Commit Graph
6820 Commits
Author SHA1 Message Date
objecttothis e6852f31d1 Merge branch 'master' into feat-export-toggle-all 2026-10-07 17:56:18 +04:00
jekkos 1eaa22a226 docs: add test-method naming convention to AGENTS.md (#4735)
Name test methods test{MethodUnderTest}_{Behavior} (e.g.
testPostSave_RejectsNegativeTaxPercent) so they read as a
self-documenting sentence and need no docblock.
2026-10-06 09:01:56 +02:00
jekkosandobjecttothis 87d575683c fix(auth): return 401 JSON for AJAX requests on session timeout (#4728)
* fix(auth): return 401 JSON for AJAX requests on session timeout (#4696)

IsLoggedIn previously threw RedirectException('login') for every request
type. For XHR calls the browser transparently followed the 302 and fetched
the login page's HTML where JSON was expected, so the table silently
rendered empty and the failure looked like a broken sort.

- Server: IsLoggedIn::before() now returns a JSON 401 response when the
  request is an AJAX call, keeping the redirect behavior for normal
  navigations.
- Client: a global $(document).ajaxError handler in the authenticated
  layout redirects to the login URL on a 401 response.

* fix(auth): run isLoggedIn before csrf for expired sessions (#4696)

An expired-session AJAX POST with an invalid CSRF token was hitting the
globally-configured csrf filter first, which throws a CSRF exception before
isLoggedIn can return its 401. Reorder the global before-filters so the
authentication check runs before CSRF validation; CSRF protection is fully
retained for authenticated requests.

---------

Co-authored-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-10-05 16:16:25 +02:00
richardmillesandjekkos 3e68295f95 fix(expenses): refresh table when date range or filters change (#4633)
Restore the daterangepicker apply and filter change handlers so
/expenses/search receives the selected start_date and end_date
instead of today's date for both. Also removes leftover comments
from the expenses manage view.

Fixes #4596

---------

Co-authored-by: jekkos <jeroen.peelaerts@gmail.com>
2026-10-05 10:40:29 +04:00
2929945d0b fix(i18n): add missing toggle_cost_and_profit key to 32 locales (#4712)
* fix(i18n): add missing toggle_cost_and_profit key to 32 locales
* fix(i18n): put toggle_cost_and_profit in alphabetical order
---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Rayan Abdul Cader <minutechreview@users.noreply.github.com>
2026-10-05 10:13:55 +04:00
objecttothisandOllama 1b8ee2e3c1 feat(items): optimize search, attribute filtering, and sort for items view (#4652)
feat(items): optimize search, attribute filtering, and sort for items view (#4652)

BREAKING CHANGE: none

## Search & Query Optimization
- Split item search into two-phase query: Phase A resolves qualifying IDs,
  Phase B joins scoped display tables for better performance and readability
- Sanitize `definition_ids` via `array_map` to prevent injection vulnerabilities
- Introduce subquery for SUM aggregation to prevent over-counting across joins
- Add validation requiring both start and end dates before applying date range filter

## Attribute Search (fixes #2919, #2722)
- Add `SHOW_IN_SEARCH` flag (value 8) to Attribute model to separate
  searchability from table visibility
- Add `parse_attribute_search()` to parse syntax like `color:blue AND size:large`
- Add `applyNamedAttributeSearch()` supporting decimal and date types with
  locale-aware parsing
- Support AND/OR logic for multi-attribute queries

## Sorting
- Add `get_attribute_sort_definition_id()` to detect attribute column sorting
- Join attribute tables dynamically when sorting by attribute columns
- Use `MAX()` for consistent results when sorting by attribute values
- Replace static sort column list with dynamic headers via `itemSortColumns()`
- Add `sanitizeSortColumnAttribute()` to validate attribute definition IDs as sort columns

## Tax & Data Row
- Streamline tax computation in `getItemDataRow()`

## Low Inventory Filter
- Require valid `stock_location_id` before applying low inventory filter
- Add conditional logic to sort by sum of quantities across all locations
  when `stock_location_id` is invalid

## Localization
- Add `show_in_search` / `show_in_search_visibility` strings to all language files
- Translated: de-DE, es-ES, fr, it; English placeholder for remaining locales
- Unify single-quote style across all attribute language files

## Refactoring & Style
- Adopt camelCase naming throughout (variables, helpers, methods)
- Replace `sanitizeSortColumnAttribute` with reusable `sanitizeSortColumn`
  from `Secure_Controller`
- Simplify column key extraction using `array_key_first`
- Apply PSR-12 formatting

## Tests
- Add tests for tax computation, quantity aggregation (single- and multi-location),
  named attribute search, free-text parsing, and date/decimal type handling
- Add `ensureStockLocation` helper to auto-create missing stock locations in tests
- Refactor tests to handle config cache issues

Co-authored-by: Ollama <ollama@steganos.dev>
2026-10-02 14:56:20 +04:00
dependabot[bot]andobjecttothis 9e06a231a7 chore(deps): bump brace-expansion (#4721)
Bumps  and [brace-expansion](https://github.com/juliangruber/brace-expansion). These dependencies needed to be updated together.

Updates `brace-expansion` from 1.1.18 to 1.1.21
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](https://github.com/juliangruber/brace-expansion/compare/v1.1.18...v1.1.21)

Updates `brace-expansion` from 2.1.4 to 2.1.7
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](https://github.com/juliangruber/brace-expansion/compare/v1.1.18...v1.1.21)

---
updated-dependencies:
- dependency-name: brace-expansion
  dependency-version: 1.1.21
  dependency-type: indirect
- dependency-name: brace-expansion
  dependency-version: 2.1.7
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-10-02 14:34:32 +04:00
dependabot[bot]andobjecttothis 90feb434eb chore(deps): bump moment from 2.30.1 to 2.31.0 (#4722)
Bumps [moment](https://github.com/moment/moment) from 2.30.1 to 2.31.0.
- [Release notes](https://github.com/moment/moment/releases)
- [Changelog](https://github.com/moment/moment/blob/develop/CHANGELOG.md)
- [Commits](https://github.com/moment/moment/compare/2.30.1...2.31.0)

---
updated-dependencies:
- dependency-name: moment
  dependency-version: 2.31.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-10-02 14:18:33 +04:00
jekkos 348a8352cf fix(release): delete the unstable release by name, leave drafts alone 2026-10-02 06:03:29 +00:00
dependabot[bot] fd3d642a8e chore(deps): bump dompurify from 3.4.13 to 3.4.16 (#4723)
Bumps [dompurify](https://github.com/cure53/DOMPurify) from 3.4.13 to 3.4.16.
- [Release notes](https://github.com/cure53/DOMPurify/releases)
- [Commits](https://github.com/cure53/DOMPurify/compare/3.4.13...3.4.16)

---
updated-dependencies:
- dependency-name: dompurify
  dependency-version: 3.4.16
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-01 20:11:07 +02:00
github-actions[bot] 89c6d5a3e9 chore: bump version to 3.4.3 2026-09-30 16:27:25 +00:00
github-actions[bot] cb5e2a16a9 docs: add 3.4.2 changelog 3.4.2 2026-09-30 16:27:22 +00:00
jekkos 7aa624c8ea chore: reset 3.4.2 (undo premature 3.4.3 bump + stale changelog) for re-cut 2026-09-30 16:23:17 +00:00
b9ad77ba07 fix(security): report unwritable .env.lock, make throttle limits configurable (#4714)
* fix(security): report unwritable .env.lock, make throttle limits configurable

envFileIsWritable() previously checked is_writable(.env) (the file), which passes in Docker even when the mutex file is root-owned by a prior env:provision run. It now checks the real write path: the directory (to create .env.tmp.* + .env.lock) and any existing .env.lock must be writable, so the app throws the clear 'run env:provision' error instead of crashing on 'Unable to open .env.lock'.

The Throttle filter now reads throttle.capacity / throttle.seconds from env (default 5 per 60s); capacity <= 0 disables throttling, so operators serving sequential HTTP clients (e.g. Zabbix) are not caught by the lockout.

* fix(security): address CodeRabbit review findings

- Throttle: validate throttle.capacity as an integer before treating a non-positive value as 'disabled', so a non-numeric value (e.g. 'five') falls back to the default instead of silently bypassing the lockout. Apply the same validation to throttle.seconds.

- envFileIsWritable(): also reject an existing non-writable .env on Windows (where rename() cannot replace a read-only destination); keep the check Windows-only since POSIX rename() replaces a read-only dest when the directory is writable.

- Tests: restore the prior throttle.capacity env state in ThrottleTest (capture/restore instead of delete); add an invalid-capacity fallback case; skip the not-writable fixtures when running as root (where is_writable() is bypassed).

* fix(migration): guard ConvertToCI4 key-write branches with envFileIsWritable()

The migration's 'no key' and 'CI3 key' branches called rotateEncryptionKey()/rotateEncryptionKeyTransaction() directly, bypassing the envFileIsWritable() guard that checkEncryption() uses. On a fresh Docker/Compose install where the web runtime cannot write /app/.env.lock, this produced a raw 'fopen(/app/.env.lock): Permission denied' error instead of the actionable 'run php spark env:provision' message.

A valid CI4 key now short-circuits to checkEncryption() (no write); every write branch is gated on envFileIsWritable() first.

* fix: read provisioned encryption.key so config sees it

env:provision persists the key as 'encryption.key' in .env (matching the
throttle path and .env.example), but Config\Encryption only read the
ENCRYPTION_KEY env var. On a fresh Docker instance the provisioned key was
invisible to config('Encryption')->key, so the app believed no key existed
and tried to write one -- hitting the .env.lock permission wall.

Read encryption.key (via $_SERVER/$_ENV/getenv) first, then fall back to
ENCRYPTION_KEY for Docker '-e' usage. Mirrors checkThrottleEncryption().

* fix: cascade encryption.key lookup past empty-string sources

* refactor: extract Encryption::resolveKey() and test it without global env mutation

* fix(security): decode fallback-selected encryption key like BaseConfig

A key picked in the constructor fallback (notably ENCRYPTION_KEY, which
BaseConfig never inspects) was assigned verbatim, bypassing the
hex2bin:/base64: decode the parent applies to `encryption.key`. Route the
selected key through a parseKey() helper mirroring BaseConfig's
parseEncryptionKey() so prefixed values decrypt consistently, and add a
pure regression test.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* chore: remove advisory ID from comments and tighten verbose comments

Per review: treat GHSA advisory IDs like secrets (drop from code) and
replace the multi-paragraph comments with concise one-liners that keep
the non-obvious "why". No logic changes.

---------

Co-authored-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-09-30 15:50:11 +02:00
jekkos 9eaa2f34f3 chore: strip advisory IDs from code comments and changelog (#4720)
Per the project's policy of treating security advisory IDs as
secret-like, remove the identifiers embedded in source/test comments
and CHANGELOG entries. Each keeps its human-readable description (and
PR number where present), so traceability is preserved. No logic changes.
2026-09-30 15:49:18 +02:00
jekkos 5d56c2cecd fix(security): strip all HTML tags from $.notify alert messages (#4716) 2026-09-29 13:19:10 +02:00
jekkos 9cafea0eed fix(release): keep package-lock.json version in sync on bump (#4718)
* fix(release): keep package-lock.json version in sync on bump

The release bump step updated app/Config/App.php and package.json but
left package-lock.json on the old version, so the lockfile drifted out
of sync with package.json on every release. Bump the @opensourcepos/
opensourcepos package version in package-lock.json (top-level and
packages."") using the same scoped approach, and stage it in the bump
commit.

Fixes #4717

* fix(release): sync package-lock.json to 3.4.3 on master

Bump the @opensourcepos/opensourcepos version in package-lock.json
(top-level + packages."") from 3.4.2 to 3.4.3 to match package.json,
which was already bumped during the 3.4.3 dev bump. This repairs the
current drift introduced by the bump commit so the upcoming 3.4.3
release ships with package.json and package-lock.json in sync.

Part of #4717
2026-09-29 13:16:18 +02:00
jekkos dc1accc65a fix(security): HTML-escape attribute dropdown option labels in items attributes view (#4715) 2026-09-28 08:44:37 +02:00
github-actions[bot] 60f6c8f5d0 chore: bump version to 3.4.3 2026-09-24 20:52:03 +00:00
github-actions[bot] bcb91a5b25 docs: add 3.4.2 changelog 2026-09-24 20:52:00 +00:00
jekkos e298b6d82e fix(release): push changelog/bump to master via admin PAT (GITHUB_TOKEN blocked by branch protection) 2026-09-24 20:51:23 +00:00
jekkos 2da95e33b6 chore(release): unified git-cliff release workflow (changelog + tag + optional bump) (#4711)
* chore: unified release workflow (git-cliff changelog + tag + optional bump)

- cliff.toml: git-cliff config (commit.author.name, Weblate/version-bump excluded)
- release.yml: replaces the 'Release Version Bump' workflow with a single
  workflow that cuts the current release (changelog + tag + draft release)
  and optionally bumps App.php to the next dev version
- build-release.yml: add official-release job (draft GitHub Release with
  changelog + assets, triggered by tag push)

Supersedes the 'changelog only' scope: this now also handles tagging,
draft release, and the version bump in one place.

* fix(release): fail fast when a tag does not match the App.php version

Catches a manually-pushed mismatched tag before building, so a draft
release is never created without its archive.

* fix(release): move env block to step level (was inside run shell script)

The env: key was dedented into the run: | literal block, so the shell
would try to execute 'env:' as a command and abort the build.
2026-09-24 20:49:51 +02:00
ff9a465b90 fix(i18n): swap print_delay_autoreturn number/required messages in 5 locales (#4699)
Swap the swapped number/required validation strings in da, es-MX, ta,
en-GB, and tl to match the mapping used by other *_number/*_required
pairs and the receipt_config.php jQuery Validate wiring. Also clear
residual English autoreturn messages from non-English locales.

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Rayan Abdul Cader <minutechreview@users.noreply.github.com>
2026-09-24 10:37:57 +04:00
dependabot[bot]andobjecttothis d821cf8d3a chore(deps): bump fflate from 0.8.2 to 0.8.3 (#4690)
Bumps [fflate](https://github.com/101arrowz/fflate) from 0.8.2 to 0.8.3.
- [Release notes](https://github.com/101arrowz/fflate/releases)
- [Changelog](https://github.com/101arrowz/fflate/blob/master/CHANGELOG.md)
- [Commits](https://github.com/101arrowz/fflate/compare/v0.8.2...v0.8.3)

---
updated-dependencies:
- dependency-name: fflate
  dependency-version: 0.8.3
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-09-23 13:40:35 +04:00
jekkos ca3d982dc2 fix(ci): stop stamping app version onto master and branch Docker tags (#4709)
Closes #4695

Master and PR builds were tagging every Docker image with the App.php
version (e.g. 3.4.2-master-<sha>), flooding Docker Hub with tags for
versions that were never released.

Docker tags are now scoped to the ref:
- master  → master, <sha>
- branch  → <branch>-<sha>
- semver tag → <version>, latest

Additional hardening:
- Release tag trigger restricted to three-component semver (N.N.N) so
  non-semver tags (e.g. 3.preview) no longer publish a `latest` image
- Branch names sanitized: chars outside [a-zA-Z0-9_.-] replaced with _,
  total tag truncated to stay within Docker's 128-char limit, leading
  `.` or `-` prevented
- Fixed README.md claim that master builds push a `latest` tag
2026-09-23 13:38:31 +04:00
4e0466fbf1 fix(i18n): translate remaining English labels in Swiss German Items.php (#4701)
* fix(i18n): translate leftover English strings in de-CH Items.php

Replace remaining English UI labels in the Swiss German items locale
with German wording aligned to de-DE, preserving keys and placeholders.

Co-authored-by: Rayan Abdul Cader <minutechreview@users.noreply.github.com>

* fix(i18n): use plural Zeilen in de-CH csv_import_partially_failed

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Rayan Abdul Cader <minutechreview@users.noreply.github.com>
Co-authored-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-09-23 07:16:25 +02:00
jekkos 00b97c3302 feat(security): add THROTTLE_KEY env-var fallback for throttle.key (#4707)
checkThrottleEncryption() now consults the THROTTLE_KEY environment
variable when throttle.key is empty, mirroring the ENCRYPTION_KEY
fallback in Config/Encryption. This lets Docker/Compose deployments
supply the throttle HMAC secret without writing a shared value into a
read-only .env. An explicit throttle.key always takes precedence.

Adds regression tests to the existing security_helperTest suite and
documents THROTTLE_KEY in .env.example.
2026-09-22 23:30:05 +02:00
jekkos edcb4bb655 Fix GHSA-frx7-c5vv-m3mr: recompute cashup total server-side and force owner identity (#4706)
* Fix GHSA-frx7-c5vv-m3mr: recompute cashup total server-side and force owner identity

* Add required description field to cashup test POSTs
2026-09-21 17:37:07 +02:00
jekkos 47aade5024 fix(locale): validate language_code against known locales to block path traversal (#4704)
* fix(locale): validate language_code against known locales to block path traversal

postSaveLocale() stored language_code from user input with no allow-list validation, and it later flows into Language::setLocale()/load() where the locale segment is require()'d. An authenticated config-grant account could store a relative path (e.g. ../../public/uploads) and, combined with a planted file in public/uploads/, achieve unauthenticated RCE on the next request.

Validate the submitted language against array_keys(get_languages()) before storing, and harden languageExists() to reject path separators and dot-dot sequences. Adds regression tests.

* test(locale): give locale fixture valid reference-code min/max defaults

* fix(locale): reject null bytes in languageExists guard

A stored language_code containing a NUL byte passes the existing path-separator and parent-dir checks, then reaches file_exists(). On PHP 8.5+ file_exists() throws a ValueError for NUL-byte paths, which breaks configuration loading. Reject NUL bytes in the guard and add regression tests.
2026-09-21 17:36:50 +02:00
184918d914 fix(security): handle special characters in .env key values and improve insertion logic (#4656)
* fix(security): handle special characters in `.env` key values and improve insertion logic

- Escape backslashes and dollar signs in `applyEnvKeyReplacement` to prevent unintended value corruption.
- Ensure new keys are inserted after `encryption.key` for better organization and manageability.
- Add explicit cast to int to prevent wrong concatenation operator warning.

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>

* fix(security): handle null return in `applyEnvKeyReplacement` and ensure proper `.env` updates

- Update `applyEnvKeyReplacement` to return `null` on failure, improving error handling.
- Adjust calls to `atomicWriteFile` with updated content to prevent unintended behavior.

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>

* fix(security): improve error logging and exception messages in file locking

- Add detailed logging for file open and locking errors in `security_helper`.
- Remove unused `helper` and `checkThrottleEncryption` calls from `Events` for cleanup.

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>

* fix(security): improve atomic file write and handle encryption key placement

- Throw `RandomException` for better error reporting in `atomicWriteFile`.
- Simplify Windows-specific `rename()` fallback logic.
- Fix `encryption.key` assignment order to ensure consistency in `.env` updates.

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>

* fix(security): improve `.env` file handling and add unit tests for helper functions

- Suppress warnings in `file_get_contents` to prevent unnecessary error logs.
- Update `applyEnvKeyReplacement` to use `preg_replace_callback` for better safety.
- Add comprehensive unit tests for `security_helper` functions to ensure `.env` updates and key management work as expected.

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>

* fix(security): enhance `.env` update logic and add robust exception handling

- Add `RandomException` to improve error reporting in encryption key management.
- Introduce environment file locking for safer `.env` updates.
- Ensure `applyEnvKeyReplacement` properly handles and inserts old key comments.
- Replace direct file writes with `atomicWriteFile` for consistency.

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>

* fix(security): refactor `.env` file initialization and encryption key handling

- Introduce `initializeEnvFile` for reusable `.env` setup logic.
- Add `backupEnvFile` and `writeNewEncryptionKey` for robust key management with backups.
- Simplify and clean up redundant `.env` handling code paths.

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>

* fix(security): clarify `checkEncryption` docblock return value description

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>

* fix(security): escape backslashes and dollar signs in `applyEnvKeyReplacement`

- Ensure `applyEnvKeyReplacement` properly escapes special characters when inserting or appending `.env` keys.
- Add new unit tests to validate correct handling of backslashes and dollar signs.

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>

* fix(i18n): add localized error messages and improve error reporting in `security_helper`

- Add missing translations for error messages across multiple language files.
- Update `security_helper` to use localized exception messages with placeholders.

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>

* Redesign encryption/throttle key provisioning as read-only runtime

- checkEncryption()/checkThrottleEncryption() are now read-only guards that
  throw when no valid key is provisioned, instead of writing .env at
  request time.
- Add rotateEncryptionKey() and provisionThrottleKey() for explicit,
  idempotent provisioning.
- Add php spark env:provision (app/Commands/EnvProvision.php) so Docker can
  provision keys once at container startup before any request.
- Add app/Libraries/CI3SecretConverter.php shared CI3->CI4 secret converter
  (AES-128-CBC decrypt + CI4 re-encrypt/verify/save) used by both the
  interactive migration and the docker startup path.
- Refactor convertToCI4 migration to use the shared converter.
- Persist .env in a named volume and run spark env:provision on boot; stop
  baking .env into the shipped image.
- Add guard/rotation/throttle + converter tests; clean up orphaned
  msg_pwd_required language keys across all locales.

* fix: save CI4 ciphertext in env:provision and bind-mount a .env file

Addresses CodeRabbit review on PR #4656:

- env:provision CI3 branch was persisting *plaintext* secrets (saveAll($plain))
  instead of the CI4 ciphertext, unlike the ConvertToCI4 migration. Now
  encrypts with encryptAll(), verifies the round trip, and saves the ciphertext.
- The ospos_env named volume mounted at /app/.env made .env a directory, so
  atomicWriteFile's rename() failed and spark env:provision could not start apache.
  Switch to a bind mount of a host file (./.env) which persists and stays a file.
- Add a regression test asserting the command persists ciphertext (not plaintext).

* chore: trim redundant docblocks in EnvProvision and provision throttle.key in CI

Follow up on @objecttothis review comments:
- app/Commands/EnvProvision.php: remove the boilerplate docblocks the
  property names already convey (group/name/usage/description, run()),
  the two inline step comments, the anyNonEmpty() param docblock, and the
  legacySecretsPresent() docblock. Keeps the class-level docblock since it
  is the only place that states the read-only runtime design + the
  never-persist-plaintext invariant.
- .github/workflows/phpunit.yml: provision a per-run throttle.key the same
  way the encryption key is already provisioned. The PR makes
  checkThrottleEncryption() a read-only guard that throws when
  env('throttle.key') is unset; CI only started exporting ENCRYPTION_KEY,
  so every test that goes through the Throttle filter (7 ThrottleTest
  cases + 4 LoginTest cases) failed with
  "No throttle key is provisioned. Run `php spark env:provision`".
  Writing `throttle.key=<KEY>` into .env matches what
  `php spark env:provision` does on a real container start.

* fix(ci): write throttle.key into .env instead of exporting an OS env var

The previous attempt exported throttle.key via GITHUB_ENV, but CodeIgniter's
env() helper resolves in the order $_ENV[$key] ?? $_SERVER[$key] ?? getenv($key),
and DotEnv populates $_ENV['throttle.key'] from the .env file first. Because the
.env (copied from .env.example) ships with the empty placeholder throttle.key='',
that $_ENV entry exists as '' and short-circuits the ?? chain before getenv()
is reached — so the OS env var was never consulted and every Throttle/Login test
still threw 'No throttle key is provisioned'.

Write the per-run key into the .env file itself (sed-replacing the empty
placeholder), which is exactly what `php spark env:provision` does in
production and is the single source env() actually reads from.

Verify the replacement happened (grep -Eq '^throttle\.key=.') so a future change
to the placeholder format fails the run loudly instead of silently breaking
the 11 throttle-dependent tests.

* fix(security): restore CI3->CI4 auto-provisioning gated by .env writability

checkEncryption()/checkThrottleEncryption() again provision the keys
inline when .env is writable (empty key -> generate; short key -> decrypt,
rotate, re-encrypt, verify, persist legacy CI3 secrets). When .env is not
writable they assume the key was provisioned externally (e.g. docker
env:provision) and throw. Update helper tests to match and correct the
EnvProvision docblock that claimed the runtime was strictly read-only.

* test(security): make short-key conversion branch injectable and test it

checkEncryption() now accepts an optional CI3SecretConverter so the
CI3->CI4 conversion branch can be exercised in unit tests without a
database. Adds testCheckEncryptionConvertsCi3ShortKeyWhenEnvWritable
which seeds CI3-era ciphertexts via a fake Appconfig model and asserts
the key is rotated and the payload verifies back to the original
plaintext.

* fix(security): abort on backup/read/saveAll failure to avoid data loss

Three related data-integrity fixes:

- backupEnvFile() now returns true/false based on whether the backup
  actually exists and is readable. rotateEncryptionKey() aborts before
  destroying the key when the backup could not be written to disk.

- rotateEncryptionKey() and provisionThrottleKey() throw
  RuntimeException(Error.unable_to_read_env_file) when the .env read
  fails, instead of silently replacing the whole file with an empty
  string. This prevents a permission error from wiping all keys.

- checkEncryption() and EnvProvision::run() now both roll back to the
  backup with abortEncryptionConversion() when the post-rotation
  saveAll() throws, matching the migration path (which already did this).
  A failing fake Appconfig is used to exercise this in the new
  testCheckEncryptionRollsBackWhenSaveAllFails test.

* fix(ci): skip comment job in deploy-pr.yml when prepare was not run

The comment job had if: always(), so it ran even when the prepare job
was skipped (e.g. review was not approved). With PR_NUMBER empty the gh
api call posted to issues//comments, received a 404, and the entire run
showed up as failure. Guard the job with
needs.prepare.result == 'success' so it only runs when PR_NUMBER is valid.

* address coderabbit open items: placeholder guards, message neutrality, ar-EG alignment

- backupEnvFile(): fail when mkdir() or either chmod() fails, so the
  pre-rotation backup is actually persisted before the key is replaced
- email/message config views: only show the 'already set' placeholder when
  the secret is actually present (prevented false positives on fresh installs)
- Error.unable_to_create_env_file / .unable_to_read_env_file (en + en-GB):
  use key-neutral wording since both keys are provisioned with the same keys
- ar-EG/Error.php: align all => arrows on the longest key

Item 7 (filesystem test isolation) is a larger refactor — the tests are
serial on CI and tearDown() restores state per test. Left for follow-up.

* test(security): isolate helper FS tests via Config\SecurityEnv

Introduce Config\SecurityEnv holding envPath/backupPath/lockPath so the
security helper reads its target paths from shared configuration instead of
hardcoded ROOTPATH/WRITEPATH literals. security_helperTest.php now redirects
all three to a unique per-run sandbox under sys_get_temp_dir() and tears it
down in tearDown(), so the suite no longer reads/writes the repository's real
.env and is safe to run in parallel.

No helper signature changes; production callers unaffected.

Addresses CodeRabbit item 7 (issue #4700).

Co-Authored-By: opencode <bot@opencode.ai>

* fix(security): run key-conversion as one locked transaction

Address CodeRabbit Major findings from the 4th re-review of the env
helper and its callers:

1. Hold .env.lock for the entire CI3 -> CI4 conversion transaction
   (backup -> rotate -> re-encrypt -> verify -> persist -> cleanup) so a
   concurrent worker cannot interleave a key write between the rotation
   and the ciphertext save. Split rotateEncryptionKey into a lock-free
   core (rotateEncryptionKeyUnlock) plus the existing lock wrapper and a
   new rotateEncryptionKeyTransaction that owns the lock across the full
   unit and performs both the in-lock rollback (abortEncryptionConversion)
   and the in-lock backup removal on success.

2. Treat the legacy value '0' as non-empty data so key rotation still
   persists the re-encrypted ciphertext when '0' is the only stored
   secret (array_filter would have dropped it and skipped saveAll).

3. Wrap the post-rotation re-encrypt/verify/saveAll sequence in a
   catch (Throwable) across all three call-sites so CI4
   EncryptionException, ReflectionException from batch_save, a failed
   round-trip verify, and any other failure all roll the .env key back
   to the pre-rotation state.

4. In Docker Compose, use long-syntax bind with create_host_path: false
   and document in INSTALL.md that the host .env must be a regular file
   (a missing one is no longer auto-created as a directory, and the
   mount now rejects a missing source on Compose implementations that
   support the flag).

Files touched: app/Helpers/security_helper.php, app/Commands/EnvProvision.php,
app/Database/Migrations/20220127000000_convertToCI4.php, docker-compose.yml,
INSTALL.md. All 4 existing helper tests still pass via CI.

* fix(security): make abortEncryptionConversion fail loudly on restore failure

The rollback path restored the .env backup with a suppressed
file_put_contents() and an unchecked file_get_contents(). If the restore
failed after the key had already been rotated, .env was left holding the new
CI4 key while the DB still held CI3-era ciphertext, so the data became
undecryptable after the next restart.

Now the backup read is checked for false and the restore goes through the
existing atomicWriteFile() helper; either failure throws so the error is
surfaced instead of silently corrupting the config. Adds a regression test
that forces an unreadable backup and asserts the throw plus that .env is
left untouched.

* fix(security): guard abortEncryptionConversion backup read before touching it

Validate the backup is a regular readable file (is_file/is_readable) before
reading it, so a missing/malformed backup fails loudly instead of emitting a
file_get_contents() warning. The unreadable-backup regression test now
exercises this guard rather than relying on a promoted warning.

---------

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
Co-authored-by: jekkos <jeroen.peelaerts@gmail.com>
Co-authored-by: jekkos <jekkos@users.noreply.github.com>
Co-authored-by: opencode <bot@opencode.ai>
2026-09-21 17:35:45 +02:00
objecttothisandcoderabbitai[bot] b610ae28ac fix(validation): broaden sendmail path regex, expand i18n, strip advisory IDs
fix(validation): allow Windows sendmail paths, tighten shell metachar exclusions

Broaden PLAIN_FILESYSTEM_PATH_STRICT to accept real-world sendmail formats
while blocking command injection characters not needed in valid paths.

- OSPOSRules.php: allow space, colon, backslash for Windows paths
  (e.g. C:\wamp64\...) and trailing args (-t -i); still excludes
  ampersand, backtick, subshell, redirect, and cmd.exe metacharacters
- OSPOSRulesTest.php: add cases for Windows paths, trailing args, and
  injection payloads
- Remove 7 ConfigTest assertions that expected metacharacter rejection;
  add acceptance test for sendmail path with trailing args

i18n(lang): expand mailpath_invalid message across all locales

- Fill previously empty mailpath_invalid keys across all locales
- Update existing translations (de-CH, de-DE, es-ES, es-MX, fr, nl-BE,
  nl-NL) to reflect newly allowed characters; nl locales corrected from
  English loanwords to proper Dutch terms
- Add missing key to ckb/Config.php

docs: remove security advisory IDs from public-facing files

- AGENTS.md: extend no-advisory-ID rule to documentation and URLs
- INSTALL.md: drop GHSA reference and advisory link from Host Header
  Injection guidance; rationale and fix instructions remain intact

Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-09-10 18:01:12 +04:00
objecttothis 6a36cdc3e9 fix(licenses): guard malformed data, parallelize gulp tasks, require Node 20
fix(config): guard against non-array and incomplete license data

- Wrap npm-prod/npm-dev license parsing in is_array() checks to avoid
  foreach errors when JSON decodes to null or non-array
- Skip dependency entries missing required keys (name, author, homepage,
  installedVersion, licenseType) in open-source and license-key loops

fix(gulp): correctly await all async tasks

- Parallelize update-licenses, copy-bootswatch, copy-bootswatch5, and
  copy-bootstrap sub-tasks via Promise.all
- Wrap exec() calls with finished(execStream.resume()) so composer and
  npm license-report commands fully write output files before task resolves;
  .resume() drains stdout so streams can emit close/finish events

build(package): require Node.js >=20

- Add engines field to package.json
- Regenerate package-lock.json with matching constraint
- Document prerequisite in BUILD.md; license-reporting dep needs regex
  features unavailable in Node 18 and earlier

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-09-10 17:32:52 +04:00
objecttothis 3c75fc0031 style(lang): normalize array keys to single quotes in ar-EG/ar-LB Common.php
Convert double-quoted string keys and values to single quotes across
app/Language/ar-EG/Common.php and app/Language/ar-LB/Common.php for
consistency with existing single-quoted entries (e.g. export_all,
export_page) already present in these files.

- No functional or translation content changes, quoting style only
- Aligns with project coding standard preferring single quotes for
  non-interpolated strings

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-09-09 11:59:44 +04:00
objecttothis c3ce98f798 i18n: add export_all and export_page translation keys
Add two new translation strings across all locale files under
app/Language/*/Common.php to support upcoming export UI that lets
users choose between exporting all records or only current page.

- Add `export_all` and `export_page` keys next to existing
  `export_csv*` entries in each language file
- Applied uniformly across every supported locale (en, en-GB, de-DE,
  de-CH, fr, es-ES, es-MX, ar-EG, ar-LB, az, bg, bs, ckb, cs, da, el,
  fa, he, hr-HR, and others) to keep translations in sync
- No logic changes; pure language resource additions

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-09-09 11:42:28 +04:00
objecttothis 016b17db9a feat(manage_tables): add keyboard accessibility to export toggle
Improve accessibility of the "export all rows" toggle switch on the
manage tables page.

- public/js/manage_tables.js: cache toggle wrapper element and add
  ARIA attributes (role="switch", aria-label, aria-checked) so
  screen readers announce the control correctly
- Add tabindex so the toggle is keyboard-focusable
- Add keydown handler for Enter/Space to trigger the toggle,
  matching native switch behavior for keyboard-only users
- Sync aria-checked state on change to keep assistive tech in sync
  with the visual toggle state

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-09-09 11:12:35 +04:00
jekkos b769873ca7 Merge branch 'master' into feat-export-toggle-all 2026-09-08 21:52:35 +02:00
jekkos 28755dfd50 fix(tests): resolve all phpunit failures — clean-DB suite green (#4626) (#4691)
* fix(tests): resolve all phpunit failures (#4626)

Bring the phpunit suite from 153 failures to 0 (281 tests passing):

- Employee: decouple grants block from save_value success; restructure
  save_employee new-employee + disallowed-grants early return
- Sale: unify sales_payments_temp schema (add sale_cash_refund,
  reference_code) so both creators produce an identical superset table
- Employees controller: provide placeholder password/hash in testing env
  so new-employee insert succeeds and grant logic is testable
- TestDatabaseBootstrapSeeder: reset shared connection table-name cache
  after bootstrap reset to avoid stale listTables()/tableExists() results
- Config: fix postSaveLocale validation rule syntax
- Test data: use unique employee usernames to avoid UNIQUE constraint
  collisions latching strict-mode transStatus=false on the shared conn
- Various test-file and language-string corrections

* test: consolidate employee fixtures in shared trait

Route test employee creation through a single EmployeeFixtureTrait
that delegates to Employee::save_employee(), so fixtures exercise the
same production code path instead of raw DB inserts. Removes six
near-duplicate helpers across EmployeeTest, SalesControllerTest, and
EmployeesControllerTest while preserving each test's specific grant
set.

Closes a piece of the fixture-scattering flagged in #4626.

Closes #4626

* test: add global DROP/CREATE grant and commit theme fixtures

* fix(ci): remove redundant symlink step, set working encryption key

* fix(ci): run phpunit with --no-coverage to avoid no-driver warning

* fix: address code review findings

- Config: restore strict locale validation (min required|integer|>0) and
  fix max cross-field check with a new gte_field rule (CI4's
  greater_than_equal_to[field] does not resolve the field value)
- Tests: assert rejection for non-numeric/zero/negative/min>max limits
- .env.example: remove shared hard-coded encryption.key (auto-generates);
  document Docker env-var usage
- phpunit.yml: scope CREATE/DROP grant to ospos_test.* and provision a
  per-run encryption key as an env var

* feat: support ENCRYPTION_KEY env var for encryption key

Read ENCRYPTION_KEY as a fallback for the encryption key when the
config value is empty. This is a supported, reliable path for Docker /
container deploys and CI, avoiding reliance on the raw dotted
encryption.key env var.

* fix: align Summary_report temp tables with Sale temp table schema

Summary_report created sales_items_taxes_temp and sales_payments_temp with fewer columns than the canonical create_temp_table() in Sale.php. A later reader expecting those columns hit a schema-mismatch SQL error on the shared temp tables. Add internal_tax/sales_tax (sales_items_taxes_temp) and reference_code (sales_payments_temp) so all creators emit the identical column set.
2026-09-08 21:49:28 +02:00
objecttothis 3f06d3b3cc refactor(manage-tables): always init export-all toggle
Remove showExportAllToggle option gate and per-instance label
overrides in manage_tables.js, since every caller enabled the
toggle anyway. Also drop the now-unused showExportAllToggle flag
from items/manage.php.

- manage_tables.js: init_export_all_toggle() no longer early-returns
  based on options.showExportAllToggle; labels hardcoded to
  'Export All' / 'Export Page' instead of reading
  exportAllToggleOnLabel/exportAllToggleOffLabel options
- manage_tables.js: toggle wrapper gains pull-right and print_hide
  classes for consistent layout/print behavior
- items/manage.php: remove now-dead showExportAllToggle: true option

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-09-08 17:35:56 +04:00
objecttothis c23ec2dd21 feat(manage-tables): add opt-in export-all-rows toggle, PoC on items
Bootstrap-table's export button only exports the current page since
sidePagination is server-side. Adds a showExportAllToggle option to
table_support.init() that injects a bootstrap-toggle switch toggling
exportDataType between 'basic' (current page) and 'all' (every page).
Wired up on the items manage table as a proof of concept.
2026-09-08 17:20:17 +04:00
objecttothis 9ecabf6f41 fix(sales): harden unsuspend with auth, status gating, and null safety
- Require reports_sales grant on postUnsuspend; return 403 on denial
- Reject unsuspend of non-SUSPENDED sales; skip silently on invalid state
- Move clear_all() after validation so an invalid sale_id no longer wipes
  the active in-progress cart
- Null-guard get_sale_status() on missing row instead of fatal property
  access; widen return type to ?int
- Fix getSaleType null-coalescing — CI4 session default only fires when
  key is unset, not when value is null
- Rename get_sale_type → getSaleType, sale_id → saleId (PSR-12 camelCase)
- Extract SaleFixtureTrait with createSale()/createSuspendedSale(); add
  regression coverage for auth denial, status gating, and cart preservation
2026-09-07 12:18:11 +04:00
jekkosandobjecttothis 839821e2eb bugfix(sales): reject non-negative gift-card amount_tendered (#4674)
* Validate gift-card payment amounts (GHSA-9847)

Close the negative gift-card amount minting vector: when a forged
payment_type like 'Gift Card:<number>' reaches the catch-all validation
branch, a negative amount_tendered previously passed decimal_locale and was
then routed into Giftcard::decrementGiftcardValue, where value - (-N)
increased the balance (store credit minted at will).

- Add nonNegativeDecimal rule + 'Sales.negative_amount_tendered' message to
  the catch-all amount_tendered rules in Sales::postAddPayment(); add the
  language key to all 46 locale files (populated in en, empty elsewhere).
- Guard Giftcard::decrementGiftcardValue() against non-positive amounts so
  the sink itself can no longer add balance from an inverted subtraction.
- Regression tests: controller-level rejection of negative amount_tendered
  and model-level rejection of negative/zero decrements.

* Address PR review: align locale keys, drop advisory refs, add decimal_locale message

- Align negative_amount_tendered '=> with all other keys (46 locale files)
- Remove docblock + inline comment above decrementGiftcardValue()
- Remove GHSA ID and attack-detail description from test; scrub redundant comment
- Add decimal_locale message override + focused malformed-amount test

* Fix formatting and spacing in SalesControllerTest

* fix(lang): remove duplicate negative amount tendered key

Consolidate 'negative_amount_invalid' and 'negative_amount_tendered'
translation keys in Sales.php across all locale files. Both keys held
identical messages, causing redundant translation maintenance.

- Drop 'negative_amount_invalid' key, keep 'negative_amount_tendered'
- Move existing translated text into 'negative_amount_tendered' where
  it was previously empty
- Applied across all app/Language/*/Sales.php locale files

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>

* fix(sales): allow negative amount_tendered in return mode

Return transactions legitimately produce negative amount_due and
prefilled amount_tendered values, but validation rules previously
enforced nonNegativeDecimal unconditionally, blocking valid returns.

- Detect return mode via sale_lib->get_mode() in Sales::process
- Build amount_tendered rule conditionally: skip nonNegativeDecimal
  check when in return mode, keep it for sale/giftcard flows
- Apply the conditional rule to both giftcard and standard payment
  branches

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>

* test: update expected error message in negative payment test

Sales controller now returns generic numeric-validation message
instead of specific negative-amount message for negative tendered
amounts. Update test assertion to match new lang key.

- tests/Controllers/SalesControllerTest.php: assert
  Sales.must_enter_numeric instead of
  Sales.negative_amount_tendered

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>

* test: remove regression tests for GHSA-9847 negative amount fix

Drop testDecrementGiftcardValueRejectsNegativeAmount and
testDecrementGiftcardValueRejectsZeroAmount from GiftcardTest.

- Remove coverage for decrementGiftcardValue() rejecting
  non-positive amounts (negative/zero) in tests/Models/GiftcardTest.php

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>

---------

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
Co-authored-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-09-07 11:47:02 +04:00
jekkos bdbc6d9cf1 fix(sales): gate getSearch behind reports_sales grant
Sales::getSearch() — the AJAX endpoint backing the Sales Takings list —
lacked the authorization check present on all sibling endpoints
(getRow, getEdit, postSave, getReceipt, getInvoice), allowing a cashier
with only the base sales grant to pull the full ledger.

- Add reports_sales guard with 403 JSON response on denial
- Add regression tests: cashier without grant → 403; employee with
  grant → search payload returned
- Clarify getSearch() coverage in SalesControllerTest comments
- Remove duplicate test methods introduced during initial commit
2026-09-07 10:54:35 +04:00
Vighnesh Nilajakar 3bec7d5c92 fix(barcode): resolve string interpolation issue in barcode display html (#4692)
Fixes an issue in Barcode_lib.php where $barcode was enclosed in single quotes, preventing string interpolation and rendering the literal string "$barcode" on the item barcode generation page instead of the barcode graphic.

Changes Made :
Refactored the string assignment in app/Libraries/Barcode_lib.php to properly concatenate $barcode.

How to Test:
1. Open Items in OSPOS.
2. Select any item and click Generate Barcodes.
3. Verify that the rendered barcode image displays correctly rather than showing literal text.
2026-09-06 21:52:22 +02:00
richardmilles 0e0d3aff10 fix: prevent duplicate items when editing imported rows (#4634)
fix: prevent duplicate items when editing imported rows

Item::exists() matched on item_id OR item_number and required exactly
one row, so a numeric barcode colliding with another item_id caused
saves to insert duplicates. Treat any match as existing.

Also removes the comment explaining numeric barcode matching behavior.

Fixes #4584
2026-09-03 10:50:03 +04:00
objecttothis f5f9052de1 fix(sales): harden payment validation and gift card handling
- Validate paymentType is a non-empty string before processing
- Reject negative or zero amounts for all payment types
- Enforce full payment coverage before completing a sale
- Bypass coverage check for invoice and quote mode sales
- Require a valid gift card number before decrementing value;
  rollback and return insufficient balance error on missing input
- Add "amount_due_not_covered" and "negative_amount_invalid"
  translations across 40+ locales
- Add test coverage for gift card validation, negative amounts,
  and quote/invoice zero-payment completion
- Rename snake_case locals to camelCase in postComplete (no behavior change)
2026-09-02 01:21:46 +04:00
objecttothis fdc1c38b43 feat(validation, tests): add valid_path_strict rule and integrate into mailpath validation (#4684)
- Introduce `valid_path_strict` rule in `OSPOSRules` to enforce stricter path validation, preventing security issues like injection attempts with newline or special characters.
- Update mail configuration validation in `Config` controller to use the new rule for the `mailpath` field.
- Add unit tests in `OSPOSRulesTest` to cover edge cases for `valid_path_strict`.

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-09-01 19:41:41 +04:00
objecttothis 6db3dde491 Bugfix tax names (#4677)
bugfix(items, validation): reject unsafe tax names and fix payments temp table collision

- Add unicode_alpha_numeric_punct rule (OSPOSRules) to allow accented/CJK
  chars in text fields while blocking HTML-unsafe chars (<, >) as
  defense-in-depth against injection
- Items controller: extract validateItemFields/validateBulkUpdateFields,
  validate tax_names on save and bulk update using new rule; add shared
  validateFields helper in Secure_Controller to DRY up validation +
  JSON error response
- Escape tax_group output in sales/quote.php and receipt_email.php views
  to harden output encoding at render time
- Rename sales_payments_temp -> sales_report_payments_temp (Summary_report)
  and -> sales_search_payments_temp (Sale model) to avoid name collision
  between concurrently-created temp tables
- AGENTS.md: document alignment rule for => columns when inserting new
  language keys

Tests:
- Add ItemsControllerTest covering postSave/bulkupdate tax_names validation
- Reject <, > in tax_names on /items/save and /items/bulkupdate
- Verify unicode and apostrophe-containing tax names are accepted
- Cover CSV import helpers: header generation (basic, multiple locations,
  attributes), stock-location/attribute header builders, get_csv_file
  parsing (plain, BOM-prefixed, multi-row)
- Validate required-header detection for import templates
- Remove outdated tax name test from SalesControllerTest
- Simplify Database class references in SalesControllerTest

i18n:
- Add tax_name_invalid translation to Items.php for 20+ locales, inserted
  alphabetically after tax_category in each file
- Normalize quote style in ar-EG/Items.php to single quotes
- Add ka/Items.php Georgian locale scaffold

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-09-01 10:59:29 +04:00
objecttothis 905a447e55 fix(reports, home): resolve double-URL-decoding bypass for method grants (#4660) (#4666)
fix(reports, home): strengthen method grant validation and URI decoding (#4660)

- Reports, Home: fix URI decoding in hasGrant() method checks to use
  urldecode consistently, preventing malformed URI segments from
  bypassing access controls
- Reports: rename snake_case variables to camelCase for PSR-12 compliance
- Reports: adjust access checks to accurately handle null submodule IDs

Tests:
- Add grant check tests for encoded URI inputs across Reports and Home
- Add test case for employee access with base reports grant
- Add secondary grant check for reports_customers in relevant test cases
- Confirm logout bypass remains functional and properly controlled
- Refactor TestDatabaseBootstrapSeeder to expose static reset() for
  per-class DB re-initialization instead of only via seeder run()
- Standardize session handling, setup logic, and boolean declarations
- Use unique data in test helpers to avoid collisions
- Add docblocks to ReportsControllerTest and HomeTest for PSR-5 compliance
- Add exception handling for failed employee creation in test setup
- Wrap password validation test in try-finally to guarantee state cleanup

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-08-31 13:33:09 +04:00
objecttothis 8cfd1a4b1d fix(sales): enforce reports_sales grant on search endpoint (#4673)
- Sales::getSearch now enforces reports_sales grant before running
  search, returns 403 with lang message when missing
- Rename snake_case helpers/methods to camelCase across
  Sales controller, Sale model, and tabular_helper
  (get_sale_data_row -> getSaleDataRow, get_payments_summary ->
  getPaymentsSummary, sales_headers -> salesHeaders, etc.)
- Config/OSPOS: reset DB data cache before checking app_config
  table existence to avoid stale schema cache in tests
- TestDatabaseBootstrapSeeder: expose static reset() so tests can
  rebuild schema once per class instead of only via seeder run()
- SalesControllerTest: bootstrap DB once per class, seed once,
  refresh app settings each setUp, add tests for search endpoint
  authorization (cashier denied, supervisor allowed), move
  createTestItem into shared ItemFixtureTrait

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-08-31 13:08:33 +04:00
objecttothis d63d31700d Ensure payload data is escaped to prevent XSS (#4664)
fix(barcode): escape payload fields to prevent XSS; PSR-12 refactor

- Apply `esc()` to name, ID, item number, category, and company name in `Barcode_lib` payloads
- Remove redundant `urldecode()` in `Item_kitsController` to prevent triple decoding
- Rename variables and methods to camelCase across barcode, item_kits, and tests
- Add type hint for `$layoutType` parameter in `manageDisplayLayout`
- Add/update unit tests covering escaping and HTTP response assertions

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-08-28 10:08:31 +04:00