mirror of
https://github.com/opensourcepos/opensourcepos.git
synced 2026-09-13 05:47:23 -04:00
* fix(xss): remove redundant escaping that double-encoded item attribute values - Remove esc()/html_entity_decode() calls now that output is escaped at render time by the framework, preventing double-encoding of special characters in attribute names, units, and definition values - Fix employee_name form_input value fields to stop pre-escaping before form_input applies its own escaping - Reorder Items.php use statements and add missing BaseConnection import - Change items/manage.php start_date from let to plain assignment for proper reassignment scope Signed-off-by: Travis Garrison <travis@chiraqbookstore.com> * test(sales): add regression tests for permission checks on sales endpoints - Ensure role-based permissions correctly restrict access to sensitive actions like price edits, receipt/invoice views, and report generation. - Add tests for both granted and restricted user scenarios to validate the behavior. Signed-off-by: Travis Garrison <travis@chiraqbookstore.com> * fix(attributes): validate `attribute_value` before processing - Add checks to ensure `attribute_value` is a non-empty string in `postSaveAttributeValue` and `postDeleteDropdownAttributeValue` methods. - Return error response if validation fails to prevent invalid data handling. Signed-off-by: Travis Garrison <travis@chiraqbookstore.com> * fix(attributes): improve error handling and optimize affected items processing - Use `array_column` for extracting item IDs to streamline logic. - Add JSON validation with `JSON_THROW_ON_ERROR` and return proper error response for invalid `definition_values`. Signed-off-by: Travis Garrison <travis@chiraqbookstore.com> * test(sales): enable database refresh for consistent test state Signed-off-by: Travis Garrison <travis@chiraqbookstore.com> * test(sales): assert unauthorized message is displayed on restricted access Signed-off-by: Travis Garrison <travis@chiraqbookstore.com> * refactor(attributes): use camelCase for `attributeValue` in controller methods - Standardize variable naming in `postSaveAttributeValue` and `postDeleteDropdownAttributeValue` methods by switching to camelCase. Signed-off-by: Travis Garrison <travis@chiraqbookstore.com> --------- Signed-off-by: Travis Garrison <travis@chiraqbookstore.com> Co-authored-by: Travis Garrison <travis@chiraqbookstore.com>