian Reports.php.
- Reorganized keys in Russian Config.php for better alignment and added shortcuts-related keys.

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-08-24 16:49:20 +04:00
objecttothis 2fd86291ba fix(i18n): standardize Russian language file formatting and improve translations
- Replaced inconsistent double quotes with single quotes across all keys/values for better alignment with project conventions.
- Fixed translation errors, updated missing strings, and corrected inaccuracies in multiple modules such as Attributes, Calendar, Employees, etc.
- Enhanced clarity and consistency in phrases while ensuring accurate localization.

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-08-24 16:31:11 +04:00
objecttothis 7086b057a6 fix(i18n): align Azerbaijani language files with EN reference, format keys/values consistently
- Corrected typos, standardized translations, and fixed formatting in Azerbaijani language files for better consistency.
- Aligned language keys and values with EN reference, ensuring proper indentation and `'` usage.
- Updated invalid or missing translations in attributes, calendar, cashups, common, employees, enum, error, and expenses modules.

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-08-24 16:30:44 +04:00
objecttothis c701d21886 fix(sales): gate per-record endpoints behind reports_sales grant (#4627)
fix(sales): gate per-record endpoints behind reports_sales grant (REDACTED)

Cashiers holding only the base `sales` grant could reach per-sale endpoints
(getRow, getEdit, postSave, getReceipt, getInvoice, getSendPdf, getSendReceipt)
that require `reports_sales`. getManage() enforced this at the list level, but
individual endpoints did not re-check. Regression tests added.

Auth:
- Introduce `IsLoggedIn` filter to centralize login checks across controllers
- Replace custom `AccessDeniedRedirectException` with built-in `RedirectException`

Employees:
- Add `DISALLOW_PASSWORD_CHANGE` and `DISALLOW_GRANT_CHANGE` env vars to restrict
  credential and permission changes in locked-down environments
- Extract `hasGrantsChanged()` to streamline `postSave`

Refactor:
- Rename snake_case variables to camelCase in Sales, Items, and Employees
  controllers for PSR-12 compliance
- Use explicit `db_connect()` for transaction clarity in Items controller

Fixes:
- SMTP config entries fall back to defaults via null coalescing
- Migration uses `DROP FOREIGN KEY` instead of `DROP CONSTRAINT`
- Password hash upgrade only sets session on successful `hash_version` update
- Correct lang key for unknown error in Module model

Language:
- Translate `error_grant_change_disallowed` / `error_password_change_disallowed`
  across all 44 supported locales with => alignment matching en reference
- Fix "cannot be deleted" messages and misc typos across ~15 language files

Tests:
- Bootstrap seeder only once in ItemsCsvImportTest; close connection after
- Restore `DISALLOW_GRANT_CHANGE` in teardown to prevent side effects
- Use `uniqid()` for test user data to avoid collisions

Signed-off-by: 17935339+objecttothis@users.noreply.github.com
2026-08-23 17:40:06 +04:00
objecttothis 9ee530e454 Hotfix: Fix CI3 database migration caused by regression (#4649)
* refactor: standardize function and variable names to camelCase and improve naming consistency across files

* refactor(config): remove spaces around `=` in configuration files for improved consistency and formatting as is required by .env formatting rules.

* refactor(security): extract `.env` key management logic into reusable `writeEnvKey` helper, add throttle key provisioning logic, and streamline encryption key updates

* fix(migration): improve error handling in CI3 to CI4 encryption data migration
- Secure `up` and `convertCI3EncryptedData` methods with detailed exception handling for script execution and data saving.

* fix(migration): ensure empty string is correctly handled in CI3 to CI4 encryption data conversion

* refactor(security): enhance `.env` management with durable writes, better locking, and helper abstraction
- Update `writeEnvKey` to return a success flag and handle file locks robustly.
- Introduce `atomicWriteFile` for atomic writes to prevent partial file updates.
- Add `applyEnvKeyReplacement` to streamline `.env` key insertion and updates.
- Improve throttle key provisioning with validation and runtime persistence safeguards.

* refactor(security): implement dedicated `.env` file locking for robust and cross-platform safe write operations
- Add `lockEnvFile` and `unlockEnvFile` helpers to manage `.env` mutex files.
- Refactor `.env` write logic to use lock helpers, improving reliability and preventing race conditions.
- Enhance `atomicWriteFile` for better handling of file overwrites on Windows and POSIX systems.

* fix(migration): improve encryption error handling during CI3 to CI4 data conversion
- Add conditional checks for `checkEncryption` to prevent failed key persistence.
- Introduce `abortEncryptionConversion` for cleanup on failure.
- Update `writeEnvKey` to handle and return errors gracefully.

* refactor(security): improve `atomicWriteFile` for better file locking and cross-platform durability
- Replace `uniqid` with `bin2hex(random_bytes())` for more secure temp file naming.
- Add explicit file permissions and locking for safe concurrent writes.
- Enhance error handling to ensure atomicity on both Windows and POSIX systems.

* Add env temp files to gitignore so they don't get tracked.

---------

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-08-21 21:00:48 +04:00
objecttothis d081346528 Codeigniter changes between 4.7.2 and 4.7.4 (#4650)
Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-08-21 11:28:19 +04:00
objecttothis cc93c31355 fix(items): add explicit sentinel value for clearing supplier in bulk edit (#4617)
* fix(items): add explicit sentinel value for clearing supplier in bulk edit

This fixes a regression introduced in the fix for [REDACTED]
Introduce `Item::CLEAR_SUPPLIER_OPTION = 'NONE'` to distinguish between
\"leave supplier_id unchanged\" (empty string) and \"clear supplier_id\"
(sentinel). Previously, empty string was ambiguous.

- Add `CLEAR_SUPPLIER_OPTION` constant with doc comment explaining intent
- Update supplier dropdown to include sentinel as first real option
- Shift empty string to mean \"do nothing\" across all bulk edit fields

* test(items): add regression tests for mass assignment in bulk edit

Cover [REDACTED]: Item::update_multiple() bypasses model
$allowedFields via Query Builder, allowing unintended field writes
during bulk edit operations.

* fix(items): add type validation to bulk-edit field filter

filterBulkEditFields now validates field values before accepting them:
- Non-scalar values are rejected (array injection guard)
- Price/quantity fields are locale-parsed to floats, invalid strings skipped
- Boolean fields must be 0 or 1, other values skipped
- supplier_id must be numeric; CLEAR_SUPPLIER_OPTION still nulls it

Update tests to assert parsed types (float for prices, int for
supplier_id) and replace the fill-all-fields fixture with a realistic
input that only covers fields a form would actually submit.

* test(items): add supplier cleanup and helper methods to bulk update tests

- Track created supplier person IDs for teardown cleanup
- Delete supplier records in tearDown to prevent test pollution
- Extract item/supplier creation into reusable helper methods

* style(tests): rename variables to camelCase in ItemBulkUpdateTest

* refactor(items): rename snake_case variables to camelCase

Convert Item model, Items controller, and bulk update tests to
PSR-compliant camelCase naming per project conventions.

- Rename update_multiple to updateMultiple in Item model
- Rename local variables (item_data, items_to_update, tax_names, etc.)
  to camelCase across Items controller and Item model
- Update ItemBulkUpdateTest to use new updateMultiple method name
- Reorder and update AGENTS.md naming conventions

* style(tests): convert snake_case variables to camelCase in ItemBulkUpdateTest

Rename local variables and property names to camelCase for PSR-12
consistency, matching convention used elsewhere in new test code.
2026-08-20 11:24:50 +04:00
objecttothis 61bb1a2c2a hotfix(auth): hash throttler keys to improve security (#4646)
* fix(auth): hash throttler keys to improve security

- Use MD5 hashing for IP and username-based throttler keys to obfuscate sensitive data while maintaining functionality.

* test(auth): add IPv6 throttling test and hash used throttler keys

- Add a test to ensure throttling works correctly with IPv6 addresses.
- Update throttler keys to use MD5 hashes for IPs and usernames for improved security and consistency.

* fix(auth): handle non-scalar usernames in throttler keys

- Ensure username input is validated as scalar before processing to prevent errors and maintain throttling logic integrity.

* fix(auth): enhance throttler key security with HMAC hashing

- Replace MD5 with HMAC-SHA256 for generating throttler keys.
- Include encryption key from app configuration for added security.

* test(filters): update ThrottleTest to use HMAC-SHA256 for throttler keys

- Replace MD5 with HMAC-SHA256 for generating throttler keys in tests.
- Introduce `check_encryption()` to ensure encryption configuration is available.

* fix(events): validate encryption key on app initialization

- Throw ConfigException if encryption key is missing or invalid during `pre_system` event.
- Remove redundant `check_encryption()` call from Throttle filter and tests.

* fix(events): improve encryption key validation in `pre_system`

- Add `check_encryption()` helper call for additional security verification.
- Update error message to highlight `.env` writability issues if the key is invalid.

* test(filters): handle non-scalar usernames in ThrottleTest

- Update `makeRequest` to validate usernames as scalar and cast them to strings before processing.
- Add a test to ensure array usernames are ignored, and throttling is applied only based on IP.
- Improve status code assertions for throttled requests.

---------

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-08-20 02:27:13 +04:00
objecttothis 29a9b1a7e7 Bugfix: Resolve Race Condition in Rewards and Gift Card Spending (#4640)
* Implement atomic updates for gift card and reward point decrements, enhance error handling for insufficient balances, and add regression tests for concurrency safety.

* Add translations for insufficient gift card balance and reward points error messages across all supported languages.

* Reorder `clear_suspended_sale_detail` call to ensure transactional consistency.

* Reorder `clear_all` call to align with success and error handling logic.

* Ensure soft-deleted gift cards are excluded in balance updates.

* Refactor change_quantity logic with atomic upserts, improve error handling for insufficient stock, and update related tests and constants.

* Added check for NEW_ENTRY

* Added unit tests to test changes.

* Fix class name casing in ItemQuantityTest for consistency.

* Fix Bulgarian translations for insufficient balance error messages in Sales module.

* Fix Greek translations for insufficient balance error messages in Sales module.

* Fix Armenian translations for insufficient balance error messages in Sales module.

* Fix Tamil translations for insufficient balance error messages in Sales module.

* Implement race condition testing for database methods with concurrent process support.

* Fix class name casing in ItemTest for consistency.

* Improve concurrent process handling in race condition tests; add readiness and synchronization barriers.

* Improve handling of process I/O streams and timeout management in race condition tests.

* Add test for decrementing gift card value when marked as deleted

* Add `finally` block to ensure proper cleanup in async database race condition tests

* Improve error handling and timeout management in async database race condition tests.

* Refactor test utilities to use shared `EmployeeFixtureTrait` and `ItemFixtureTrait`.

* Track process exit codes explicitly in race condition tests for improved error detection and debugging.

* Improve error handling in `ConcurrentDbRaceTrait` by adding exceptions for `mysqli_poll` and `mysqli_reap_async_query`.

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>

---------

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-08-20 02:24:23 +04:00
objecttothis a2b91493c7 Feature: CodeIgniter Throttler (#4619)
* fix(auth): throttle login attempts to prevent brute-force attacks

Add Throttle filter and wire into login route to mitigate
credential-stuffing/brute-force risk (redacted).

- Register App\\Filters\\Throttle in Filters config
- Add \"too_many_attempts\" language string for throttled responses
- Add tests for Throttle filter and Login controller throttling

* Correct bug causing error to not display.


* i18n(login): add too_many_attempts translation for login throttling

Add localized \"too many attempts\" message across all language files
to support login throttling feature. Message informs users to wait
before retrying after exceeding attempt limit.

* fix(auth): rate limit login attempts to prevent brute-force attacks

Add Throttle filter that rate limits login/migrate POST requests,
keyed by IP and submitted username, using CodeIgniter's cache-based
Throttler (redacted).

- Wire filter into login/migrate routes
- Show localized error message when rate limit exceeded
- Broaden writable/cache ignore pattern to cover throttler cache file

* Update app/Language/ar-EG/Login.php

Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>

* style(i18n): use single quotes for translation array keys and values

Convert double-quoted array keys and string values to single quotes
across all Login.php language files for style consistency.

* test(auth): update LoginTest to use throttler service directly

Replace clearThrottleState's Services::resetSingle('throttler') call
with Services::throttler() to reset state via the service instance.
Add usedKeys property to track throttle keys used across test cases.

* test(auth): skip login test assertion when migration required

LoginTest now check migration-required response state before
asserting HTTP 200. Prevent false failures when app force
pending-migration redirect during test run.

* Added missing return statements
2026-08-19 00:25:22 +04:00
objecttothis 8bd2a51cb5 fix(items): validate item_number and skip receiving quantity default for temp items (#4621)
* fix(items): validate item_number and skip receiving quantity default for temp items

- Validate item_number against alpha_numeric_punct rule, return JSON error on failure
- Add item_number_invalid language string

* i18n: reorder Items language keys and add item_number_invalid string

Add item_number_invalid translation across all locale files and
resort surrounding keys alphabetically to match key ordering
convention.

* PSR-12 refactoring.

- Change local variable to camelCase.
- Use single quote in language files.

* i18n: translate item_number_invalid string in ta, th, tl, zh-Hans

Item_number_invalid key had English placeholder text in Tamil,
Thai, Tagalog, Chinese Simplified language files. Translate to
match each locale.

* fix(items): use FormatRules for item_number validation

* refactor(items): use camelCase for variable names

* refactor(items): use camelCase for variable names in Items controller
2026-08-18 02:51:42 +04:00
Sai Asish Yandobjecttothis 0e8fc0963a Reject item CSV imports whose header row is missing required columns (#4597)
* Reject item CSV imports whose header row is missing required columns

Signed-off-by: Sai Asish Y <say.apm35@gmail.com>

* Require all template columns when validating CSV import headers

Signed-off-by: Sai Asish Y <say.apm35@gmail.com>

* fix: derive required CSV import headers from the template generator

---------

Signed-off-by: Sai Asish Y <say.apm35@gmail.com>
Co-authored-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-08-14 14:05:43 +04:00
dependabot[bot] 65b99fea97 chore(deps): bump dompurify from 3.4.12 to 3.4.13 (#4639)
Bumps [dompurify](https://github.com/cure53/DOMPurify) from 3.4.12 to 3.4.13.
- [Release notes](https://github.com/cure53/DOMPurify/releases)
- [Commits](https://github.com/cure53/DOMPurify/compare/3.4.12...3.4.13)

---
updated-dependencies:
- dependency-name: dompurify
  dependency-version: 3.4.13
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-10 21:42:43 +04:00
dependabot[bot] 29f8f16459 chore(deps): bump codeigniter4/framework from 4.7.2 to 4.7.4 (#4638)
Bumps [codeigniter4/framework](https://github.com/codeigniter4/framework) from 4.7.2 to 4.7.4.
- [Release notes](https://github.com/codeigniter4/framework/releases)
- [Commits](https://github.com/codeigniter4/framework/compare/v4.7.2...v4.7.4)

---
updated-dependencies:
- dependency-name: codeigniter4/framework
  dependency-version: 4.7.4
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-09 19:58:14 +02:00
objecttothisandTravis Garrison 5c9b1b81e6 fix(xss): remove redundant escaping that double-encoded item attribute values (#4628)
* fix(xss): remove redundant escaping that double-encoded item attribute values

- Remove esc()/html_entity_decode() calls now that output is escaped
  at render time by the framework, preventing double-encoding of
  special characters in attribute names, units, and definition values
- Fix employee_name form_input value fields to stop pre-escaping
  before form_input applies its own escaping
- Reorder Items.php use statements and add missing BaseConnection import
- Change items/manage.php start_date from let to plain assignment for
  proper reassignment scope

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

* test(sales): add regression tests for permission checks on sales endpoints

- Ensure role-based permissions correctly restrict access to sensitive actions like price edits, receipt/invoice views, and report generation.
- Add tests for both granted and restricted user scenarios to validate the behavior.

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

* fix(attributes): validate `attribute_value` before processing

- Add checks to ensure `attribute_value` is a non-empty string in `postSaveAttributeValue` and `postDeleteDropdownAttributeValue` methods.
- Return error response if validation fails to prevent invalid data handling.

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

* fix(attributes): improve error handling and optimize affected items processing

- Use `array_column` for extracting item IDs to streamline logic.
- Add JSON validation with `JSON_THROW_ON_ERROR` and return proper error response for invalid `definition_values`.

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

* test(sales): enable database refresh for consistent test state

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

* test(sales): assert unauthorized message is displayed on restricted access

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

* refactor(attributes): use camelCase for `attributeValue` in controller methods

- Standardize variable naming in `postSaveAttributeValue` and `postDeleteDropdownAttributeValue` methods by switching to camelCase.

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

---------

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>
Co-authored-by: Travis Garrison <travis@chiraqbookstore.com>
2026-08-09 11:37:38 +04:00
richardmilles 08b0951a84 fix: use db_connect() for item save transactions (#4636)
postSave() called $this->db which is not set on the Items controller, causing Undefined property errors when saving items. Match the CSV import path and obtain the connection via db_connect().

Fixes #4623
2026-08-09 00:10:53 +02:00
objecttothisandTravis Garrison f5ba1709eb fix(security): sanitize filenames and escape logo path in config (#4630)
* fix(security): sanitize filenames and escape logo path in config

- Sanitize uploaded filename in Config.php via preg_replace, strip
  chars outside [a-zA-Z0-9_-] before storing raw_name
- Escape $logo_src with esc(..., 'attr') in info_config.php view to
  prevent XSS via crafted logo path/filename

Prevents stored XSS and path traversal from unsanitized filenames
used in config uploads.

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

* fix(config): sanitize uploaded config filenames

Replace inline regex filename sanitization with sanitize_filename()
helper to prevent path traversal via crafted upload filenames.

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

---------

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>
Co-authored-by: Travis Garrison <travis@chiraqbookstore.com>
2026-08-07 20:30:02 +04:00
Rayan Abdul Caderandobjecttothis aa96ad0284 refactor: apply PSR-12 naming to Attribute definition methods (#4624)
Renames the Attribute-specific definition methods from snake_case to
camelCase and updates every call site:

  get_definition_by_name   -> getDefinitionByName
  get_definition_names     -> getDefinitionNames
  get_definition_values    -> getDefinitionValues
  get_definitions_by_type  -> getDefinitionsByType
  get_definitions_by_flags -> getDefinitionsByFlags
  get_definition_flags     -> getDefinitionFlags

Also documents getDefinitionByName()'s return contract: a single
definition row as an associative array, or [] when none matches,
matching the getRowArray() behaviour introduced in #4464.

get_found_rows() and get_total_rows() are deliberately left alone -
they are declared across 15 models and renaming them only here would
break that shared convention.

Refs #4622

Co-authored-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-08-07 13:13:05 +04:00
objecttothisandTravis Garrison a5d70c07bb fix(auth): validate gcaptcha before password to prevent bypass (#4618)
* fix(auth): validate gcaptcha before password to prevent bypass

Move gcaptcha check before credential validation so a valid captcha
is required prior to any login attempt. Previously, password auth
ran first, allowing timing-based enumeration without captcha.

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

* test(auth): add regression tests for gcaptcha validation order in OSPOSRules

Guards fix from 5dea748b0: gcaptcha must be validated before
Employee::login() is attempted to prevent auth bypass.

Change gcaptcha_check visibility to protected to allow testing.

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

---------

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>
Co-authored-by: Travis Garrison <travis@chiraqbookstore.com>
2026-08-07 02:27:33 +04:00
objecttothisandTravis Garrison 35f056ce69 refactor(migrations): rename execute_script to executeScript across all migrations (#4611)
Align migration helper function calls with PSR-12 camelCase naming convention.
Affects all migration files from initial schema through recent upgrades.

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>
Co-authored-by: Travis Garrison <travis@chiraqbookstore.com>
2026-08-07 02:26:43 +04:00
objecttothisandTravis Garrison 0808ffae0d fix(sales): escape quote number in email template to prevent XSS (#4625)
Wrap $quote_number output with esc() in quote_email.php. Raw
interpolation allowed injected HTML/JS via quote number field.

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>
Co-authored-by: Travis Garrison <travis@chiraqbookstore.com>
2026-08-07 02:21:19 +04:00
objecttothisandTravis Garrison 3bafa07e04 fix(sales): enforce server-side authorization for price changes (#4631)
Client-side \"change_price\" flag is UI-only, not trustworthy. Compare
submitted price against current cart price server-side and require
sales_change_price grant when they differ, else reject with
not_authorized error.

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>
Co-authored-by: Travis Garrison <travis@chiraqbookstore.com>
2026-08-07 02:20:01 +04:00
2c69dc0c34 fix(config): validate theme param to prevent XSS via invalid theme (#4620)
* fix(config): validate theme param to prevent XSS via invalid theme

Add validation rule for theme field before batch save, rejecting
requests with unrecognized theme values. Add test coverage for
theme validation in postSaveGeneral.

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

* Update app/Config/Validation/OSPOSRules.php

Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>

---------

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>
Co-authored-by: Travis Garrison <travis@chiraqbookstore.com>
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
2026-08-07 02:18:44 +04:00
0a4c418690 fix: get_definition_by_name() returns single row instead of multi-dimensional array (#4452) (#4464)
Co-authored-by: jekkos <jekkos@users.noreply.github.com>
Co-authored-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-08-06 12:27:13 +04:00
6e273a2fb1 refactor: Replace var with let/const in JavaScript files (#4503)
* refactor: Replace var with let/const in JavaScript files

- Replace var with let for variables that are reassigned
- Replace var with const for variables that are never reassigned
- Modernize manage_tables.js and nominatim.autocomplete.js
- Skip third-party libraries (imgpreview.full.jquery.js, clipboard.min.js)

Closes #4491

* refactor: Replace var with let/const in inline JavaScript

- Fixed CodeRabbit review: changed enable_actions and load_success
  from const to let in manage_tables.js (they are reassigned in init)
- Replaced all var declarations in inline JavaScript in Views with
  let (for reassigned) or const (for never reassigned)
- Modernized 48 additional files with inline JavaScript

* refactor: Replace var with let/const in remaining JS files

- Modernized gulpfile.js: 3 var declarations replaced
- Modernized app/Views/errors/html/debug.js: all var declarations replaced
- Used const for never-reassigned, let for reassigned variables

* fix: Replace remaining var declarations in Views

- Changed var  to const in sales/register.php
- Changed var  to const in configs/receipt_config.php

These were missed in the initial pass.

* fix: Replace remaining var declarations in gulpfile.js

- Converted 12 remaining var declarations to const
- All variables are function-scoped and never reassigned
- Complete coverage for this file now

* fix: Address CodeRabbit review comments

- items/manage.php: Remove duplicate let declaration for start_date
  (partial/daterangepicker already declares it)
- header_js.php: Escape CSRF hash in JavaScript context
- tax_jurisdictions.php: Fix mismatched selector (remove_tax_jurisdictions
  -> remove_tax_jurisdiction)

* style(views): Replace var with let/const and fix comment casing

- Convert var to let in items/manage.php for JS modernization
- Capitalize \"Submit\" in validation comments across tax view files

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

---------

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>
Co-authored-by: Ollama <ollama@steganos.dev>
Co-authored-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
Co-authored-by: Travis Garrison <travis@chiraqbookstore.com>
2026-08-06 12:15:45 +04:00
c0abf80c86 fix: Wrap postSave() in single transaction for atomicity (#4506)
* fix: wrap postSave() in single transaction for atomicity

- Remove internal transaction from Item_taxes->save_value() to allow controller-level transaction
- Wrap entire save sequence (item, taxes, quantities, inventory, attributes) in single transaction
- Ensure all operations succeed or all fail together
- Prevents partial writes when saveItemAttributes() fails after item/tax/quantity saves succeed

Fixes #4474

* fix: Use explicit transBegin/transCommit/transRollback for atomicity

- Replace transStart/transComplete with transBegin/transCommit/transRollback
- Check all success conditions before committing
- Explicit rollback on failure

Address CodeRabbit review feedback

* refactor(items): rename postSave locals to camelCase per PSR-12

Convert snake_case variables to camelCase in postSave() and related
item-save logic to match project naming convention for new methods.

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

---------

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>
Co-authored-by: Ollama <ollama@steganos.dev>
Co-authored-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
Co-authored-by: Travis Garrison <travis@chiraqbookstore.com>
2026-08-06 12:04:16 +04:00
cdf477f823 fix(login): skip auth validation on new install to allow migration (#4609)
* fix(login): skip auth validation on new install to allow migration

On fresh installs with no DB version, login validation would fail
before migrations could run. Check MY_Migration::getCurrentVersion()
and bypass credential check when no version exists.

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

* fix(login): distinguish DB unavailable from empty install

`getCurrentVersion()` previously returned `int` with 0 used for both
\"empty database\" and \"DB connection failure\". This conflated two
distinct states, causing login to skip auth when DB was unreachable.

Changes:
- Return type widened to `?int`: null = DB unavailable, 0 = confirmed
  empty DB (new install), positive int = migrated
- Login controller now returns 503 on null (DB error) before checking
  isNewInstall
- isNewInstall gate now uses `=== 0` instead of falsy check

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

* fix(login): return 503 JSON response when DB connection unavailable

Extract getCurrentVersion() before building data array to distinguish
null (connection failure) from 0 (new install). Return early with JSON
503 when DB is unreachable instead of rendering broken view.

Update return type hint to include ResponseInterface.

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

---------

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>
Co-authored-by: Travis Garrison <travis@chiraqbookstore.com>
Co-authored-by: jekkos <jekkos@users.noreply.github.com>
2026-08-05 11:48:05 +04:00
objecttothisandTravis Garrison 8e465f9256 chore(deps): bump lodash.template from 4.5.0 to 4.18.1 (#4616)
Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>
Co-authored-by: Travis Garrison <travis@chiraqbookstore.com>
2026-08-04 17:58:50 +04:00
objecttothisandTravis Garrison 734c7d291c chore(deps): add xlsx via SheetJS CDN and upgrade tableexport plugin (#4615)
- Add xlsx 0.20.3 from SheetJS CDN via package overrides
- Bump tableexport.jquery.plugin from ^1.30.0 to ^1.33.0
- Add xlsx bundle to gulp JS pipeline before tableexport

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>
Co-authored-by: Travis Garrison <travis@chiraqbookstore.com>
2026-08-04 17:57:41 +04:00
dependabot[bot] 337cc098f2 chore(deps): bump brace-expansion (#4614)
Bumps  and [brace-expansion](https://github.com/juliangruber/brace-expansion). These dependencies needed to be updated together.

Updates `brace-expansion` from 1.1.12 to 1.1.18
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](https://github.com/juliangruber/brace-expansion/compare/v1.1.12...v1.1.18)

Updates `brace-expansion` from 2.1.0 to 2.1.4
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](https://github.com/juliangruber/brace-expansion/compare/v1.1.12...v1.1.18)

---
updated-dependencies:
- dependency-name: brace-expansion
  dependency-version: 1.1.18
  dependency-type: indirect
- dependency-name: brace-expansion
  dependency-version: 2.1.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-04 17:15:13 +04:00
objecttothisandTravis Garrison 89677cb8f2 chore(deps): upgrade dompdf from v2.0.8 to v3.1.6 (#4610)
- Update dompdf/dompdf constraint from ^2.0.3 to ^3.1.6
- Dependency names changed: phenx/php-font-lib and phenx/php-svg-lib
  replaced by dompdf/php-font-lib and dompdf/php-svg-lib ^1.0.0
- Remove ThirdParty/dompdf path from Autoload.php psr4 namespace map
- Update composer.lock with new content hash and package references

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>
Co-authored-by: Travis Garrison <travis@chiraqbookstore.com>
2026-08-01 00:24:02 +02:00
objecttothisandTravis Garrison 2fbe746c95 style(models): normalize quote style in SQL GROUP_CONCAT expression (#4608)
Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>
Co-authored-by: Travis Garrison <travis@chiraqbookstore.com>
2026-07-30 15:21:29 +04:00
objecttothisandTravis Garrison 231e716c14 bugfix(reports): crash on detailed sales report when sale has multiple payments with reference codes (#4599)
* fix(sales): aggregate reference codes for multi-payment sales

Use GROUP_CONCAT to combine multiple payment reference codes into a
single comma-separated value, and group only by sale_id to correctly
handle sales with multiple payment records.

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

* docs(agents): update AGENTS.md with expanded coding standards

- Clarify PSR-12 enforcement via PHP-CS-Fixer config reference
- Bump minimum PHP version requirement from 8.1 to 8.2
- Add JavaScript const/let/var convention rule
- Reorganize coding standards section for clarity

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

* fix(sales): exclude empty strings from payment reference code aggregation

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

---------

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>
Co-authored-by: Travis Garrison <travis@chiraqbookstore.com>
2026-07-28 14:23:54 +04:00