Autosave: 20260225-172428

This commit is contained in:
Flatlogic Bot 2026-02-25 17:24:28 +00:00
parent 46245138f0
commit c850a45169
3 changed files with 211 additions and 24 deletions

View File

@ -2,6 +2,9 @@
require_once __DIR__ . '/../db/config.php';
require_once __DIR__ . '/../includes/functions.php';
// Ensure user is logged in first
require_login();
$pdo = db();
require_permission('dashboard_view');

View File

@ -60,22 +60,196 @@ function get_product_price($product) {
return $price;
}
function get_base_url() {
$protocol = (!empty($_SERVER['HTTPS']) && $_SERVER['HTTPS'] !== 'off') || $_SERVER['SERVER_PORT'] == 443 ? "https://" : "http://";
$domainName = $_SERVER['HTTP_HOST'];
// Check for Flatlogic VM base URL (if needed)
// For now, standard detection
$path = str_replace(basename($_SERVER['SCRIPT_NAME']), "", $_SERVER['SCRIPT_NAME']);
// Normalize path: ensure it ends with /
if (substr($path, -1) !== '/') {
$path .= '/';
/**
* Paginate a query result.
*
* @param PDO $pdo The PDO connection object.
* @param string $query The base SQL query (without LIMIT/OFFSET).
* @param array $params Query parameters.
* @param int $default_limit Default items per page.
* @return array Pagination result with keys: data, total_rows, total_pages, current_page, limit.
*/
function paginate_query($pdo, $query, $params = [], $default_limit = 20) {
// Get current page
$page = isset($_GET['page']) && is_numeric($_GET['page']) ? (int)$_GET['page'] : 1;
if ($page < 1) $page = 1;
// Get limit (allow 20, 50, 100, or -1 for all)
$limit = isset($_GET['limit']) ? (int)$_GET['limit'] : $default_limit;
// Validate limit
if ($limit != -1 && !in_array($limit, [20, 50, 100])) {
$limit = $default_limit;
}
// If we are in admin/ or api/ or other subdirs, we might need to go up
// But this function is usually called from root files or with knowledge of its location
return $protocol . $domainName . $path;
// If limit is -1, fetch all
if ($limit == -1) {
$stmt = $pdo->prepare($query);
$stmt->execute($params);
$data = $stmt->fetchAll();
return [
'data' => $data,
'total_rows' => count($data),
'total_pages' => 1,
'current_page' => 1,
'limit' => -1
];
}
// Count total rows using a subquery to handle complex queries safely
$count_sql = "SELECT COUNT(*) FROM ($query) as count_table";
$stmt = $pdo->prepare($count_sql);
$stmt->execute($params);
$total_rows = $stmt->fetchColumn();
$total_pages = ceil($total_rows / $limit);
if ($page > $total_pages && $total_pages > 0) $page = $total_pages;
// Calculate offset
$offset = ($page - 1) * $limit;
if ($offset < 0) $offset = 0;
// Add LIMIT and OFFSET
$query_with_limit = $query . " LIMIT " . (int)$limit . " OFFSET " . (int)$offset;
$stmt = $pdo->prepare($query_with_limit);
$stmt->execute($params);
$data = $stmt->fetchAll();
return [
'data' => $data,
'total_rows' => $total_rows,
'total_pages' => $total_pages,
'current_page' => $page,
'limit' => $limit
];
}
/**
* Render pagination controls and limit selector.
*
* @param array $pagination The result array from paginate_query.
* @param array $extra_params Additional GET parameters to preserve.
*/
function render_pagination_controls($pagination, $extra_params = []) {
$page = $pagination['current_page'];
$total_pages = $pagination['total_pages'];
$limit = $pagination['limit'];
// Build query string for limit change
$params = array_merge($_GET, $extra_params);
unset($params['page']); // Reset page when limit changes
// Limit Selector
$limits = [20, 50, 100, -1];
echo '<div class="d-flex justify-content-between align-items-center mb-0 bg-white p-2 rounded flex-wrap gap-2">';
echo '<div class="d-flex align-items-center flex-wrap gap-3">';
echo '<form method="GET" class="d-flex align-items-center mb-0">';
// Preserve other GET params
foreach ($params as $key => $val) {
if ($key !== 'limit') echo '<input type="hidden" name="'.htmlspecialchars((string)$key).'" value="'.htmlspecialchars((string)$val).'">';
}
echo '<small class="me-2 text-muted fw-bold">SHOW:</small>';
echo '<select name="limit" class="form-select form-select-sm" style="width: auto;" onchange="this.form.submit()">';
foreach ($limits as $l) {
$label = $l == -1 ? 'All' : $l;
$selected = $limit == $l ? 'selected' : '';
echo "<option value='$l' $selected>$label</option>";
}
echo '</select>';
echo '</form>';
// Total Count
echo '<span class="text-muted small border-start ps-3">Total: <strong>' . $pagination['total_rows'] . '</strong> items</span>';
// Optional Total Amount (Sum)
if (isset($pagination['total_amount_sum'])) {
echo '<span class="text-success small border-start ps-3">Total Sum: <strong class="fs-5">' . format_currency($pagination['total_amount_sum']) . '</strong></span>';
}
if ($total_pages > 0) {
echo '<span class="text-muted small border-start ps-3">Page <strong>' . $page . '</strong> of <strong>' . $total_pages . '</strong></span>';
}
echo '</div>';
// Pagination Links
if ($total_pages > 1) {
echo '<nav aria-label="Page navigation">';
echo '<ul class="pagination pagination-sm mb-0">';
// Previous
$prev_disabled = $page <= 1 ? 'disabled' : '';
$prev_page = max(1, $page - 1);
$url_params = array_merge($params, ['page' => $prev_page, 'limit' => $limit]);
$prev_url = '?' . http_build_query($url_params);
echo "<li class='page-item $prev_disabled'><a class='page-link' href='$prev_url' aria-label='Previous'><span aria-hidden='true'>&laquo;</span></a></li>";
// Logic to show limited page numbers with ellipsis
$shown_pages = [];
$shown_pages[] = 1;
$shown_pages[] = $total_pages;
for ($i = $page - 3; $i <= $page + 3; $i++) {
if ($i > 1 && $i < $total_pages) {
$shown_pages[] = $i;
}
}
sort($shown_pages);
$shown_pages = array_unique($shown_pages);
$prev_p = 0;
foreach ($shown_pages as $p) {
if ($prev_p > 0 && $p > $prev_p + 1) {
echo "<li class='page-item disabled'><span class='page-link'>...</span></li>";
}
$active = $p == $page ? 'active' : '';
$url_params = array_merge($params, ['page' => $p, 'limit' => $limit]);
$url = '?' . http_build_query($url_params);
echo "<li class='page-item $active'><a class='page-link' href='$url'>$p</a></li>";
$prev_p = $p;
}
// Next
$next_disabled = $page >= $total_pages ? 'disabled' : '';
$next_page = min($total_pages, $page + 1);
$url_params = array_merge($params, ['page' => $next_page, 'limit' => $limit]);
$next_url = '?' . http_build_query($url_params);
echo "<li class='page-item $next_disabled'><a class='page-link' href='$next_url' aria-label='Next'><span aria-hidden='true'>&raquo;</span></a></li>";
echo '</ul></nav>';
}
echo '</div>';
}
/**
* Get the project root URL
*/
function get_base_url() {
$protocol = (!empty($_SERVER['HTTPS']) && $_SERVER['HTTPS'] !== 'off') || ($_SERVER['SERVER_PORT'] ?? 80) == 443 ? "https://" : "http://";
$host = $_SERVER['HTTP_HOST'] ?? 'localhost';
$script = $_SERVER['SCRIPT_NAME'] ?? '/index.php';
$path = dirname($script);
$path = str_replace('\\', '/', $path); // Corrected escaping for backslash
$subdirs = ['/admin', '/api', '/includes', '/db', '/mail', '/ai', '/assets'];
foreach ($subdirs as $dir) {
if ($path === $dir || str_ends_with($path, $dir)) {
$path = substr($path, 0, -strlen($dir));
break;
}
}
if ($path === '' || $path === '.') $path = '/';
return $protocol . $host . rtrim($path, '/') . '/';
}
if (!function_exists('str_ends_with')) {
function str_ends_with($haystack, $needle) {
$length = strlen($needle);
if (!$length) return true;
return substr($haystack, -$length) === $needle;
}
}
/**
@ -90,7 +264,7 @@ function init_session() {
ini_set('session.gc_maxlifetime', (string)$lifetime);
// Set cookie parameters before session_start
$isSecure = (!empty($_SERVER['HTTPS']) && $_SERVER['HTTPS'] !== 'off') || $_SERVER['SERVER_PORT'] == 443;
$isSecure = (!empty($_SERVER['HTTPS']) && $_SERVER['HTTPS'] !== 'off') || ($_SERVER['SERVER_PORT'] ?? 80) == 443;
session_set_cookie_params([
'lifetime' => $lifetime,
@ -103,11 +277,6 @@ function init_session() {
session_start();
}
// Refresh session expiration on each load if user is logged in
if (isset($_SESSION['user'])) {
// Optional: you could implement a last_activity check here
}
}
function login_user($username, $password) {
@ -151,14 +320,29 @@ function has_permission($permission) {
$user = get_logged_user();
if (!$user) return false;
// Admin has all permissions
if ($user['permissions'] === 'all') return true;
// If permissions are missing from session (stale session), fetch from DB
if (!isset($user['permissions'])) {
$pdo = db();
$stmt = $pdo->prepare("SELECT g.permissions FROM users u JOIN user_groups g ON u.group_id = g.id WHERE u.id = ?");
$stmt->execute([$user['id']]);
$perms = $stmt->fetchColumn();
$_SESSION['user']['permissions'] = $perms;
$user['permissions'] = $perms;
}
$userPerms = $user['permissions'] ?: '';
// Admin has all permissions
if ($userPerms === 'all') return true;
$permissions = explode(',', $userPerms);
$permissions = array_map('trim', $permissions);
$permissions = json_decode($user['permissions'] ?: '[]', true);
return in_array('all', $permissions) || in_array($permission, $permissions);
}
function require_permission($permission) {
require_login();
if (!has_permission($permission)) {
die("Access Denied: You do not have permission to view this page ($permission).");
}

View File

@ -12,7 +12,7 @@ $baseUrl = get_base_url();
function get_redirect_url($baseUrl) {
if (has_permission('dashboard_view')) {
return $baseUrl . 'admin/index.php';
} elseif (has_permission('pos')) {
} elseif (has_permission('pos_view')) {
return $baseUrl . 'pos.php';
} elseif (has_permission('kitchen_view')) {
return $baseUrl . 'kitchen.php';