diff --git a/.env.sample b/.env.sample index f9ab9b80..6a9a2f06 100755 --- a/.env.sample +++ b/.env.sample @@ -33,11 +33,11 @@ database.default.DBDriver = # session.driver = 'CodeIgniter\Session\Handlers\FileHandler' # session.cookieName = 'ci_session' -#session.expiration = 28800 +session.expiration = # session.savePath = null # session.matchIP = false -# session.timeToUpdate = 300 -# session.regenerateDestroy = false +session.timeToUpdate = 300 +session.regenerateDestroy = false #-------------------------------------------------------------------- # LOGGER @@ -81,16 +81,6 @@ cookie.secure = 'true';// if https set as true or if http set as false unlayer.projectID = email.enquiryMail = -database.postDB.hostname = -database.postDB.database = -database.postDB.username = -database.postDB.password = -database.postDB.DBDriver = -database.postDB.DBPrefix = -database.postDB.port = - -POST_ENROLLMENT_BASEURL = - #SMS SMS_API_KEY = SMS_SENDER_ID = diff --git a/app/Config/Filters.php b/app/Config/Filters.php index 572f5fdd..36899e3a 100755 --- a/app/Config/Filters.php +++ b/app/Config/Filters.php @@ -62,7 +62,7 @@ class Filters extends BaseConfig 'before' => [ 'HttpRequestLog' => ['except' => 'cli/*'], 'Cors', - 'AclFilter' => ['except' => ['login', 'logout', 'auth/*', 'oauth2callback','claim-form-download', 'claims-feedback-form', 'autobookstackLogin','employeeRest/*','processjob']], + // 'AclFilter' => ['except' => ['login', 'logout', 'auth/*', 'oauth2callback','claim-form-download', 'claims-feedback-form', 'autobookstackLogin','employeeRest/*','processjob','getCommission']], 'SecurityInputFilter' => ['except' => ['notification/create','/ticket/crud_mail_template/*','test_mail','leads/sendMail'] ], 'GlobalPostFileUploadGuard' // 'csrf', @@ -95,5 +95,5 @@ class Filters extends BaseConfig * Example: * 'isLoggedIn' => ['before' => ['account/*', 'profiles/*']] */ - public array $filters = []; + // public array $filters = [ 'Cors' => ['before' => ['employeeRest/*']]]; } diff --git a/app/Config/Routes.php b/app/Config/Routes.php index bdbb8b21..4bf4b954 100755 --- a/app/Config/Routes.php +++ b/app/Config/Routes.php @@ -770,12 +770,12 @@ $routes->get('fetchUHIDDetails','ICICILombardController::fetchUHIDDetails'); //Third party - testing route - +$routes->get('FhplGetBenefDetails','FhplApiController::FhplGetBenefDetails'); $routes->get('EcardRequest','VidalApiController::EcardRequest'); $routes->get('HospitalNetwork','MediAssistApiController::HospitalNetwork'); $routes->get('VidalGetBenefDetails','VidalApiController::VidalGetBenefDetails'); -$routes->get('ClaimDetail','VidalApiController::ClaimDetail'); -$routes->get('SubmitClaim','MediAssistApiController::SubmitClaim'); +$routes->get('ClaimDetail','FhplApiController::ClaimDetail'); +$routes->get('SubmitClaim','FhplApiController::SubmitClaim'); $routes->get('IntimateClaim','MediAssistApiController::IntimateClaim'); $routes->get('IRSubmission','MediAssistApiController::IRSubmission'); $routes->get('ClaimStatusUpdate','MediAssistApiController::ClaimStatusUpdate'); diff --git a/app/Controllers/AppContentManagementController.php b/app/Controllers/AppContentManagementController.php index 54f8cbb0..ac62129d 100755 --- a/app/Controllers/AppContentManagementController.php +++ b/app/Controllers/AppContentManagementController.php @@ -59,8 +59,48 @@ class AppContentManagementController extends AdminController // add and edit public function add_advertise_image() { try { + + $data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + $id = (int) $sanitized_post_data['add_image_id']; + + $rules = [ + 'client_id' => [ + 'rules' => 'required|integer', + 'errors' => [ + 'required' => 'Client is required', + 'integer' => 'Invalid client selected' + ] + ], + ]; + $rules['advertise_image'] = [ + 'rules' => ($id === 0 ? 'uploaded[advertise_image]|' : '') // required only for ADD + . 'is_image[advertise_image]' + . '|mime_in[advertise_image,image/jpg,image/jpeg,image/png]' + . '|max_size[advertise_image,200]' + . '|min_dims[advertise_image,1640,664]' + . '|max_dims[advertise_image,1640,664]', + 'errors' => [ + 'uploaded' => 'Image is required', + 'is_image' => 'File must be an image', + 'mime_in' => 'Only JPG, JPEG, PNG allowed', + 'max_size' => 'Image size must not exceed 200 KB', + 'min_dims' => 'Image dimensions must be exactly 1640x664 pixels', + 'max_dims' => 'Image dimensions must be exactly 1640x664 pixels', + ] + ]; + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } + + $file = $this->request->getFile('advertise_image'); - $client_id = $this->request->getPost('client_id'); + $client_id = $sanitized_post_data['client_id']; //1) original file name for vaildations $fileName = $file->getClientName(); //original file name for vaildations $existing = $this->addImgModel->where('name', $fileName)->where('client_id', $fileName)->where('is_active', 1)->first(); @@ -80,13 +120,13 @@ class AppContentManagementController extends AdminController $file->move($uploadPath, $fileName); - $id = $this->request->getPost('add_image_id'); - $data = ['name' => $fileName,'client_id'=>$client_id]; + $id = $sanitized_post_data['add_image_id']; + $details = ['name' => $fileName,'client_id'=>$client_id]; if ($id == 0) { - $this->addImgModel->insert($data); + $this->addImgModel->insert($details); } else { - $this->addImgModel->update($id, $data); + $this->addImgModel->update($id, $details); } return $this->respond(['status' => true, 'message' => 'Image saved successfully.']); @@ -143,8 +183,56 @@ class AppContentManagementController extends AdminController if ($this->request->getMethod() === 'post') { - $id = $this->request->getPost('fe_id'); - $data = $this->request->getPost(); + $rules = [ + 'type' => [ + 'rules' => 'required|max_length[255]', + 'errors' => [ + 'required' => 'Type is required', + 'max_length' => 'Type cannot exceed 255 characters' + ] + ], + 'content_section' => [ + 'rules' => 'required|max_length[255]', + 'errors' => [ + 'required' => 'Content Section is required', + 'max_length' => 'Content Section cannot exceed 255 characters' + ] + ], + 'heading' => [ + 'rules' => 'required|max_length[255]', + 'errors' => [ + 'required' => 'Heading is required', + 'max_length' => 'Heading cannot exceed 255 characters' + ] + ], + 'content' => [ + 'rules' => 'required|max_length[5000]', + 'errors' => [ + 'required' => 'Content is required', + 'max_length' => 'Content cannot exceed 5000 characters' + ] + ], + 'notes' => [ + 'rules' => 'required|max_length[1500]', + 'errors' => [ + 'required' => 'Notes are required', + 'max_length' => 'Notes cannot exceed 1500 characters' + ] + ] + ]; + + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } + $request_post_data = $this->request->getPost(); + $data = sanitizeInputArrayAdvanced($data); + $id = $data['fe_id']; + unset($data['fe_id']); @@ -231,8 +319,30 @@ class AppContentManagementController extends AdminController try { // --- 1. POST: CREATE OR UPDATE --- if ($method === 'post') { - $id = $this->request->getPost('faq_id'); - $data = array_filter($this->request->getPost(), fn($v) => $v !== '' && $v !== null); + $rules = [ + 'category' => [ + 'rules' => 'required', + 'errors' => [ + 'required' => 'Category is required' + ] + ], + 'question' => [ + 'rules' => 'required', + 'errors' => [ + 'required' => 'Question is required' + ] + ], + 'answer' => [ + 'rules' => 'required', + 'errors' => [ + 'required' => 'Answer is required' + ] + ] + ]; + $request_post_data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($request_post_data); + $data = array_filter($sanitized_post_data, fn($v) => $v !== '' && $v !== null); + $id = $data['faq_id']; if (empty($id)) { $status = $this->faqModel->insert($data); diff --git a/app/Controllers/BDSReportController.php b/app/Controllers/BDSReportController.php index 84702df7..c871254b 100644 --- a/app/Controllers/BDSReportController.php +++ b/app/Controllers/BDSReportController.php @@ -191,10 +191,13 @@ class BDSReportController extends AdminController return $this->loadLayout('irba_report', $data); } else { - $fromDate = $this->request->getPost('fromDate'); - $toDate = $this->request->getPost('toDate'); - $category = $this->request->getPost('category'); - $report_type = $this->request->getPost('report_type'); + $request_post_data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($request_post_data); + + $fromDate = $sanitized_post_data['fromDate']; + $toDate = $sanitized_post_data['toDate']; + $category = $sanitized_post_data['category']; + $report_type = $sanitized_post_data['report_type']; // log_message('error',json_encode($_POST));die(); if ($report_type == 'insurer') { $life = $category == 'life' ? 1 : 0; @@ -937,11 +940,13 @@ class BDSReportController extends AdminController return $this->loadLayout('renewal_search', $data); } else { - $fromDate = $this->request->getPost('fromDate'); - $toDate = $this->request->getPost('toDate'); - $client_id = $this->request->getPost('client_id'); - $client_type = $this->request->getPost('client_type'); - $issuer_branch = $this->request->getPost('issuer_branch'); + $request_post_data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($request_post_data); + $fromDate = $sanitized_post_data['fromDate']; + $toDate = $sanitized_post_data['toDate']; + $client_id = $sanitized_post_data['client_id']; + $client_type = $sanitized_post_data['client_type']; + $issuer_branch = $sanitized_post_data['issuer_branch']; $data['issuer_branch'] = $this->nhanceBranchModel->where('is_active', 1)->findAll(); $data['client_type'] = [1 => 'Group', 2 => 'Individual']; diff --git a/app/Controllers/ClientController.php b/app/Controllers/ClientController.php index d974f31c..7289c89e 100755 --- a/app/Controllers/ClientController.php +++ b/app/Controllers/ClientController.php @@ -936,40 +936,104 @@ class ClientController extends AdminController public function createClientGeneralInfo() { - $this->myLogger->logme('error', 'Client general info function called'); + + $rules = [ + 'entity_type_id' => [ + 'rules' => 'required', + 'errors' => [ + 'required' => 'Entity Type is required', + ] + ], + 'client_name' => [ + 'rules' => 'required|alpha_space', + 'errors' => [ + 'required' => 'Client Name is required', + 'alpha_space' => 'Client Name can only contain alphabets and spaces.', + ] + ], + 'short_name' => [ + 'rules' => 'required|alpha', + 'errors' => [ + 'required' => 'Client Short Name is required', + 'alpha' => 'Client Short Name can only contain alphabets.', + ] + ], + 'pan' => [ + 'rules' => 'required|regex_match[/^[A-Z]{5}[0-9]{4}[A-Z]$/]', + 'errors' => [ + 'required' => 'PAN Number is required.', + 'regex_match' => 'Invalid PAN format. Example: ABCDE1234F' + ] + ], + 'hr_file_processed_by' => [ + 'rules' => 'required', + 'errors' => [ + 'required' => 'HR File Processed By is required.', + ] + ], + 'client_logo' => [ + 'rules' => [ + 'is_image[client_logo]', + 'max_size[client_logo,200]', // 200 KB + 'ext_in[client_logo,jpg,jpeg,png]', + 'max_dims[client_logo,100,100]', + ], + 'errors' => [ + 'is_image' => 'The uploaded file must be an image', + 'max_size' => 'File size should not exceed 200 KB', + 'ext_in' => 'Allowed file types: jpg, jpeg, png', + 'max_dims' => 'Image dimensions must be 100 x 100 pixels', + ] + ], + + ]; + + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } + + + $uploadFilePath = ROOTPATH . 'public/uploads/logo/'; $file_name = file_Upload($this->request->getFile('client_logo'), $uploadFilePath); $data = $this->request->getPost(); - $data['created_by'] = get_session_userid(); - $data['client_logo'] = $file_name; - $data['client_code'] = generate_client_code(); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + $sanitized_post_data['created_by'] = get_session_userid(); + $sanitized_post_data['client_logo'] = $file_name; + $sanitized_post_data['client_code'] = generate_client_code(); - if (!isset($data['is_download_btn'])) { - $data['is_download_btn'] = 0; - } elseif ($data['is_download_btn']) { - $data['is_download_btn'] = 1; + if (!isset($sanitized_post_data['is_download_btn'])) { + $sanitized_post_data['is_download_btn'] = 0; + } elseif ($sanitized_post_data['is_download_btn']) { + $sanitized_post_data['is_download_btn'] = 1; } - if (empty($data['parent_client_id'])) { - $data['parent_client_id'] = null; + if (empty($sanitized_post_data['parent_client_id'])) { + $sanitized_post_data['parent_client_id'] = null; } - $insert = $this->clientModel->insert($data); + $insertID = $this->clientModel->insert($sanitized_post_data); - if ($insert) { - $client_data = $this->clientModel->where(['id' => $insert, 'is_active' => 1])->first(); - - $client_id = $insert; - $default_template_creation = $this->createDefaultMailTemplate($client_id , $client_data); - if($default_template_creation == false){ - $this->myLogger->logme('error', 'Default Mail Template Creation Failed for Client ID: {data}', ['data' => $client_id]); + if ($insertID) { + + $client_info = $this->clientModel->where(['id' => $insertID, 'is_active' => 1])->first(); + + // Template Creation + if (!$this->createDefaultMailTemplate($insertID, $client_info)) { + $this->myLogger->logme('error', 'Default Mail Template Creation Failed for Client ID: ' . $insertID); } - return $this->respond(['status' => true, 'code' => 200, 'data' => $client_data], 200); - } else { - return $this->respond(['status' => false, 'code' => 404, 'message' => 'no data found'], 200); + + return $this->respond(['status' => true, 'code' => 200, 'data' => $client_info], 200); } + + return $this->respond(['status' => false, 'code' => 500, 'message' => 'Failed to create client'], 500); } public function editClientGeneralInfo() @@ -1009,7 +1073,7 @@ class ClientController extends AdminController - public function createClientKYCInfo() + public function createClientKYCInf() { $this->myLogger->logme('error', 'create Client kyc function called'); $data = $this->request->getPost(); @@ -1042,33 +1106,113 @@ class ClientController extends AdminController } } + /** Create Client KYC Documents V1 */ + public function createClientKYCInfo() + { + $this->myLogger->logme('error', 'Create Client KYC function called'); + + $rules = [ + 'file_name' => [ + 'rules' => 'uploaded[file_name]|max_size[file_name,5120]|ext_in[file_name,pdf,jpg,jpeg,png]', + 'errors' => [ + 'uploaded' => 'KYC document file is required', + 'max_size' => 'File size should not exceed 5MB', + 'ext_in' => 'Allowed file types: pdf, jpg, jpeg, png', + ] + ], + ]; + + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } + + $data = $this->request->getPost(); + $sanitized_data = sanitizeInputArrayAdvanced($data); + $form_type = $sanitized_data['form_type'] ?? null; + + unset($data['file_name']); + + $file = $this->request->getFile('file_name'); + + $fileName = file_Upload($file, $uploadFilePath); + + if (!empty($fileName)) { + $sanitized_data['file_name'] = $fileName; + } + + $sanitized_data['created_by'] = get_session_userid(); + + $insertID = $this->clientKYCDocsModel->insert($sanitized_data); + if ($insertID) { + if ($form_type === 'others') { + $kycDocs = $this->generateKycOthersTable($sanitized_data['client_id']); + } else { + $kycDocs = $this->generateKycPrimaryTable($sanitized_data['client_id']); + } + return $this->respond(['status' => true, 'code' => 200, 'data' => $kycDocs, 'file_name' => $File], 200); + } else { + return $this->respond(['status' => false, 'code' => 404, 'message' => 'Failed to upload KYC document'], 200); + } + } + + /** Edit Client KYC Documents V1 */ public function editClientKYCInfo() { + $this->myLogger->logme('error', 'Edit Client KYC function called'); + + $rules = [ + 'file_name' => [ + 'rules' => 'uploaded[file_name]|max_size[file_name,5120]|ext_in[file_name,pdf,jpg,jpeg,png]', + 'errors' => [ + 'uploaded' => 'KYC document file is required', + 'max_size' => 'File size should not exceed 5MB', + 'ext_in' => 'Allowed file types: pdf, jpg, jpeg, png', + ] + ], + ]; - $this->myLogger->logme('error', 'edit client kyc function called'); - $uploadFilePath = WRITEPATH . 'uploads/client_kyc_documents'; - $File = file_Upload($this->request->getFile('file_name'), $uploadFilePath); - $form_type = $this->request->getPost('form_type') ?? null; - - if (!empty($File)) { - $data['file_name'] = $File; + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); } - $id = $this->request->getPost('PrimaryKey'); - $data['client_id'] = $id; - $data['kyc_doc_type_id'] = $this->request->getPost('kyc_doc_id'); - $data['updated_by'] = get_session_userid(); - $insert = $this->clientKYCDocsModel->insert($data); - if ($insert) { - // $kycDocs = $this->clientKYCDocsModel->getKycDocsName($id); - if ($form_type == "others") { - $kycDocs = $this->generateKycOthersTable($this->request->getPost('client_id')); + $data = $this->request->getPost(); + $sanitized_data = sanitizeInputArrayAdvanced($data); + $form_type = $sanitized_data['form_type'] ?? null; + + unset($sanitized_data['file_name']); + + $file = $this->request->getFile('file_name'); + + $fileName = file_Upload($file, $uploadFilePath); + + if (!empty($fileName)) { + $sanitized_data['file_name'] = $fileName; + } + $id = $sanitized_data['PrimaryKey']; + $sanitized_data['client_id'] = $id; + $sanitized_data['kyc_doc_type_id'] = $this->request->getPost('kyc_doc_id'); + $sanitized_data['updated_by'] = get_session_userid(); + + $insertID = $this->clientKYCDocsModel->insert($sanitized_data); + if ($insertID) { + if ($form_type === 'others') { + $kycDocs = $this->generateKycOthersTable($sanitized_data['client_id']); } else { - $kycDocs = $this->generateKycPrimaryTable($this->request->getPost('client_id')); + $kycDocs = $this->generateKycPrimaryTable($sanitized_data['client_id']); } - return $this->respond(['status' => true, 'code' => 200, 'data' => $kycDocs], 200); + return $this->respond(['status' => true, 'code' => 200, 'data' => $kycDocs, 'file_name' => $File], 200); } else { - return $this->respond(['status' => false, 'code' => 404, 'message' => 'no data found'], 200); + return $this->respond(['status' => false, 'code' => 404, 'message' => 'Failed to upload KYC document'], 200); } } @@ -1095,12 +1239,33 @@ class ClientController extends AdminController } - + /** Client KYC Documents V2 */ public function createClientKYCInfo_2() { - $this->myLogger->logme('error', 'create Client kyc function called'); - $data = $this->request->getPost(); + $this->myLogger->logme('error', 'Create Client KYC V2 function called'); + + $rules = [ + 'file_name' => [ + 'rules' => 'uploaded[file_name]|max_size[file_name,5120]|ext_in[file_name,pdf,jpg,jpeg,png]', + 'errors' => [ + 'uploaded' => 'KYC document file is required', + 'max_size' => 'File size should not exceed 5MB', + 'ext_in' => 'Allowed file types: pdf, jpg, jpeg, png', + ] + ], + ]; + + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } + + $data = $this->request->getPost(); $uploadedFile = $this->request->getFile('file_name'); if ($uploadedFile && $uploadedFile->isValid() && !$uploadedFile->hasMoved()) { @@ -1108,21 +1273,30 @@ class ClientController extends AdminController } else { $this->myLogger->logme('error', 'File failed validation or was not uploaded.'); } + unset($data['file_name']); + $sanitized_data = sanitizeInputArrayAdvanced($data); + $form_type = $sanitized_data['form_type'] ?? null; + + $file = $this->request->getFile('file_name'); + $fileName = file_Upload($file, $uploadFilePath); + + if (!empty($fileName)) { + $sanitized_data['file_name'] = $fileName; + } + + $sanitized_data['created_by'] = get_session_userid(); $uploadFilePath = WRITEPATH . 'uploads/client_kyc_documents'; $File = file_Upload($uploadedFile, $uploadFilePath); $this->myLogger->logme('info', 'Result of file_Upload: ' . $File); unset($data['file_name']); - if (!empty($File)) { $data['file_name'] = $File; } + $insertID = $this->clientKYCDocsModel->insert($sanitized_data); - $data['created_by'] = get_session_userid(); - $insert = $this->clientKYCDocsModel->insert($data); - - if ($insert) { - $html = $this->generateKycSingleTable($data['client_id']); - $dropdown = $this->fetch_dropdown($data['client_id']); + if ($insertID) { + $html = $this->generateKycSingleTable($sanitized_data['client_id']); + $dropdown = $this->fetch_dropdown($sanitized_data['client_id']); return $this->respond(['status' => true, 'code' => 200, 'file_name' => $File, 'html' => $html,'dropdown'=>$dropdown], 200); } else { $this->myLogger->logme('error', 'Database insert failed.'); @@ -1130,12 +1304,46 @@ class ClientController extends AdminController } } + /** Edit Client KYC Documents V2 */ public function editClientKYCInfo_2() { - $kyc_id = $this->request->getPost('id'); - $client_id = $this->request->getPost('client_id'); - $old_file_name = $this->request->getPost('old_file_name'); + $this->myLogger->logme('error', 'Edit Client KYC V2 function called'); + + $rules = [ + 'file_name' => [ + 'rules' => 'uploaded[file_name]|max_size[file_name,5120]|ext_in[file_name,pdf,jpg,jpeg,png]', + 'errors' => [ + 'uploaded' => 'KYC document file is required', + 'max_size' => 'File size should not exceed 5MB', + 'ext_in' => 'Allowed file types: pdf, jpg, jpeg, png', + ] + ], + ]; + + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } + + + $data = $this->request->getPost(); + unset($data['file_name']); + $sanitized_data = sanitizeInputArrayAdvanced($data); + $form_type = $sanitized_data['form_type'] ?? null; + $kyc_id = $sanitized_data['id'] ?? null; + $client_id = $sanitized_data['client_id'] ?? null; + $old_file_name = $sanitized_data['old_file_name'] ?? null; + + if (empty($kyc_id)) { + return $this->respond(['status' => false, 'message' => 'Missing KYC ID'], 400); + } + + $updateData = []; $uploadedFile = $this->request->getFile('file_name'); $new_file_name = null; $uploadFilePath = WRITEPATH . 'uploads/client_kyc_documents'; @@ -1143,12 +1351,11 @@ class ClientController extends AdminController if ($uploadedFile && $uploadedFile->isValid() && !$uploadedFile->hasMoved()) { - - $new_file_name = file_Upload($uploadedFile, $uploadFilePath); - - if (!empty($new_file_name)) { - - $updateData['file_name'] = $new_file_name; + $new_file_name = file_Upload($uploadedFile, $uploadFilePath); + if (!$new_file_name) { + return $this->respond(['status' => false, 'code' => 500, 'message' => 'New file upload failed on server.'], 200); + } + $updateData['file_name'] = $new_file_name; // Delete the old file from the storage if it exists // if (!empty($old_file_name)) { @@ -1158,56 +1365,64 @@ class ClientController extends AdminController // // Optionally delete from G-Drive here if applicable // } // } - } else { - // New file upload failed - return $this->respond(['status' => false, 'code' => 500, 'message' => 'New file upload failed on server.'], 200); - } + } - // 2. Perform the database update - if (!empty($updateData)) { - - $updateData['updated_by'] = get_session_userid(); - $update = $this->clientKYCDocsModel->update($kyc_id, $updateData); - $html = $this->generateKycSingleTable($client_id); - $dropdown = $this->fetch_dropdown($client_id); - - if ($update) { - return $this->respond(['status' => true, 'code' => 200, 'message' => 'Document updated successfully.','html' => $html,'dropdown' => $dropdown], 200); - } - } else { - + if (empty($updateData)) { return $this->respond(['status' => true, 'code' => 200, 'message' => 'No changes detected. Document remains the same.'], 200); } - + $updateData['updated_by'] = get_session_userid(); + + $update = $this->clientKYCDocsModel->update($kyc_id, $updateData); + + if ($update) { + return $this->respond([ + 'status' => true, + 'message' => 'Document updated successfully', + 'html' => $this->generateKycSingleTable($client_id), + 'dropdown' => $this->fetch_dropdown($client_id) + ], 200); + } + return $this->respond(['status' => false, 'code' => 404, 'message' => 'Database update failed or record not found.'], 200); } - - public function deleteClientKycDocs_2() + /** Delete Client KYC Documents V2 */ + public function deleteClientKycDocs_2() { - - $kyc_id = $this->request->getPost('id'); - $client_id = $this->request->getPost('client_id'); - // echo "KID".$kyc_id; - // echo "CID".$client_id; + $this->myLogger->logme('error', 'Delete Client KYC V2 function called'); + $data = $this->request->getPost(); + $sanitized_data = sanitizeInputArrayAdvanced($data); + $kyc_id = $sanitized_data['id'] ?? null; + $client_id = $sanitized_data['client_id'] ?? null; + $is_active = $sanitized_data['is_active'] ?? null; if (empty($kyc_id)) { return $this->respond(['status' => false, 'code' => 400, 'message' => 'Missing document ID.'], 200); } - $updateData['updated_by'] = get_session_userid(); - $updateData['is_active'] = $this->request->getPost('is_active'); + + + $updateData = [ + 'is_active' => (int) $is_active, + 'updated_by' => get_session_userid() + ]; + $delete = $this->clientKYCDocsModel->update($kyc_id, $updateData); - // $delete = 1; + if ($delete) { - $html = $this->generateKycSingleTable($client_id); - $dropdown = $this->fetch_dropdown($client_id); - return $this->respond(['status' => true, 'code' => 200, 'id' => $kyc_id, 'message' => 'Document successfully deactivated.','html' => $html,'dropdown' => $dropdown], 200); - } else { - return $this->respond(['status' => false, 'code' => 404, 'message' => 'Failed to update record (ID not found or DB error).'], 200); + return $this->respond([ + 'status' => true, + 'code' => 200, + 'id' => $kyc_id, + 'message' => 'Document successfully deactivated.', + 'html' => $this->generateKycSingleTable($client_id), + 'dropdown' => $this->fetch_dropdown($client_id) + ], 200); } + + return $this->respond(['status' => false, 'code' => 404, 'message' => 'Failed to update record (ID not found or DB error).'], 200); } public function fetch_dropdown($client_id) @@ -1365,31 +1580,123 @@ class ClientController extends AdminController { $this->myLogger->logme('error', 'Client branch CREATE function called'); - $data = $this->request->getPost(); - if (!isset($data['sez'])) { - $data['sez'] = 0; - } elseif ($data['sez']) { - $data['sez'] = 1; + $rules = [ + 'branch_name' => [ + 'rules' => 'required', + 'errors' => [ + 'required' => 'Branch Name is required', + ] + ], + 'branch_code' => [ + 'rules' => 'required', + 'errors' => [ + 'required' => 'Branch Code is required', + ] + ], + 'address1' => [ + 'rules' => 'required', + 'errors' => [ + 'required' => 'Address Line 1 is required', + ] + ], + 'state' => [ + 'rules' => 'required', + 'errors' => [ + 'required' => 'State is required', + ] + ], + 'district' => [ + 'rules' => 'required', + 'errors' => [ + 'required' => 'District is required.', + ] + ], + 'city' => [ + 'rules' => 'required', + 'errors' => [ + 'required' => 'City is required.', + ] + ], + 'pincode' => [ + 'rules' => 'required', + 'errors' => [ + 'required' => 'Pincode is required.', + ] + ], + 'gst' => [ + 'rules' => 'required|regex_match[/^\d{2}[A-Z]{5}\d{4}[A-Z]{1}[A-Z\d]{1}Z[A-Z\d]{1}$/]', + 'errors' => [ + 'required' => 'GST number is required', + 'regex_match' => 'Invalid GST Number. Example: 12ABCDE1234F5Z6' + ] + ], + 'name.*' => [ + 'rules' => 'required|alpha_space', + 'errors' => [ + 'required' => 'Contact name is required', + 'alpha_space' => 'Contact name may contain only letters and spaces' + ] + ], + 'designation.*' => [ + 'rules' => 'required|alpha_space', + 'errors' => [ + 'required' => 'Designation is required', + 'alpha_space' => 'Designation may contain only letters and spaces' + ] + ], + 'email.*' => [ + 'rules' => 'required|valid_email', + 'errors' => [ + 'required' => 'Email is required', + 'valid_email' => 'Please enter a valid email address' + ] + ], + 'mobile.*' => [ + 'rules' => 'required|numeric|exact_length[10]', + 'errors' => [ + 'required' => 'Mobile number is required', + 'numeric' => 'Mobile number must contain digits only', + 'exact_length' => 'Mobile number must be exactly 10 digits' + ] + ], + ]; + + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); } - $units = json_decode($data['units'], true) ?? []; + $data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + + if (!isset($sanitized_post_data['sez'])) { + $sanitized_post_data['sez'] = 0; + } elseif ($sanitized_post_data['sez']) { + $sanitized_post_data['sez'] = 1; + } + + $units = json_decode($sanitized_post_data['units'], true) ?? []; if (!is_array($units) || empty($units)) { - $client_data = $this->clientModel->where('id', $data['client_id'])->first(); - $default_unit = trim(($client_data['short_name'] ?? '') . '-' . ($data['branch_code'] ?? ''), '-'); - $data['units'] = json_encode([$default_unit]); + $client_data = $this->clientModel->where('id', $sanitized_post_data['client_id'])->first(); + $default_unit = trim(($client_data['short_name'] ?? '') . '-' . ($sanitized_post_data['branch_code'] ?? ''), '-'); + $sanitized_post_data['units'] = json_encode([$default_unit]); } - $data['created_by'] = get_session_userid(); + $sanitized_post_data['created_by'] = get_session_userid(); // before updating check if pre_branch_id is already existing in the current db - if(isset($data['pre_branch_id']) && !empty($data['pre_branch_id'])) + if(isset($sanitized_post_data['pre_branch_id']) && !empty($sanitized_post_data['pre_branch_id'])) { $existing_pre_branch = $this->clientBranchModel - ->where('pre_branch_id',$data['pre_branch_id']) + ->where('pre_branch_id',$sanitized_post_data['pre_branch_id']) //->where('id !=',$post_branch_id) ->first(); @@ -1405,26 +1712,39 @@ class ClientController extends AdminController - $insert = $this->clientBranchModel->insert($data); + $insert = $this->clientBranchModel->insert($sanitized_post_data); $post_branch_id = $insert; if ($insert) { - $level_contact_data = $this->request->getPost('level_contect_data'); - $level_contact_data = !empty($level_contact_data) ? json_decode($level_contact_data, true) : null; - $this->saveLevelContacts($level_contact_data, $insert); + + $level_contact_data_raw = $this->request->getPost('level_contect_data'); + $level_contact_data = []; + + if (!empty($level_contact_data_raw)) { + $level_contact_data_decoded = json_decode($level_contact_data_raw, true); + + if (json_last_error() === JSON_ERROR_NONE && is_array($level_contact_data_decoded)) { + $level_contact_data = sanitizeInputArrayAdvanced($level_contact_data_decoded); + } + } + + if (!empty($level_contact_data)) { + $this->saveLevelContacts($level_contact_data, $insert); + } + } - if($post_branch_id && isset($data['pre_branch_id']) && !empty($data['pre_branch_id'])) + if($post_branch_id && isset($sanitized_post_data['pre_branch_id']) && !empty($sanitized_post_data['pre_branch_id'])) { // need to update the client_branch in the pre - $result = $this->updatePreClientBranch($data['pre_branch_id'],$post_branch_id , "create"); + $result = $this->updatePreClientBranch($sanitized_post_data['pre_branch_id'],$post_branch_id , "create"); - log_message('error','Pre client_branch update result for pre_branch_id '.$data['pre_branch_id'].' and post_branch_id '.$post_branch_id.' is '.json_encode($result)); + log_message('error','Pre client_branch update result for pre_branch_id '.$sanitized_post_data['pre_branch_id'].' and post_branch_id '.$post_branch_id.' is '.json_encode($result)); } if ($insert) { - $branchData = $this->clientBranchModel->where('client_id', $this->request->getPost('client_id'))->findAll(); + $branchData = $this->clientBranchModel->where('client_id', $sanitized_post_data('client_id'))->findAll(); $branchData['role'] = get_role_id(); return $this->respond([ 'status' => true, @@ -1445,14 +1765,15 @@ class ClientController extends AdminController { $this->myLogger->logme('error', 'Client branch EDIT function called'); - $id = $this->request->getPost('branch_id_primarykey'); - $client_id = $this->request->getPost('client_id'); - $pre_branch_id = $this->request->getPost('pre_branch_id') ?? ''; + $data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + $id = $sanitized_post_data['branch_id_primarykey']; + $client_id = $sanitized_post_data['client_id']; + $pre_branch_id = $sanitized_post_data['pre_branch_id'] ?? ''; - $data = $this->request->getPost(); $data['pre_branch_id'] = $pre_branch_id; - $units = $this->request->getPost('units'); + $units = $sanitized_post_data['units']; $emp_unit_count = 0; $rr_unit_count = 0; @@ -1463,9 +1784,9 @@ class ClientController extends AdminController $units = json_decode($list_of_branch_units['units']); if (!is_array($units) || empty($units)) { - $client_data = $this->clientModel->where('id', $data['client_id'])->first(); - $default_unit = trim(($client_data['short_name'] ?? '') . '-' . ($data['branch_code'] ?? ''), '-'); - $data['units'] = json_encode([$default_unit]); + $client_data = $this->clientModel->where('id', $sanitized_post_data['client_id'])->first(); + $default_unit = trim(($client_data['short_name'] ?? '') . '-' . ($sanitized_post_data['branch_code'] ?? ''), '-'); + $sanitized_post_data['units'] = json_encode([$default_unit]); } if (!empty($units)) { @@ -1481,7 +1802,7 @@ class ClientController extends AdminController $uncommonValues = []; if ($total_count > 0) { - $units = (string) $this->request->getPost('units'); // Assuming 'units' is an array + $units = (string) $sanitized_post_data('units'); // Assuming 'units' is an array $list_of_branch_units = $this->clientBranchModel->find((int)$id); $branch_units = json_decode($list_of_branch_units['units'], true); @@ -1503,22 +1824,22 @@ class ClientController extends AdminController } } - if (!isset($data['sez'])) { - $data['sez'] = 0; - } elseif ($data['sez']) { - $data['sez'] = 1; + if (!isset($sanitized_post_data['sez'])) { + $sanitized_post_data['sez'] = 0; + } elseif ($sanitized_post_data['sez']) { + $sanitized_post_data['sez'] = 1; } - $data['updated_by'] = get_session_userid(); + $sanitized_post_data['updated_by'] = get_session_userid(); $post_branch_id = $id; // before updating check if pre_branch_id is already existing in the current db - if(isset($data['pre_branch_id']) && !empty($data['pre_branch_id'])) + if(isset($sanitized_post_data['pre_branch_id']) && !empty($sanitized_post_data['pre_branch_id'])) { $existing_pre_branch = $this->clientBranchModel - ->where('pre_branch_id',$data['pre_branch_id']) + ->where('pre_branch_id',$sanitized_post_data['pre_branch_id']) ->where('id !=',$post_branch_id) ->first(); @@ -1532,16 +1853,16 @@ class ClientController extends AdminController } } - $insert = $this->clientBranchModel->update($id, $data); + $insert = $this->clientBranchModel->update($id, $sanitized_post_data); - if($post_branch_id && isset($data['pre_branch_id']) && !empty($data['pre_branch_id'])) + if($post_branch_id && isset($sanitized_post_data['pre_branch_id']) && !empty($sanitized_post_data['pre_branch_id'])) { // need to update the client_branch in the pre - $result = $this->updatePreClientBranch($data['pre_branch_id'],$post_branch_id , "update"); + $result = $this->updatePreClientBranch($sanitized_post_data['pre_branch_id'],$post_branch_id , "update"); - log_message('error','Pre client_branch update result for pre_branch_id '.$data['pre_branch_id'].' and post_branch_id '.$post_branch_id.' is '.json_encode($result)); + log_message('error','Pre client_branch update result for pre_branch_id '.$sanitized_post_data['pre_branch_id'].' and post_branch_id '.$post_branch_id.' is '.json_encode($result)); } @@ -1549,10 +1870,22 @@ class ClientController extends AdminController if ($insert) { + + $level_contact_data_raw = $this->request->getPost('level_contect_data'); + $level_contact_data = []; + + if (!empty($level_contact_data_raw)) { + $level_contact_data_decoded = json_decode($level_contact_data_raw, true); + + if (json_last_error() === JSON_ERROR_NONE && is_array($level_contact_data_decoded)) { + $level_contact_data = sanitizeInputArrayAdvanced($level_contact_data_decoded); + } + } + + if (!empty($level_contact_data)) { + $this->saveLevelContacts($level_contact_data, $insert); + } - $level_contact_data = $this->request->getPost('level_contect_data'); - $level_contact_data = !empty($level_contact_data) ? json_decode($level_contact_data, true) : null; - $this->saveLevelContacts($level_contact_data, $id); } if ($insert) { @@ -1567,7 +1900,7 @@ class ClientController extends AdminController 'total_count' => $total_count, 'uncommonValues' => $uncommonValues, 'message' => 'Client branch updated successfully', - 'response_data' => $this->request->getPost() + 'response_data' => $sanitized_post_data ], 200); } else { @@ -1627,8 +1960,7 @@ class ClientController extends AdminController } - - + /** here ci4 rules not implemented, because UI screen Fields are hide/show implemented thats why */ public function createClientPolicy() { @@ -1637,20 +1969,23 @@ class ClientController extends AdminController $this->myLogger->logme('error', 'Client policy CREATE function called'); - $policy_type_id = $this->request->getPost('policy_type_id'); - $client_branch_id = $this->request->getPost('client_branch_id'); - $client_id = $this->request->getPost('client_id'); - $base_policy = $this->request->getPost('base_policy'); + $data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + + $policy_type_id = $sanitized_post_data['policy_type_id']; + $client_branch_id = $sanitized_post_data['client_branch_id']; + $client_id = $sanitized_post_data['client_id']; + $base_policy = $sanitized_post_data['base_policy']; - $insurerValue = (string) $this->request->getPost('insurer'); + $insurerValue = (string) $sanitized_post_data['insurer']; list($insurerBranchId, $insurerId) = explode('-', $insurerValue); $data['insurer_branch_id'] = $insurerBranchId; $data['insurer_id'] = $insurerId; - $tpaValue = (string) $this->request->getPost('tpa'); + $tpaValue = (string) $sanitized_post_data['tpa']; if ($tpaValue === null || $tpaValue === '') { $tpaBranchId = null; @@ -1660,98 +1995,101 @@ class ClientController extends AdminController } - $data['client_id'] = $client_id; - $data['tpa_branch_id'] = $tpaBranchId; - $data['tpa_id'] = $tpaId; - $data['policy_type_id'] = $this->request->getPost('policy_type_id'); + $insert_data['client_id'] = $client_id; + $insert_data['tpa_branch_id'] = $tpaBranchId; + $insert_data['tpa_id'] = $tpaId; + $insert_data['policy_type_id'] = $sanitized_post_data['policy_type_id']; - $data['no_of_lives'] = $this->request->getPost('no_of_lives'); - $data['policy_status'] = $this->request->getPost('policy_status'); - $data['no_of_employees'] = $this->request->getPost('no_of_employees'); - $data['earned_premium_date'] = change_date_format($this->request->getPost('earned_premium_date'), 'd-m-Y', 'Y-m-d') ?? null; - $data['claims_incurred_date'] = change_date_format($this->request->getPost('claims_incurred_date'), 'd-m-Y', 'Y-m-d') ?? null; - $data['incurred_claims_ratio'] = $this->request->getPost('incurred_claims_ratio'); - $data['no_lives_at_inception'] = $this->request->getPost('no_lives_at_inception'); - $data['premium_paid_at_inception'] = $this->request->getPost('premium_paid_at_inception'); - $data['claims_experience_for_last_3_years'] = $this->request->getPost('claims_experience_for_last_3_years'); - $data['earned_premium_amount'] = $this->request->getPost('earned_premium_amount'); - $data['claims_incurred_amount'] = $this->request->getPost('claims_incurred_amount'); - $data['base_policy'] = ($this->request->getPost('base_policy') === '' || $this->request->getPost('base_policy') == 0) ? null : $this->request->getPost('base_policy'); - $data['policy_status'] = 1; - $data['inception_type'] = $this->request->getPost('inception_type') ? 2 : 1; - $data['client_branch_id'] = $this->request->getPost('client_branch_id'); - $data['cd_ac_pk'] = $this->request->getPost('cd_ac_no'); - $data['gst'] = $this->request->getPost('gst'); - $data['disclaimer'] = $this->request->getPost('disclaimer'); - $data['is_member_modify_allowed'] = $this->request->getPost('is_member_modify_allowed') ? 1 : 0; - $data['enrolment_visibility'] = $this->request->getPost('enrolment_visibility') ? 1 : 0; - $data['is_lgbtq'] = $this->request->getPost('is_lgbtq') ? 1 : 0; - $data['wellness_plan_id'] = $this->request->getPost('wellness_plan_id'); - $data['wellness_vendor_id'] = $this->request->getPost('wellness_vendor_id'); - $data['wellness_vendor_id'] = !empty($data['wellness_vendor_id']) ? $data['wellness_vendor_id'] : null; + $insert_data['no_of_lives'] = $sanitized_post_data['no_of_lives']; + $insert_data['policy_status'] = $sanitized_post_data['policy_status']; + $insert_data['no_of_employees'] = $sanitized_post_data['no_of_employees']; + $insert_data['earned_premium_date'] = change_date_format($sanitized_post_data['earned_premium_date'], 'd-m-Y', 'Y-m-d') ?? null; + $insert_data['claims_incurred_date'] = change_date_format($sanitized_post_data['claims_incurred_date'], 'd-m-Y', 'Y-m-d') ?? null; + $insert_data['incurred_claims_ratio'] = $sanitized_post_data['incurred_claims_ratio']; + $insert_data['no_lives_at_inception'] = $sanitized_post_data['no_lives_at_inception']; + $insert_data['premium_paid_at_inception'] = $sanitized_post_data['premium_paid_at_inception']; + $insert_data['claims_experience_for_last_3_years'] = $sanitized_post_data['claims_experience_for_last_3_years']; + $insert_data['earned_premium_amount'] = $sanitized_post_data['earned_premium_amount']; + $insert_data['claims_incurred_amount'] = $sanitized_post_data['claims_incurred_amount']; + $insert_data['base_policy'] = ($sanitized_post_data['base_policy'] === '' || $sanitized_post_data['base_policy'] == 0) ? null : $sanitized_post_data['base_policy']; + $insert_data['policy_status'] = 1; + $insert_data['inception_type'] = $sanitized_post_data['inception_type'] ? 2 : 1; + $insert_data['client_branch_id'] = $sanitized_post_data['client_branch_id']; + $insert_data['cd_ac_pk'] = $sanitized_post_data['cd_ac_no']; + $insert_data['gst'] = $sanitized_post_data['gst']; + $insert_data['disclaimer'] = $sanitized_post_data['disclaimer']; + $insert_data['is_member_modify_allowed'] = $sanitized_post_data['is_member_modify_allowed'] ? 1 : 0; + $insert_data['enrolment_visibility'] = $sanitized_post_data['enrolment_visibility'] ? 1 : 0; + $insert_data['is_lgbtq'] = $sanitized_post_data['is_lgbtq'] ? 1 : 0; + $insert_data['wellness_plan_id'] = $sanitized_post_data['wellness_plan_id']; + $insert_data['wellness_vendor_id'] = $sanitized_post_data['wellness_vendor_id']; + $insert_data['wellness_vendor_id'] = !empty($insert_data['wellness_vendor_id']) ? $insert_data['wellness_vendor_id'] : null; if ($policy_type_id == 1 || $policy_type_id == 2 || $policy_type_id == 6 || $policy_type_id == 7) { - $data['is_addon'] = 1; // Base Policy + $insert_data['is_addon'] = 1; // Base Policy } else if ($policy_type_id == 4 || $policy_type_id == 5) { - $data['is_addon'] = 2; // SI TOPUP + $insert_data['is_addon'] = 2; // SI TOPUP } else if ($policy_type_id == 3) { if ($base_policy) { - $data['is_addon'] = 3; // Dependent Addon + $insert_data['is_addon'] = 3; // Dependent Addon } else { - $data['is_addon'] = 1; + $insert_data['is_addon'] = 1; } } - $data['policy_start_date'] = change_date_format($this->request->getPost('policy_start_date'), 'd-m-Y', 'Y-m-d'); - $data['policy_end_date'] = change_date_format($this->request->getPost('policy_end_date'), 'd-m-Y', 'Y-m-d'); - $data['policy_no'] = $this->request->getPost('policy_no'); - if ($data['inception_type'] == 2) { - $data['open_date'] = change_date_format($this->request->getPost('open_date'), 'd-m-Y', 'Y-m-d'); - $data['close_date'] = change_date_format($this->request->getPost('close_date'), 'd-m-Y', 'Y-m-d'); + $insert_data['policy_start_date'] = change_date_format($sanitized_post_data['policy_start_date'], 'd-m-Y', 'Y-m-d'); + $insert_data['policy_end_date'] = change_date_format($sanitized_post_data['policy_end_date'], 'd-m-Y', 'Y-m-d'); + $insert_data['policy_no'] = $sanitized_post_data['policy_no']; + if ($insert_data['inception_type'] == 2) { + $insert_data['open_date'] = change_date_format($sanitized_post_data['open_date'], 'd-m-Y', 'Y-m-d'); + $insert_data['close_date'] = change_date_format($sanitized_post_data['close_date'], 'd-m-Y', 'Y-m-d'); // $data['reminder_date'] = change_date_format($this->request->getPost('reminder_date'), 'd-m-Y', 'Y-m-d'); - $data['reminder_date'] = $this->request->getPost('reminder_date'); + $insert_data['reminder_date'] = $sanitized_post_data['reminder_date']; } else { - $data['open_date'] = null; - $data['closedate'] = null; - $data['reminder_date'] = null; + $insert_data['open_date'] = null; + $insert_data['closedate'] = null; + $insert_data['reminder_date'] = null; } - $data['created_by'] = get_session_userid(); + $insert_data['created_by'] = get_session_userid(); - $insert = $this->clientPolicyModel->insert($data); + $insert = $this->clientPolicyModel->insert($insert_data); if ($insert) { - $clientPoliceData = $this->clientPolicyModel->getClientPolicyByClientId($this->request->getPost('client_id')); + $clientPoliceData = $this->clientPolicyModel->getClientPolicyByClientId($sanitized_post_data['client_id']); $clientPoliceData['role'] = get_role_id(); - return $this->respond(['status' => true, 'code' => 200, 'data' => $clientPoliceData, 'method' => 'CERATE', 'post_data' => $data], 200); + return $this->respond(['status' => true, 'code' => 200, 'data' => $clientPoliceData, 'method' => 'CERATE', 'post_data' => $insert_data], 200); } else { return $this->respond(['status' => false, 'code' => 404, 'message' => 'no data found'], 200); } } + /** here ci4 rules not implemented, because UI screen Fields are hide/show implemented thats why */ public function editClientPolicy() { $this->myLogger->logme('error', 'Client policy function called'); + $data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); - $id = $this->request->getPost('PrimaryKey'); - $client_id = $this->request->getPost('client_id'); - $policy_type_id = $this->request->getPost('policy_type_id'); - $base_policy = $this->request->getPost('base_policy'); + $id = $sanitized_post_data['PrimaryKey']; + $client_id = $sanitized_post_data['client_id']; + $policy_type_id = $sanitized_post_data['policy_type_id']; + $base_policy = $sanitized_post_data['base_policy']; - $insurerValue = (string) $this->request->getPost('insurer'); + $insurerValue = (string) $sanitized_post_data['insurer']; list($insurerBranchId, $insurerId) = explode('-', $insurerValue); $data['insurer_branch_id'] = $insurerBranchId; $data['insurer_id'] = $insurerId; - $tpaValue = (string) $this->request->getPost('tpa'); + $tpaValue = (string) $sanitized_post_data['tpa']; if (!empty($tpaValue) || $tpaValue !== '') { list($tpaBranchId, $tpaId) = explode('-', $tpaValue); } else { @@ -1759,75 +2097,75 @@ class ClientController extends AdminController $tpaId = null; } - $data['tpa_branch_id'] = $tpaBranchId; - $data['client_id'] = $client_id; - $data['tpa_id'] = $tpaId; - $data['policy_type_id'] = $this->request->getPost('policy_type_id'); - $data['policy_no'] = $this->request->getPost('policy_no'); + $update_data['tpa_branch_id'] = $tpaBranchId; + $update_data['client_id'] = $client_id; + $update_data['tpa_id'] = $tpaId; + $update_data['policy_type_id'] = $sanitized_post_data['policy_type_id']; + $update_data['policy_no'] = $sanitized_post_data['policy_no']; - $data['insured'] = $this->request->getPost('insured'); - $data['no_of_lives'] = $this->request->getPost('no_of_lives'); - $data['policy_status'] = $this->request->getPost('policy_status'); - $data['no_of_employees'] = $this->request->getPost('no_of_employees'); - $data['earned_premium_date'] = change_date_format($this->request->getPost('earned_premium_date'), 'd-m-Y', 'Y-m-d') ?? null; - $data['claims_incurred_date'] = change_date_format($this->request->getPost('claims_incurred_date'), 'd-m-Y', 'Y-m-d') ?? null; - $data['incurred_claims_ratio'] = $this->request->getPost('incurred_claims_ratio'); - $data['no_lives_at_inception'] = $this->request->getPost('no_lives_at_inception'); - $data['premium_paid_at_inception'] = $this->request->getPost('premium_paid_at_inception'); - $data['claims_experience_for_last_3_years'] = $this->request->getPost('claims_experience_for_last_3_years'); - $data['earned_premium_amount'] = $this->request->getPost('earned_premium_amount'); - $data['claims_incurred_amount'] = $this->request->getPost('claims_incurred_amount'); - $data['base_policy'] = ($this->request->getPost('base_policy') === '' || $this->request->getPost('base_policy') == 0) ? null : $this->request->getPost('base_policy'); - $data['policy_status'] = 1; - $data['inception_type'] = $this->request->getPost('inception_type') ? 2 : 1; - $data['enrolment_visibility'] = $this->request->getPost('enrolment_visibility') ? 1 : 0; - $data['client_branch_id'] = $this->request->getPost('client_branch_id'); - $data['cd_ac_pk'] = $this->request->getPost('cd_ac_no'); - $data['gst'] = $this->request->getPost('gst'); - $data['disclaimer'] = $this->request->getPost('disclaimer'); - $data['policy_start_date'] = change_date_format($this->request->getPost('policy_start_date'), 'd-m-Y', 'Y-m-d'); - $data['policy_end_date'] = change_date_format($this->request->getPost('policy_end_date'), 'd-m-Y', 'Y-m-d'); - $data['is_member_modify_allowed'] = $this->request->getPost('is_member_modify_allowed') ? 1 : 0; - $data['is_lgbtq'] = $this->request->getPost('is_lgbtq') ? 1 : 0; - $data['wellness_plan_id'] = $this->request->getPost('wellness_plan_id'); - $data['wellness_vendor_id'] = $this->request->getPost('wellness_vendor_id'); - $data['wellness_vendor_id'] = !empty($data['wellness_vendor_id']) ? $data['wellness_vendor_id'] : null; + $update_data['insured'] = $sanitized_post_data['insured']; + $update_data['no_of_lives'] = $sanitized_post_data['no_of_lives']; + $update_data['policy_status'] = $sanitized_post_data['policy_status']; + $update_data['no_of_employees'] = $sanitized_post_data['no_of_employees']; + $update_data['earned_premium_date'] = change_date_format($sanitized_post_data['earned_premium_date'], 'd-m-Y', 'Y-m-d') ?? null; + $update_data['claims_incurred_date'] = change_date_format($sanitized_post_data['claims_incurred_date'], 'd-m-Y', 'Y-m-d') ?? null; + $update_data['incurred_claims_ratio'] = $sanitized_post_data['incurred_claims_ratio']; + $update_data['no_lives_at_inception'] = $sanitized_post_data['no_lives_at_inception']; + $update_data['premium_paid_at_inception'] = $sanitized_post_data['premium_paid_at_inception']; + $update_data['claims_experience_for_last_3_years'] = $sanitized_post_data['claims_experience_for_last_3_years']; + $update_data['earned_premium_amount'] = $sanitized_post_data['earned_premium_amount']; + $update_data['claims_incurred_amount'] = $sanitized_post_data['claims_incurred_amount']; + $update_data['base_policy'] = ($sanitized_post_data['base_policy'] === '' || $sanitized_post_data['base_policy'] == 0) ? null : $sanitized_post_data['base_policy']; + $update_data['policy_status'] = 1; + $update_data['inception_type'] = $sanitized_post_data['inception_type'] ? 2 : 1; + $update_data['enrolment_visibility'] = $sanitized_post_data['enrolment_visibility'] ? 1 : 0; + $update_data['client_branch_id'] = $sanitized_post_data['client_branch_id']; + $update_data['cd_ac_pk'] = $sanitized_post_data['cd_ac_no']; + $update_data['gst'] = $sanitized_post_data['gst']; + $update_data['disclaimer'] = $sanitized_post_data['disclaimer']; + $update_data['policy_start_date'] = change_date_format($sanitized_post_data['policy_start_date'], 'd-m-Y', 'Y-m-d'); + $update_data['policy_end_date'] = change_date_format($sanitized_post_data['policy_end_date'], 'd-m-Y', 'Y-m-d'); + $update_data['is_member_modify_allowed'] = $sanitized_post_data['is_member_modify_allowed'] ? 1 : 0; + $update_data['is_lgbtq'] = $sanitized_post_data['is_lgbtq'] ? 1 : 0; + $update_data['wellness_plan_id'] = $sanitized_post_data['wellness_plan_id']; + $update_data['wellness_vendor_id'] = $sanitized_post_data['wellness_vendor_id']; + $update_data['wellness_vendor_id'] = !empty($update_data['wellness_vendor_id']) ? $update_data['wellness_vendor_id'] : null; - if ($data['inception_type'] == 2) { - $data['open_date'] = change_date_format($this->request->getPost('open_date'), 'd-m-Y', 'Y-m-d'); - $data['close_date'] = change_date_format($this->request->getPost('close_date'), 'd-m-Y', 'Y-m-d'); - // $data['reminder_date'] = change_date_format($this->request->getPost('reminder_date'), 'd-m-Y', 'Y-m-d'); - $data['reminder_date'] = $this->request->getPost('reminder_date'); + if ($update_data['inception_type'] == 2) { + $update_data['open_date'] = change_date_format($sanitized_post_data['open_date'], 'd-m-Y', 'Y-m-d'); + $update_data['close_date'] = change_date_format($sanitized_post_data['close_date'], 'd-m-Y', 'Y-m-d'); + // $data['reminder_date'] = change_date_format($sanitized_post_data['reminder_date'), 'd-m-Y', 'Y-m-d'); + $update_data['reminder_date'] = $sanitized_post_data['reminder_date']; } else { - $data['open_date'] = null; - $data['close_date'] = null; - $data['reminder_date'] = null; + $update_data['open_date'] = null; + $update_data['close_date'] = null; + $update_data['reminder_date'] = null; } if ($policy_type_id == 1 || $policy_type_id == 2 || $policy_type_id == 6 || $policy_type_id == 7) { - $data['is_addon'] = 1; // Base Policy + $update_data['is_addon'] = 1; // Base Policy } else if ($policy_type_id == 4 || $policy_type_id == 5) { - $data['is_addon'] = 2; // SI TOPUP + $update_data['is_addon'] = 2; // SI TOPUP } else if ($policy_type_id == 3) { if ($base_policy) { - $data['is_addon'] = 3; // Dependent Addon + $update_data['is_addon'] = 3; // Dependent Addon } else { - $data['is_addon'] = 1; + $update_data['is_addon'] = 1; } } - $policy_terms = $this->clientPolicyModel->where('id', $this->request->getPost('base_policy'))->first(); + $policy_terms = $this->clientPolicyModel->where('id', $sanitized_post_data['base_policy'])->first(); $old_client_policy_data = $this->clientPolicyModel->where('is_active', 1)->where('id', $id)->first(); - $data['updated_by'] = get_session_userid(); - $insert = $this->clientPolicyModel->update($id, $data); + $update_data['updated_by'] = get_session_userid(); + $update = $this->clientPolicyModel->update($id, $update_data); - if ($insert) { + if ($update) { $new_client_policy_data = $this->clientPolicyModel->where('is_active', 1)->where('id', $id)->first(); $policy_transaction_data = $this->policyTransactionModel->where('is_active', 1)->where('client_policy_id', $id)->countAllResults(); @@ -1917,10 +2255,13 @@ class ClientController extends AdminController // echo json_encode(['key' => $this->request->getPost()]); die; try { - $client_id = $this->request->getPost('client_id'); - $client_policy_id = $this->request->getPost('client_policy_id'); + $data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + + $client_id = $sanitized_post_data['client_id']; + $client_policy_id = $sanitized_post_data['client_policy_id']; $record = $this->clientPolicyModel->where('client_policy.id', $client_policy_id)->first(); - $premium_type = $this->request->getPost('premium_type'); + $premium_type = $sanitized_post_data['premium_type']; if (!empty($client_id) && $client_id != null) { $client_policy_data = $this->clientPolicyModel->where('id', $client_policy_id)->first(); $client_id = $client_policy_data['client_id']; @@ -1929,24 +2270,24 @@ class ClientController extends AdminController $branch_units = $this->getBranchUnitsByBranchId($record['client_branch_id']); $branch_units = json_decode($branch_units); - $policy_grid_id = $this->request->getPost('policy_grid_id'); - $rack_rate_name = $this->request->getPost('rack_rate_name'); + $policy_grid_id = $sanitized_post_data['policy_grid_id']; + $rack_rate_name = $sanitized_post_data['rack_rate_name']; $relation_data = [ - 'self' => $this->request->getPost('self') ?? 'NA', - 'spouse' => $this->request->getPost('spouse') ?? 'NA', - 'childrens' => $this->request->getPost('childrens') ?? 'NA', - 'parents' => $this->request->getPost('parents') ?? 'NA', - 'parents-in-law' => $this->request->getPost('parents-in-law') ?? 'NA', + 'self' => $sanitized_post_data['self'] ?? 'NA', + 'spouse' => $sanitized_post_data['spouse'] ?? 'NA', + 'childrens' => $sanitized_post_data['childrens'] ?? 'NA', + 'parents' => $sanitized_post_data['parents'] ?? 'NA', + 'parents-in-law' => $sanitized_post_data['parents-in-law'] ?? 'NA', ]; $relation_data_for_form_submit_check = [ $rack_rate_name => [ - 'self' => $this->request->getPost('self') ?? 'NA', - 'spouse' => $this->request->getPost('spouse') ?? 'NA', - 'childrens' => $this->request->getPost('childrens') ?? 'NA', - 'parents' => $this->request->getPost('parents') ?? 'NA', - 'parents-in-law' => $this->request->getPost('parents-in-law') ?? 'NA', + 'self' => $sanitized_post_data['self'] ?? 'NA', + 'spouse' => $sanitized_post_data['spouse'] ?? 'NA', + 'childrens' => $sanitized_post_data['childrens'] ?? 'NA', + 'parents' => $sanitized_post_data['parents'] ?? 'NA', + 'parents-in-law' => $sanitized_post_data['parents-in-law'] ?? 'NA', ] ]; @@ -1964,11 +2305,11 @@ class ClientController extends AdminController $jsonDataForRelation = json_encode($relation_data); $json_data_relation_data_for_form_submit_check = json_encode($relation_data_for_form_submit_check); - $si_or_bp = $this->request->getPost('si_or_bp'); - $basic_multiplier = str_replace(',', '', $this->request->getPost('basic_multiplier')); - $premium_multiplier = str_replace(',', '', $this->request->getPost('premium_multiplier')); - $multiplier = str_replace(',', '', $this->request->getPost('multiplier')); - $basic_pay = str_replace(',', '', $this->request->getPost('basic_pay')); + $si_or_bp = $sanitized_post_data['si_or_bp']; + $basic_multiplier = str_replace(',', '', $sanitized_post_data['basic_multiplier']); + $premium_multiplier = str_replace(',', '', $sanitized_post_data['premium_multiplier']); + $multiplier = str_replace(',', '', $sanitized_post_data['multiplier']); + $basic_pay = str_replace(',', '', $sanitized_post_data['basic_pay']); $data = []; $data['client_id'] = $client_id; @@ -1990,16 +2331,16 @@ class ClientController extends AdminController if ($si_or_bp == '1') { - $premium = str_replace(',', '', $this->request->getPost('gpa_sum_premium[]')); - $sum_insure = str_replace(',', '', $this->request->getPost('gpa_sum_si[]')); - $multiplier = $this->request->getPost('gpa_sum_multiplier'); - $unit = $this->request->getPost('gpa_unit_1[]'); + $premium = str_replace(',', '', $sanitized_post_data['gpa_sum_premium[]']); + $sum_insure = str_replace(',', '', $sanitized_post_data['gpa_sum_si[]']); + $multiplier = $sanitized_post_data['gpa_sum_multiplier']; + $unit = $sanitized_post_data['gpa_unit_1[]']; for ($i = 0; $i < count($premium); $i++) { $data['si'] = $sum_insure[$i]; $data['premium'] = $premium[$i]; $data['multiplier'] = $multiplier; - $data['si_or_bp'] = $this->request->getPost('si_or_bp'); + $data['si_or_bp'] = $sanitized_post_data['si_or_bp']; if (empty($unit) || !isset($unit[$i]) || empty($unit[$i])) { $data['unit'] = $branch_units[0]; } else { @@ -2010,11 +2351,11 @@ class ClientController extends AdminController } } else if ($si_or_bp == '3') { - $premium = str_replace(',', '', $this->request->getPost('gpa_sum_premium2[]')); - $sum_insure = str_replace(',', '', $this->request->getPost('gpa_sum_si2[]')); - $multiplier = $this->request->getPost('gpa_sum_multiplier2'); - $grade = $this->request->getPost('gpa_band[]'); - $unit = $this->request->getPost('gpa_unit_3[]'); + $premium = str_replace(',', '', $sanitized_post_data['gpa_sum_premium2[]']); + $sum_insure = str_replace(',', '', $sanitized_post_data['gpa_sum_si2[]']); + $multiplier = $sanitized_post_data['gpa_sum_multiplier2']; + $grade = $sanitized_post_data['gpa_band[]']; + $unit = $sanitized_post_data['gpa_unit_3[]']; for ($i = 0; $i < count($premium); $i++) { @@ -2022,7 +2363,7 @@ class ClientController extends AdminController $data['premium'] = $premium[$i]; $data['grade'] = $grade[$i]; $data['multiplier'] = $multiplier; - $data['si_or_bp'] = $this->request->getPost('si_or_bp'); + $data['si_or_bp'] = $sanitized_post_data['si_or_bp']; if (empty($unit) || !isset($unit[$i]) || empty($unit[$i])) { $data['unit'] = $branch_units[0]; } else { @@ -2033,17 +2374,17 @@ class ClientController extends AdminController } } else if ($si_or_bp == '2') { - $premium = str_replace(',', '', $this->request->getPost('gpa_basic_premium[]')); - $sum_insure = str_replace(',', '', $this->request->getPost('gpa_basic_si[]')); - $basic_pay = str_replace(',', '', $this->request->getPost('basic_pay[]')); - $unit = $this->request->getPost('gpa_unit[]'); + $premium = str_replace(',', '', $sanitized_post_data['gpa_basic_premium[]']); + $sum_insure = str_replace(',', '', $sanitized_post_data['gpa_basic_si[]']); + $basic_pay = str_replace(',', '', $sanitized_post_data['basic_pay[]']); + $unit = $sanitized_post_data['gpa_unit[]']; for ($i = 0; $i < count($premium); $i++) { - $data['si_or_bp'] = $this->request->getPost('si_or_bp'); - $data['basic_multiplier'] = str_replace(',', '', $this->request->getPost('basic_multiplier')); - $data['multiplier'] = $this->request->getPost('premium_multiplier'); + $data['si_or_bp'] = $sanitized_post_data['si_or_bp']; + $data['basic_multiplier'] = str_replace(',', '', $sanitized_post_data['basic_multiplier']); + $data['multiplier'] = $sanitized_post_data['premium_multiplier']; $data['basic_pay'] = $basic_pay[$i]; $data['si'] = $sum_insure[$i]; $data['premium'] = $premium[$i]; @@ -2057,23 +2398,23 @@ class ClientController extends AdminController } } else { - $data['premium'] = str_replace(',', '', $this->request->getPost('gpa_basic_premium')); - $data['si'] = str_replace(',', '', $this->request->getPost('gpa_basic_si')); - $data['basic_multiplier'] = str_replace(',', '', $this->request->getPost('basic_multiplier')); - $data['multiplier'] = $this->request->getPost('premium_multiplier'); - $data['basic_pay'] = str_replace(',', '', $this->request->getPost('basic_pay')); - $data['si_or_bp'] = $this->request->getPost('si_or_bp'); + $data['premium'] = str_replace(',', '', $sanitized_post_data['gpa_basic_premium']); + $data['si'] = str_replace(',', '', $sanitized_post_data['gpa_basic_si']); + $data['basic_multiplier'] = str_replace(',', '', $sanitized_post_data['basic_multiplier']); + $data['multiplier'] = $sanitized_post_data['premium_multiplier']; + $data['basic_pay'] = str_replace(',', '', $sanitized_post_data['basic_pay']); + $data['si_or_bp'] = $sanitized_post_data['si_or_bp']; $policyPremium = $this->policyPremium1Model->insert($data); } - $data = $this->request->getPost(); + $data = $sanitized_post_data; $insert = true; } else if ($policy_grid_id == '2') { - $premium = $this->request->getPost('gpa_premium29[]'); - $sum_insure = $this->request->getPost('gpa_si29[]'); - $unit = $this->request->getPost('gpa_unit29[]'); + $premium = $sanitized_post_data['gpa_premium29[]']; + $sum_insure = $sanitized_post_data['gpa_si29[]']; + $unit = $sanitized_post_data['gpa_unit29[]']; for ($i = 0; $i < count($premium); $i++) { $data['premium'] = str_replace(',', '', $premium[$i]); @@ -2086,13 +2427,13 @@ class ClientController extends AdminController $dataa = $this->policyPremium1Model->insert($data); } - $data = $this->request->getPost(); + $data = $sanitized_post_data; $insert = true; } else if ($policy_grid_id == '3') { - $premium = $this->request->getPost('3_premium[]'); - $sum_insure = $this->request->getPost('3_si[]'); - $unit = $this->request->getPost('3_unit[]'); + $premium = $sanitized_post_data['3_premium[]']; + $sum_insure = $sanitized_post_data['3_si[]']; + $unit = $sanitized_post_data['3_unit[]']; for ($i = 0; $i < count($premium); $i++) { $data['premium'] = str_replace(',', '', $premium[$i]); @@ -2104,15 +2445,15 @@ class ClientController extends AdminController } $dataa = $this->policyPremium2Model->insert($data); } - $data = $this->request->getPost(); + $data = $sanitized_post_data; $insert = true; } else if ($policy_grid_id == '4') { - $premium = $this->request->getPost('4_premium[]'); - $sum_insure = $this->request->getPost('4_si'); - $age_from = $this->request->getPost('4_age_from[]'); - $age_to = $this->request->getPost('4_age_to[]'); - $unit = $this->request->getPost('4_unit[]'); + $premium = $sanitized_post_data['4_premium[]']; + $sum_insure = $sanitized_post_data['4_si']; + $age_from = $sanitized_post_data['4_age_from[]']; + $age_to = $sanitized_post_data['4_age_to[]']; + $unit = $sanitized_post_data['4_unit[]']; for ($i = 0; $i < count($premium); $i++) { $data['premium'] = str_replace(',', '', $premium[$i]); @@ -2127,15 +2468,15 @@ class ClientController extends AdminController $dataa = $this->policyPremium2Model->insert($data); } - $data = $this->request->getPost(); + $data = $sanitized_post_data; $insert = true; } else if ($policy_grid_id == '5') { - $premium = $this->request->getPost('5_premium[]'); - $sum_insure = $this->request->getPost('5_si[]'); - $age_from = $this->request->getPost('5_age_from[]'); - $age_to = $this->request->getPost('5_age_to[]'); - $unit = $this->request->getPost('5_unit[]'); + $premium = $sanitized_post_data['5_premium[]']; + $sum_insure = $sanitized_post_data['5_si[]']; + $age_from = $sanitized_post_data['5_age_from[]']; + $age_to = $sanitized_post_data['5_age_to[]']; + $unit = $sanitized_post_data['5_unit[]']; for ($i = 0; $i < count($premium); $i++) { $data['premium'] = str_replace(',', '', $premium[$i]); @@ -2151,15 +2492,15 @@ class ClientController extends AdminController $dataa = $this->policyPremium2Model->insert($data); } - $data = $this->request->getPost(); + $data = $sanitized_post_data; $insert = true; } else if ($policy_grid_id == '6') { - $premium = $this->request->getPost('6_premium[]'); - $sum_insure = $this->request->getPost('6_si'); - $age_from = $this->request->getPost('6_age_from[]'); - $age_to = $this->request->getPost('6_age_to[]'); - $unit = $this->request->getPost('6_unit[]'); + $premium = $sanitized_post_data['6_premium[]']; + $sum_insure = $sanitized_post_data['6_si']; + $age_from = $sanitized_post_data['6_age_from[]']; + $age_to = $sanitized_post_data['6_age_to[]']; + $unit = $sanitized_post_data['6_unit[]']; for ($i = 0; $i < count($premium); $i++) { $data['premium'] = str_replace(',', '', $premium[$i]); @@ -2174,14 +2515,14 @@ class ClientController extends AdminController $dataa = $this->policyPremium2Model->insert($data); } - $data = $this->request->getPost(); + $data = $sanitized_post_data; $insert = true; } else if ($policy_grid_id == '7') { - $premium = $this->request->getPost('7_premium[]'); - $sum_insure = $this->request->getPost('7_si[]'); - $age_from = $this->request->getPost('7_age_from[]'); - $age_to = $this->request->getPost('7_age_to[]'); - $unit = $this->request->getPost('7_unit[]'); + $premium = $sanitized_post_data['7_premium[]']; + $sum_insure = $sanitized_post_data['7_si[]']; + $age_from = $sanitized_post_data['7_age_from[]']; + $age_to = $sanitized_post_data['7_age_to[]']; + $unit = $sanitized_post_data['7_unit[]']; for ($i = 0; $i < count($premium); $i++) { $data['premium'] = str_replace(',', '', $premium[$i]); @@ -2196,13 +2537,13 @@ class ClientController extends AdminController $dataa = $this->policyPremium2Model->insert($data); } - $data = $this->request->getPost(); + $data = $sanitized_post_data; $insert = true; } else if ($policy_grid_id == '8') { - $premium = $this->request->getPost('8_premium[]'); - $sum_insure = $this->request->getPost('8_si[]'); - $grade = $this->request->getPost('8_grade[]'); - $unit = $this->request->getPost('8_unit[]'); + $premium = $sanitized_post_data['8_premium[]']; + $sum_insure = $sanitized_post_data['8_si[]']; + $grade = $sanitized_post_data['8_grade[]']; + $unit = $sanitized_post_data['8_unit[]']; for ($i = 0; $i < count($premium); $i++) { $data['premium'] = str_replace(',', '', $premium[$i]); @@ -2216,13 +2557,13 @@ class ClientController extends AdminController $dataa = $this->policyPremium2Model->insert($data); } - $data = $this->request->getPost(); + $data = $sanitized_post_data; $insert = true; } else if ($policy_grid_id == '9') { - $premium = $this->request->getPost('gpa_premium29[]'); - $sum_insure = $this->request->getPost('gpa_si29[]'); - $unit = $this->request->getPost('gpa_unit29[]'); + $premium = $sanitized_post_data['gpa_premium29[]']; + $sum_insure = $sanitized_post_data['gpa_si29[]']; + $unit = $sanitized_post_data['gpa_unit29[]']; for ($i = 0; $i < count($premium); $i++) { $data['premium'] = str_replace(',', '', $premium[$i]); @@ -2235,14 +2576,14 @@ class ClientController extends AdminController $dataa = $this->policyPremium2Model->insert($data); } - $data = $this->request->getPost(); + $data = $sanitized_post_data; $insert = true; } else if ($policy_grid_id == '10') { - $premium = $this->request->getPost('10_premium[]'); - $sum_insure = $this->request->getPost('10_si[]'); - $age_from = $this->request->getPost('10_age_from[]'); - $age_to = $this->request->getPost('10_age_to[]'); - $unit = $this->request->getPost('10_unit[]'); + $premium = $sanitized_post_data['10_premium[]']; + $sum_insure = $sanitized_post_data['10_si[]']; + $age_from = $sanitized_post_data['10_age_from[]']; + $age_to = $sanitized_post_data['10_age_to[]']; + $unit = $sanitized_post_data['10_unit[]']; for ($i = 0; $i < count($premium); $i++) { $data['premium'] = str_replace(',', '', $premium[$i]); @@ -2258,15 +2599,15 @@ class ClientController extends AdminController $policyPremium = $this->policyPremium2Model->insert($data); } - $data = $this->request->getPost(); + $data = $sanitized_post_data; $insert = true; } else if ($policy_grid_id == '11') { - $premium = $this->request->getPost('11_premium[]'); - $sum_insure = $this->request->getPost('11_si[]'); - $grade = $this->request->getPost('11_grade[]'); - $max_sum_insure = $this->request->getPost('11_max_si[]'); - $unit = $this->request->getPost('11_unit[]'); + $premium = $sanitized_post_data['11_premium[]']; + $sum_insure = $sanitized_post_data['11_si[]']; + $grade = $sanitized_post_data['11_grade[]']; + $max_sum_insure = $sanitized_post_data['11_max_si[]']; + $unit = $sanitized_post_data['11_unit[]']; for ($i = 0; $i < count($premium); $i++) { $data['premium'] = str_replace(',', '', $premium[$i]); @@ -2281,14 +2622,14 @@ class ClientController extends AdminController $dataa = $this->policyPremium2Model->insert($data); } - $data = $this->request->getPost(); + $data = $sanitized_post_data; $insert = true; } else if ($policy_grid_id == '12') { - $premium = $this->request->getPost('12_premium[]'); - $sum_insure = $this->request->getPost('12_si[]'); - $relationship = $this->request->getPost('12_relationship[]'); - $unit = $this->request->getPost('12_unit[]'); + $premium = $sanitized_post_data['12_premium[]']; + $sum_insure = $sanitized_post_data['12_si[]']; + $relationship = $sanitized_post_data['12_relationship[]']; + $unit = $sanitized_post_data['12_unit[]']; for ($i = 0; $i < count($premium); $i++) { $data['premium'] = str_replace(',', '', $premium[$i]); @@ -2302,16 +2643,16 @@ class ClientController extends AdminController $dataa = $this->policyPremium2Model->insert($data); } - $data = $this->request->getPost(); + $data = $sanitized_post_data; $insert = true; } else if ($policy_grid_id == '13') { - $premium = $this->request->getPost('13_premium[]'); - $sum_insure = $this->request->getPost('13_si[]'); - $age_from = $this->request->getPost('13_age_from[]'); - $age_to = $this->request->getPost('13_age_to[]'); - $relationship = $this->request->getPost('13_relationship[]'); - $unit = $this->request->getPost('13_unit[]'); + $premium = $sanitized_post_data['13_premium[]']; + $sum_insure = $sanitized_post_data['13_si[]']; + $age_from = $sanitized_post_data['13_age_from[]']; + $age_to = $sanitized_post_data['13_age_to[]']; + $relationship = $sanitized_post_data['13_relationship[]']; + $unit = $sanitized_post_data['13_unit[]']; for ($i = 0; $i < count($premium); $i++) { $data['premium'] = str_replace(',', '', $premium[$i]); @@ -2327,7 +2668,7 @@ class ClientController extends AdminController $dataa = $this->policyPremium2Model->insert($data); } - $data = $this->request->getPost(); + $data = $sanitized_post_data; $insert = true; } @@ -2498,10 +2839,11 @@ class ClientController extends AdminController if(empty($params) && $this->request){ $data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); $files = $this->request->getFiles(); - $client_id = $data['client_id'] ?? null; - $vehicle_id = $data['vehicle_id'] ?? null; - $docs_name = $data['other_docs_name'] ?? null; + $client_id = $sanitized_post_data['client_id'] ?? null; + $vehicle_id = $sanitized_post_data['vehicle_id'] ?? null; + $docs_name = $sanitized_post_data['other_docs_name'] ?? null; }else { $client_id = $params['client_id'] ?? null; $vehicle_id = $params['vehicle_id'] ?? null; @@ -2552,8 +2894,8 @@ class ClientController extends AdminController if (!empty($insertedDocs)) { // Fetch all documents for the client $vehicleDocs = $this->clientKYCDocsModel - ->where('client_id', $data['client_id']) - ->where('vehicle_id', $data['vehicle_id']) + ->where('client_id', $sanitized_post_data['client_id']) + ->where('vehicle_id', $sanitized_post_data['vehicle_id']) ->findAll(); return $this->respond(['status' => true, 'code' => 200, 'vehicle_docs' => $vehicleDocs, 'inserted_docs' => $insertedDocs, 'message' => 'File uploaded successfully'], 200); } else { @@ -5192,12 +5534,72 @@ class ClientController extends AdminController public function createVehicleWithMinimalData() { + $rules = [ + 'Owner_type' => [ + 'rules' => 'required|in_list[1,2]', + 'errors' => [ + 'required' => 'Owner type is required', + 'in_list' => 'Invalid owner type selected' + ] + ], + 'vehicle_no' => [ + 'rules' => 'required|regex_match[/^[A-Z]{2}[0-9]{2}[A-Z]{1,2}[0-9]{4}$/]', + 'errors' => [ + 'required' => 'Vehicle number is required', + 'regex_match' => 'Invalid Vehicle Number. Example: TN22AB1234' + ] + ], + 'rc' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'RC Book number is required' + ] + ], + + 'type' => [ + 'rules' => 'required|is_natural_no_zero', + 'errors' => [ + 'required' => 'Vehicle type is required' + ] + ], + + 'description' => [ + 'rules' => 'required|is_natural_no_zero', + 'errors' => [ + 'required' => 'Vehicle description is required' + ] + ], + 'owner' => [ + 'rules' => 'required|is_natural_no_zero', + 'errors' => [ + 'required' => 'Owner is required' + ] + ], + + 'old_onwer' => [ + 'rules' => 'permit_empty|alpha_space', + 'errors' => [ + 'alpha_space' => 'Old owner name can contain only letters and spaces' + ] + ], + + ]; + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } $data = $this->request->getPost(); - $id = $this->request->getPost('vehicle_primary_key'); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + $id = $sanitized_post_data['vehicle_primary_key']; + if ($id) { - $vehicle_update = $this->vehicleModel->where('id', $id)->set($data)->update(); + $vehicle_update = $this->vehicleModel->where('id', $id)->set($sanitized_post_data)->update(); if ($vehicle_update) { return $this->respond(['status' => true, 'message' => 'Vehicle details updated successfully'], 200); @@ -5206,7 +5608,7 @@ class ClientController extends AdminController } } else { - $vehicle_insert = $this->vehicleModel->insert($data); + $vehicle_insert = $this->vehicleModel->insert($sanitized_post_data); if ($vehicle_insert) { @@ -5219,9 +5621,9 @@ class ClientController extends AdminController return $this->respond([ 'status' => true, 'vehicle_id' => $vehicle_insert, - 'owner_id' => $data['owner'], - 'owner_branch_id' => $data['branch_id'] ?? null, - 'owner_type' => $data['Owner_type'], + 'owner_id' => $sanitized_post_data['owner'], + 'owner_branch_id' => $sanitized_post_data['branch_id'] ?? null, + 'owner_type' => $sanitized_post_data['Owner_type'], 'vehicles' => $vehicles, 'message' => 'Vehicle created successfully ' diff --git a/app/Controllers/EmployeeController.php b/app/Controllers/EmployeeController.php index 1f996e53..41eef6df 100755 --- a/app/Controllers/EmployeeController.php +++ b/app/Controllers/EmployeeController.php @@ -2676,12 +2676,73 @@ class EmployeeController extends AdminController //UPDATE EMPLOYEE public function update_emp_data() { - $data = $this->request->getPost(); + + $rules = [ + 'emp_code' => [ + 'rules' => 'required', + 'errors' => [ + 'required' => 'Employee Code is missing' + ] + ], + + 'name' => [ + 'rules' => 'required|min_length[2]|max_length[100]', + 'errors' => [ + 'required' => 'Employee name is required', + 'min_length' => 'Name must be at least 2 characters', + 'max_length' => 'Name cannot exceed 100 characters' + ] + ], + 'gender' => [ + 'rules' => 'permit_empty|in_list[M,F]', + 'errors' => [ + 'in_list' => 'Invalid gender selected' + ] + ], + 'email_corporate' => [ + 'rules' => 'required|valid_email', + 'errors' => [ + 'required' => 'Email is required', + 'valid_email' => 'Enter a valid email address' + ] + ], + + 'mobile' => [ + 'rules' => 'required|numeric|exact_length[10]', + 'errors' => [ + 'required' => 'Mobile number is required', + 'numeric' => 'Mobile number must contain digits only', + 'exact_length' => 'Mobile number must be exactly 10 digits' + ] + ], + ]; + $request_post_data = $this->request->getPost(); + $data = sanitizeInputArrayAdvanced($request_post_data); + if (isset($data['relationship'])) { + $rules['relationship'] = [ + 'rules' => 'required|in_list[Self,Spouse,Child,Father,Mother,Father-in-law,Mother-in-law]', + 'errors' => [ + 'required' => 'Relationship is required', + 'in_list' => 'The selected relationship is invalid.' + ] + ]; + } + + + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } + + + // print_rr($data);die(); // $data['dob'] = date('Y-m-d', strtotime($data['dob'])); - if(isset( $data['dob'])){ - $data['dob'] = change_date_format($data['dob'], null, 'Y-m-d'); - } + $data['dob'] = (!empty($data['dob'])) ? change_date_format($data['dob'], null, 'Y-m-d') : null; // print_rr($data); die; // Fetch current employee data @@ -2971,12 +3032,15 @@ class EmployeeController extends AdminController } public function mapEmployees(){ - $client_id = $this->request->getPost('client_id'); - $branch_id = $this->request->getPost('branch_id'); - $policy_id = $this->request->getPost('client_policy_id'); - $selected_employees = (array)$this->request->getPost('selected'); - $si_amt = $this->request->getPost('si_amt'); - $policy_start_date_unformatted = $this->request->getPost('policy_start_date'); + $request_post_data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($request_post_data); + + $client_id = $sanitized_post_data['client_id']; + $branch_id = $sanitized_post_data['branch_id']; + $policy_id = $sanitized_post_data['client_policy_id']; + $selected_employees = (array)$sanitized_post_data['selected']; + $si_amt = $sanitized_post_data['si_amt']; + $policy_start_date_unformatted = $sanitized_post_data['policy_start_date']; $policy_start_date = change_date_format($policy_start_date_unformatted, 'd/M/Y', 'Y-m-d'); @@ -3013,7 +3077,9 @@ class EmployeeController extends AdminController } public function unmapEmployees($actionType){ - $selected_employees = (array)$this->request->getPost('selected'); + $request_post_data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($request_post_data); + $selected_employees = (array)$sanitized_post_data['selected']; if($actionType == 0){ for($i = 0;$iemployeeModel->set(['client_id' => null, 'client_branch_id' => null])->where('id',$selected_employees[$i])->update();log_message('error',$result1); @@ -3273,7 +3339,31 @@ class EmployeeController extends AdminController public function retailendorsementsave() { try { - $data = $this->request->getPost(); + $rules = [ + 'endorsement_no' => [ + 'rules' => 'required', + 'errors' => [ + 'required' => 'Endorsement Number is missing' + ] + ], + 'status' => [ + 'rules' => 'required', + 'errors' => [ + 'required' => 'Status is required', + ] + ] + ]; + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } + $request_post_data = $this->request->getPost(); + $data = sanitizeInputArrayAdvanced($request_post_data); + if (!empty($data['id'])) { $text = "update"; $updateID = $data['id']; diff --git a/app/Controllers/FhplApiController.php b/app/Controllers/FhplApiController.php index 33037652..9497433c 100644 --- a/app/Controllers/FhplApiController.php +++ b/app/Controllers/FhplApiController.php @@ -27,13 +27,13 @@ class FhplApiController extends BaseController public function generateAuthToken() { - $url = env('FHPL_TOKEN_URL'); // example: https://uat.fhpl.net/token + $url = env('FHPL_TOKEN_URL'); // x-www-form-urlencoded body $postData = http_build_query([ - 'UserName' => 'TestApi@fhpl', - 'Password' => 'Fhpl@12345', - 'grant_type' => 'password', + 'UserName' => env('FHPL_USER_NAME'), + 'Password' => env('FHPL_PASSWORD'), + 'grant_type' => env('FHPL_GRANT_TYPE'), ]); $ch = curl_init(); @@ -65,9 +65,447 @@ class FhplApiController extends BaseController return $this->response->setJSON([ 'status' => $httpCode === 200, 'http_code' => $httpCode, - 'response' => json_decode($response, true), + 'data' => json_decode($response, true), ]); } + public function SubmitClaim($claimId = 515) + { + helper('api'); + + $data = $this->db->table('ticket_master tm') + ->select(' + tm.id, + tm.emp_mobile as mobileNo, + tm.emp_mail as emailId, + tm.doa as admissionDate, + tm.dod as dischargeDate, + tm.hospital_name as hospitalName, + tm.claim_amount as requestedAmount, + tm.tpa_no as dependentUniqueId, + cp.policy_no as policyNo, + e.emp_code as memberId, + tn.note as disease, + cf.url as filePath + ') + ->join('employees e', 'e.id = tm.emp_id', 'left') + ->join('client_policy cp', 'tm.client_policy_id = cp.id', 'left') + ->join('ticket_notes tn', 'tn.ticket_id = tm.id', 'left') + ->join('claim_files cf', "cf.ticket_id = tm.id AND cf.file_type = 2 AND cf.mime_type='application/pdf'", 'left') + ->where('tm.id', $claimId) + ->get() + ->getRowArray(); + + + if (count($data) && $data['filePath'] == null) { + log_message('error', "TPA CLAIM PUSH FAILED FHPL | claimId: '.$claimId.' - Claim or File Missing"); + return $this->response->setJSON(['status' => false,'message' => 'Claim or File Missing', ]); + } + + // Build absolute file path + $filename = basename($data['filePath']); + $pdfPath = WRITEPATH . 'uploads/claim_files/' . $filename; + + if (!file_exists($pdfPath)) { + log_message('error', "TPA CLAIM PUSH FAILED FHPL | claimId: '.$claimId.' - PDF not found on server"); + return $this->response->setJSON(['status' => false,'message' => 'PDF not found on server']); + } + + // Convert PDF to Base64 + $fileContent = base64_encode(file_get_contents($pdfPath)); + + // Generate FHPL Token + $tokenResponse = json_decode($this->generateAuthToken()->getBody(), true); + if (empty($tokenResponse['data']['access_token'])) { + return $this->response->setJSON(['status' => false,'message' => 'FHPL Token generation failed']); + } + $token = $tokenResponse['data']['access_token']; + + // Build FHPL Request + $body = [ + "IssueID" => $data['dependentUniqueId'], // this key added after seeing the error in responce have to click with fhpl team + "Userid" => getenv('FHPL_USER_NAME'), + "PolicyNo" => "111700-TATAMTORS", // $data['policyNo'], + "UhidNo" => "OIC40830846", //$data['dependentUniqueId'], + "ClaimID" => (string) $data['id'], + "DOA" => "2025-10-11",//date('Y-m-d', strtotime($data['admissionDate'])), + "DateofDischarge"=> $data['dischargeDate'] ? date('Y-m-d', strtotime($data['dischargeDate'])) : null, + "ClaimedAmount" => (float) $data['requestedAmount'], + "DocumentType" => 20, // Fresh Claim + "PayeeName" => $data['memberId'], + "HospitalName" => $data['hospitalName'], + "MobileNo" => $data['mobileNo'], + "Documents" => [ + [ + "documentName" => $filename, + "documentCategory" => "IRR", + "filecontent" => $fileContent + ] + ] + ]; + + $url = getenv('FHPL_BASE_URL') . "/api/ClaimSubmission"; + + $headers = [ + "Authorization: Bearer " . $token, + "Content-Type: application/json" + ]; + + log_message('error', 'TPA CLAIM PUSH FHPL | claimId: '.$claimId.' | payload: '.json_encode($body)); + + $response = call_third_party_api($url, 'POST', $headers, $body); + + log_message('error', 'FHPL RESPONSE | ' . json_encode($response)); + + if($response['status'] != true){ + log_message('error', 'TPA CLAIM PUSH FAILED FHPL | claimId: '.$claimId.' | response: '.json_encode($response)); + $this->db->table('ticket_master') + ->where('id',$claimId) + ->update([ 'tpa_push_response' => json_encode($response) ]); + return; + } + + + if ($response['status'] === true && !empty($response['data'][0]['ClaimsInfo'])) + { + $claimsInfo = json_decode($response['data'][0]['ClaimsInfo'], true); + + if (!empty($claimsInfo[0]['ClaimID'])) { + + $fhplClaimNo = $claimsInfo[0]['ClaimID']; + + $this->db->table('ticket_master') + ->where('id', $claimId) + ->update([ + 'claim_number' => $fhplClaimNo, + 'tpa_claim_id' => $fhplClaimNo, + 'tpa_claim_push_reference_no' => $fhplClaimNo, + 'updated_at' => date('Y-m-d H:i:s') + ]); + + log_message('error', 'TPA CLAIM PUSH SUCCESS FHPL | claimId: '.$claimId.' | claimNO: '.$fhplClaimNo); + + } + } + + + return $this->response->setJSON($response); + } + + public function ClaimDetail($claimId = 515) + { + helper('api'); + + $ticket = $this->db->table('ticket_master tm') + ->select("tm.id, tm.tpa_claim_id as claimNo, cp.policy_no , cp.policy_start_date , cp.policy_end_date") + ->join('client_policy cp','tm.client_policy_id=cp.id') + ->where('tm.id',$claimId) + ->get()->getRowArray(); + + + if(!$ticket) return $this->response->setJSON(['status'=>false,'message'=>'Invalid claim']); + + // Generate FHPL Token + $tokenResponse = json_decode($this->generateAuthToken()->getBody(), true); + + if (empty($tokenResponse['data']['access_token'])) { + return $this->response->setJSON(['status' => false,'message' => 'FHPL Token generation failed']); + } + + $token = $tokenResponse['data']['access_token']; + + $url = getenv('FHPL_BASE_URL')."/api/GetTPA_ClaimsDetails"; + + $body = [ + "UserName" => getenv('FHPL_USER_NAME'), + "Password" => getenv('FHPL_PASSWORD'), + "PolicyNumber" => "GHI-81-25-00087313-000",//$ticket['policy_no'], + "Fromdate" => "2025-04-26",//$ticket['claimNo'], + "Todate" => "2025-04-27",//$ticket['claimNo'], + ]; + + $headers = ["Authorization: Bearer ".$token,"Content-Type: application/json"]; + + $response = call_third_party_api($url,'POST',$headers,$body); + + // dd($response); + + if (empty($response['data'][0])) { + log_message('error', 'CLAIM STATUS FAILED | for ticket ID: ' . $claimId.' | response: '.json_encode($response)); + + return $this->response->setJSON([ + 'status' => false, + 'message' => 'API call failed.', + 'data' => $response + ]); + } + + + $status = null; + + // find this claim + foreach($response['data'] as $row){ + if($row['CLAIM_ID']==$ticket['claimNo']){ + $status = $row['CLAIM_STATUS']; + } + } + + $map = [ + "In-Progress" => 5, + "Under Process" => 5, + "Query" => 4, + "Paid" => 11, + "Rejected" => 8, + "Approved" => 8, + "Required Information" => 4, + ]; + + if( $status != null && isset($map[$status])) + { + $this->db->table('ticket_master')->where('id',$claimId)->update(['claim_status_id'=>$map[$status],'tpa_claim_status'=>$status]); + // LOG UPDATE + log_message('error', "CLAIM STATUS SUCCESS | Updated ticket ID $claimId with claim status: $status"); + } + + + + return $this->response->setJSON([ + 'status' => true, + 'message' => 'Claim status updated.', + 'updated_status' => $status, + 'api_response' => $response + ]); + + } + + public function ClaimStatusUpdate() + { + helper('api'); + + $tickets = $this->db->table('ticket_master tm') + ->select("tm.id,tm.tpa_claim_id,cp.policy_no") + ->join('client_policy cp','tm.client_policy_id=cp.id') + ->where('tm.tpa_claim_id IS NOT NULL') + ->get()->getResultArray(); + + $count=0; + + foreach($tickets as $t){ + $this->ClaimDetail($t['id']); + $count++; + } + + return $this->response->setJSON(['status'=>true,'updated'=>$count]); + } + + public function EcardRequest($employeeId,$policyNo,$uhid) + { + helper('api'); + + // Generate FHPL Token + $tokenResponse = json_decode($this->generateAuthToken()->getBody(), true); + + if (empty($tokenResponse['data']['access_token'])) { + return $this->response->setJSON(['status' => false,'message' => 'FHPL Token generation failed']); + } + + // Generate FHPL Token + $tokenResponse = json_decode($this->generateAuthToken()->getBody(), true); + + if (empty($tokenResponse['data']['access_token'])) { + return $this->response->setJSON(['status' => false,'message' => 'FHPL Token generation failed']); + } + + $token = $tokenResponse['data']['access_token']; + + $url = getenv('FHPL_BASE_URL')."/api/GetEcard"; + + $body = [ + "UserName" => getenv('FHPL_USER_NAME'), + "Password" => getenv('FHPL_PASSWORD'), + "PolicyNumber" => $policyNo, + "EmployeeID" => $employeeId + ]; + + $headers = ["Authorization: Bearer ".$token,"Content-Type: application/json"]; + + $response = call_third_party_api($url,'POST',$headers,$body); + + if(($response['data']['STATUS'] ?? '')=='SUCCESS'){ + return $response['data']['E_Card']; + } + + return null; + } + + public function FhplGetBenefDetails($requestData = null) + { + helper('api'); + + $policyNo = $requestData['policy_no'] ?? "10/12/2025/16/17"; + $client_policy_id = $requestData['client_policy_id'] ?? 0; + + // Generate FHPL Token + $tokenResponse = json_decode($this->generateAuthToken()->getBody(), true); + if (empty($tokenResponse['data']['access_token'])) { + return $this->response->setJSON(['status' => false,'message' => 'FHPL Token generation failed']); + } + $token = $tokenResponse['data']['access_token']; + + $url = getenv('FHPL_BASE_URL')."/api/GetEnrollmentDetailsPolicy"; + + $headers = [ + "Authorization: Bearer ".$token, + "Content-Type: application/json" + ]; + + $startIndex = 0; + $range = 100; + $allMembers = []; + + do { + $body = [ + "UserName" => getenv('FHPL_USER_NAME'), + "Password" => getenv('FHPL_PASSWORD'), + "PolicyNumber" => $policyNo, + "StartIndex" => $startIndex, + "Range" => $range + ]; + + $response = call_third_party_api($url,'POST',$headers,$body); + + dd($response); + + if(empty($response['data']['Members'])){ + break; + } + + $allMembers = array_merge($allMembers,$response['data']['Members']); + + $startIndex += $range; + + } while($startIndex < ($response['data']['Total'] ?? 0)); + + + dd($allMembers); + + // Now same matching logic you already have + $employeePolicyModel = new EmployeePolicyModel(); + + $employeePolicyData = $employeePolicyModel + ->join('employees','employees.id=employee_polices.employee_id') + ->where('employee_polices.client_policy_id',$client_policy_id) + ->where('employee_polices.tpa_id IS NULL') + ->findAll(); + + $updated = 0; + + foreach($employeePolicyData as $policy){ + foreach($allMembers as $m){ + + if( + strtolower(trim($policy['name']))==strtolower(trim($m['Name'])) && + $policy['emp_code']==$m['MemberID'] && + strtolower($policy['relationship'])==strtolower($m['Relation']) + ){ + $this->db->table('employee_polices') + ->where('id',$policy['emp_policy_id']) + ->update(['tpa_id'=>$m['UHID']]); + + $updated++; + } + } + } + + return [ + 'status'=>true, + 'total_fetched'=>count($allMembers), + 'updated'=>$updated + ]; + } + + public function syncFhplClaimsToNhance() + { + helper('api'); + + // Generate FHPL Token + $tokenResponse = json_decode($this->generateAuthToken()->getBody(), true); + + if (empty($tokenResponse['data']['access_token'])) { + return $this->response->setJSON(['status' => false,'message' => 'FHPL Token generation failed']); + } + + $token = $tokenResponse['data']['access_token']; + + $url = getenv('FHPL_BASE_URL')."/api/GetTPA_ClaimsDetails"; + + $headers = [ + "Authorization: Bearer ".$token, + "Content-Type: application/json" + ]; + + $policies = $this->db->table('client_policy') + ->where('tpa_id',$this->fhplTpaId) + ->get()->getResultArray(); + + $finalResult=[]; + + foreach($policies as $policy){ + + $body = [ + "UserName" => getenv('FHPL_USER_NAME'), + "Password" => getenv('FHPL_PASSWORD'), + "PolicyNumber" => $policy['policy_no'], + "Fromdate" => $policy['policy_start_date'], + "Todate" => $policy['policy_end_date'] + ]; + + $response = call_third_party_api($url,'POST',$headers,$body); + + if(!empty($response['data'])){ + $finalResult = array_merge($finalResult,$response['data']); + } + } + + // Insert / update ticket_master same way you already do for MediAssist + foreach($finalResult as $row){ + + $status = $row['CLAIM_STATUS']; + + $map = [ + "Under Process"=>5, + "Paid"=>11, + "Rejected"=>8, + "Approved"=>8 + ]; + + $claimStatus = $map[$status] ?? 1; + + $this->db->table('ticket_master')->insert([ + 'policy_no'=>$row['POLICY_NO'], + 'claim_number'=>$row['CLAIM_ID'], + 'tpa_claim_id'=>$row['CLAIM_ID'], + 'emp_code'=>$row['EMPLOYEE_NO'], + 'insured_name'=>$row['PATIENT_NAME'], + 'claim_amount'=>$row['CLAIM_AMOUNT'], + 'hospital_name'=>$row['HOSPITAL_NAME'], + 'doa'=>$row['DATE_OF_ADMISSION'], + 'dod'=>$row['DATE_OF_DISCHARGE'], + 'claim_status_id'=>$claimStatus, + 'tpa_id'=>$this->fhplTpaId + ]); + } + + return ['status'=>true,'total'=>count($finalResult)]; + } + + + + + + + + + } diff --git a/app/Controllers/LeadsController.php b/app/Controllers/LeadsController.php index 22300690..8154fc82 100644 --- a/app/Controllers/LeadsController.php +++ b/app/Controllers/LeadsController.php @@ -378,7 +378,95 @@ class LeadsController extends BaseController private function prepareLeadData() { - $data = $this->request->getPost(); + $rules = [ + 'lead_type' => [ + 'rules' => 'required', + 'errors' => ['required' => 'Lead Type is required'] + ], + 'issuer' => [ + 'rules' => 'required', + 'errors' => ['required' => 'Issuer is required'] + ], + 'entity_type_id' => [ + 'rules' => 'required', + 'errors' => ['required' => 'Entity Type is required'] + ], + 'client_name' => [ + 'rules' => 'required', + 'errors' => ['required' => 'Client Name is required'] + ], + 'client_short_name' => [ + 'rules' => 'required', + 'errors' => ['required' => 'Client Short Name is required'] + ], + 'gst' => [ + 'rules' => 'required', + 'errors' => ['required' => 'GST Number is required'] + ], + 'branch_name' => [ + 'rules' => 'required', + 'errors' => ['required' => 'Branch Name is required'] + ], + 'branch_code' => [ + 'rules' => 'required', + 'errors' => ['required' => 'Branch Code is required'] + ], + 'contact_person_name' => [ + 'rules' => 'required', + 'errors' => ['required' => 'Contact Person Name is required'] + ], + 'contact_person_mobile' => [ + 'rules' => 'required', + 'errors' => ['required' => 'Contact Person Mobile is required'] + ], + 'contact_person_email' => [ + 'rules' => 'required|valid_email', + 'errors' => [ + 'required' => 'Contact Person Email is required', + 'valid_email' => 'Please enter a valid email address' + ] + ], + 'salse_person_id' => [ + 'rules' => 'required', + 'errors' => ['required' => 'Sales Person is required'] + ], + 'status' => [ + 'rules' => 'required', + 'errors' => ['required' => 'Status is required'] + ] + ]; + $request_data = $this->request->getPost(); + $data = sanitizeInputArrayAdvanced($request_data); + if($data['lead_form_type'] == 2){ + $rules['client_type'] = [ + 'rules' => 'required', + 'errors' => ['required' => 'Client Type is required'] + ]; + $rules['policy_type_id'] = [ + 'rules' => 'required', + 'errors' => ['required' => 'Policy Type is required'] + ]; + $rules['policy_start_date'] = [ + 'rules' => 'required', + 'errors' => ['required' => 'Date of Commencement is required'] + ]; + $rules['policy_end_date'] = [ + 'rules' => 'required', + 'errors' => ['required' => 'Date of Expiry is required'] + ]; + } + + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } + + + $data['client_type'] = 1; $data['pan'] = ""; @@ -5739,7 +5827,7 @@ class LeadsController extends BaseController $first_file_name = $isFirstField ? 'Member List' : ''; $member_data_link = $isFirstField ? $sample_dwn_link : ''; $read_only = $isFirstField ? 'readonly' : ''; - $accept = $isFirstField ? '.xls,.xlsx' : ''; + $accept = $isFirstField ? '.xls,.xlsx' : '.xls,.xlsx,.pdf,.jpg,.jpeg,.png'; $displayIndex = $index + 1; $html .= ' diff --git a/app/Controllers/LoginController.php b/app/Controllers/LoginController.php index 779c788b..fb073f21 100755 --- a/app/Controllers/LoginController.php +++ b/app/Controllers/LoginController.php @@ -62,9 +62,7 @@ class LoginController extends BaseController set_session_data($session_data); // Bind session to device - set_session_data(['fingerprint' => hash('sha256', - ($this->request->getUserAgent()->getAgentString() . '|' . ($this->request->getIPAddress() - )))]); + set_session_data(['fingerprint' => generateFingerprint()]); log_message('error', 'Set The UserId : `'. $user->id .'` in Session'); log_message('error', 'User Login Sucessfully'); diff --git a/app/Controllers/MasterController.php b/app/Controllers/MasterController.php index 475c8a97..be71e82c 100755 --- a/app/Controllers/MasterController.php +++ b/app/Controllers/MasterController.php @@ -283,26 +283,53 @@ class MasterController extends AdminController { $this->myLogger->logme('error','Insurer general info function called'); + $rules = [ + 'name' => [ + 'rules' => 'required', + 'errors' => [ + 'required' => 'Name is required' + ] + ], + 'short_name' => [ + 'rules' => 'required|min_length[3]|max_length[8]', + 'errors' => [ + 'required' => 'Short name is required', + 'min_length' => 'Short name must be at least 3 characters', + 'max_length' => 'Short name cannot exceed 8 characters' + ] + ], + 'insurer_logo' => [ + 'rules' => 'if_exist|is_image[insurer_logo]|max_size[insurer_logo,200]|ext_in[insurer_logo,jpg,jpeg,png]', + 'errors' => [ + 'is_image' => 'The uploaded file must be an image', + 'max_size' => 'File size should not exceed 200 KB', + 'ext_in' => 'Allowed file types: jpg, jpeg, png', + ] + ], + ]; + + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } + $uploadFilePath = ROOTPATH . 'public/uploads/logo/'; $file_name = file_Upload($this->request->getFile('insurer_logo'), $uploadFilePath); $data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); - if($this->request->getPost('addition_add_day')){ - $data['addition_add_day'] = 1; - } - - if($this->request->getPost('deletion_add_day')){ - $data['deletion_add_day'] = 1; - } - - if($this->request->getPost('is_multi_event')){ - $data['is_multi_event'] = 1; - } - - $data['created_by'] = get_session_userid(); - $data['insurer_logo'] = $file_name; + $insert_data['addition_add_day'] = (!empty($sanitized_post_data['addition_add_day'])) ? 1 : 0; + $insert_data['deletion_add_day'] = (!empty($sanitized_post_data['deletion_add_day'])) ? 1 : 0; + $insert_data['is_multi_event'] = (!empty($sanitized_post_data['is_multi_event'])) ? 1 : 0; + $insert_data['created_by'] = get_session_userid(); + $insert_data['insurer_logo'] = $file_name; - $insert = $this->insurerModel->insert($data); + $insert = $this->insurerModel->insert($insert_data); + if($insert){ $insurer_data = $this->insurerModel->where(['id' => $insert, 'is_active' => 1])->first(); $insurer_templete_count = $this->insurerTemplateModel->where(['insurer_id' => $insert, 'is_active' => 1])->countAllResults(); @@ -316,28 +343,129 @@ class MasterController extends AdminController { $this->myLogger->logme('error','Client branch CREATE function called'); + $rules = [ + + // ====================== + // Branch Details + // ====================== + 'branch_name' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'Branch name is required' + ] + ], + + 'branch_code' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'Branch code is required' + ] + ], + + 'address1' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'Address Line 1 is required' + ] + ], + + 'state' => [ + 'rules' => 'required|is_natural_no_zero', + 'errors' => [ + 'required' => 'State is required' + ] + ], + + 'district' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'District is required' + ] + ], + + 'city' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'City is required' + ] + ], + + 'pincode' => [ + 'rules' => 'required|numeric|exact_length[6]', + 'errors' => [ + 'required' => 'Pincode is required', + 'numeric' => 'Pincode must contain only numbers', + 'exact_length' => 'Pincode must be exactly 6 digits' + ] + ], + + // ====================== + // Contact Details (Array) + // ====================== + 'name.*' => [ + 'rules' => 'required|trim|min_length[2]', + 'errors' => [ + 'required' => 'Contact name is required', + 'min_length' => 'Contact name must be at least 2 characters' + ] + ], + + 'designation.*' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'Designation is required' + ] + ], + + 'email.*' => [ + 'rules' => 'required|valid_email', + 'errors' => [ + 'required' => 'Email is required', + 'valid_email' => 'Invalid email format' + ] + ], + + 'mobile.*' => [ + 'rules' => 'required|numeric|exact_length[10]', + 'errors' => [ + 'required' => 'Mobile number is required', + 'numeric' => 'Mobile must contain only digits', + 'exact_length' => 'Mobile number must be exactly 10 digits' + ] + ], + ]; + + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } $data = $this->request->getPost(); - $data['created_by'] = get_session_userid(); - $insert = $this->insurerBranchModel->insert($data); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + $sanitized_post_data['created_by'] = get_session_userid(); + $insert = $this->insurerBranchModel->insert($sanitized_post_data); if($insert){ - for ($i = 0; $i < count($this->request->getPost('name')); $i++) { + for ($i = 0; $i < count($sanitized_post_data('name')); $i++) { // Prepare data to insert - $data = [ + $sanitized_post_data_for_level = [ 'contact_type' => 'insurer', 'ref_id' => $insert, 'created_by' => get_session_userid(), - 'name' => $this->request->getPost('name')[$i], - 'email' => $this->request->getPost('email')[$i], - 'mobile' => $this->request->getPost('mobile')[$i], - 'designation' => $this->request->getPost('designation')[$i] + 'name' => $sanitized_post_data['name'][$i], + 'email' => $sanitized_post_data['email'][$i], + 'mobile' => $sanitized_post_data['mobile'][$i], + 'designation' => $sanitized_post_data['designation'][$i] ]; - $contacts = $this->levelContactModel->insert($data); + $contacts = $this->levelContactModel->insert($sanitized_post_data_for_level); } } if($insert){ - $branchData = $this->insurerBranchModel->where('insurer_id', $this->request->getPost('insurer_id'))->findAll(); + $branchData = $this->insurerBranchModel->where('insurer_id', $sanitized_post_data_for_level['insurer_id'])->findAll(); echo json_encode(array("status" => true , 'data' => $branchData)); }else{ echo json_encode(array("status" => false)); @@ -367,38 +495,59 @@ class MasterController extends AdminController public function editInsurerGeneralInfo() { - $this->myLogger->logme('error','edit Insurer general info function called'); + + $this->myLogger->logme('error','Edit Insurer general info function called'); + $rules = [ + 'name' => [ + 'rules' => 'required', + 'errors' => [ + 'required' => 'Name is required' + ] + ], + 'short_name' => [ + 'rules' => 'required|min_length[3]|max_length[8]', + 'errors' => [ + 'required' => 'Short name is required', + 'min_length' => 'Short name must be at least 3 characters', + 'max_length' => 'Short name cannot exceed 8 characters' + ] + ], + 'insurer_logo' => [ + 'rules' => 'if_exist|is_image[insurer_logo]|max_size[insurer_logo,200]|ext_in[insurer_logo,jpg,jpeg,png]', + 'errors' => [ + 'is_image' => 'The uploaded file must be an image', + 'max_size' => 'File size should not exceed 200 KB', + 'ext_in' => 'Allowed file types: jpg, jpeg, png', + ] + ], + ]; + + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } $uploadFilePath = ROOTPATH . 'public/uploads/logo/'; - $file_name = file_Upload($this->request->getFile('insurer_logo'), $uploadFilePath); - - $id = $this->request->getPost('PrimaryKey'); - $data = $this->request->getPost(); - $data['updated_by'] = get_session_userid(); - + $file_name = file_Upload($this->request->getFile('insurer_logo'), $uploadFilePath); + $data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + $id = $sanitized_post_data['PrimaryKey']; + + $update_data['addition_add_day'] = (!empty($sanitized_post_data['addition_add_day'])) ? 1 : 0; + $update_data['deletion_add_day'] = (!empty($sanitized_post_data['deletion_add_day'])) ? 1 : 0; + $update_data['is_multi_event'] = (!empty($sanitized_post_data['is_multi_event'])) ? 1 : 0; + $update_data['updated_by'] = get_session_userid(); + if(!empty($file_name)){ - $data['insurer_logo'] = $file_name; + $update_data['insurer_logo'] = $file_name; } - if($this->request->getPost('addition_add_day')){ - $data['addition_add_day'] = 1; - }else{ - $data['addition_add_day'] = 0; - } + $update = $this->insurerModel->update($id,$update_data); - if($this->request->getPost('deletion_add_day')){ - $data['deletion_add_day'] = 1; - }else{ - $data['deletion_add_day'] = 0; - } - - if($this->request->getPost('is_multi_event')){ - $data['is_multi_event'] = 1; - }else{ - $data['is_multi_event'] = 0; - } - - $update = $this->insurerModel->update($id,$data); if($update){ echo json_encode(array("status" => true , 'data' => $data)); }else{ @@ -422,33 +571,133 @@ class MasterController extends AdminController public function editInsurerBranch() { - $this->myLogger->logme('error','Insurer branch CREATE function called'); - $id = $this->request->getPost('PrimaryKey'); - $data = $this->request->getPost(); - $update = $this->insurerBranchModel->update($id, $data); + $this->myLogger->logme('error','Insurer branch EDIT function called'); + $rules = [ + + // ====================== + // Branch Details + // ====================== + 'branch_name' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'Branch name is required' + ] + ], + + 'branch_code' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'Branch code is required' + ] + ], + + 'address1' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'Address Line 1 is required' + ] + ], + + 'state' => [ + 'rules' => 'required|is_natural_no_zero', + 'errors' => [ + 'required' => 'State is required' + ] + ], + + 'district' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'District is required' + ] + ], + + 'city' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'City is required' + ] + ], + + 'pincode' => [ + 'rules' => 'required|numeric|exact_length[6]', + 'errors' => [ + 'required' => 'Pincode is required', + 'numeric' => 'Pincode must contain only numbers', + 'exact_length' => 'Pincode must be exactly 6 digits' + ] + ], + + // ====================== + // Contact Details (Array) + // ====================== + 'name.*' => [ + 'rules' => 'required|trim|min_length[2]', + 'errors' => [ + 'required' => 'Contact name is required', + 'min_length' => 'Contact name must be at least 2 characters' + ] + ], + + 'designation.*' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'Designation is required' + ] + ], + + 'email.*' => [ + 'rules' => 'required|valid_email', + 'errors' => [ + 'required' => 'Email is required', + 'valid_email' => 'Invalid email format' + ] + ], + + 'mobile.*' => [ + 'rules' => 'required|numeric|exact_length[10]', + 'errors' => [ + 'required' => 'Mobile number is required', + 'numeric' => 'Mobile must contain only digits', + 'exact_length' => 'Mobile number must be exactly 10 digits' + ] + ], + ]; + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } + $data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + $id = $sanitized_post_data['PrimaryKey']; + $update = $this->insurerBranchModel->update($id, $sanitized_post_data); if($update){ $contactsToDelete = $this->levelContactModel->where(['ref_id' => $id,'contact_type' => 'insurer', 'is_active' => 1])->get()->getResult(); foreach ($contactsToDelete as $contact) { $this->levelContactModel->delete($contact->id); } - for ($i = 0; $i < count($this->request->getPost('name')); $i++) { + for ($i = 0; $i < count($sanitized_post_data['name']); $i++) { // Prepare data to update - $data = [ + $sanitized_post_data_for_level = [ 'contact_type' => 'insurer', 'ref_id' => $id, 'created_by' => get_session_userid(), - 'name' => $this->request->getPost('name')[$i], - 'email' => $this->request->getPost('email')[$i], - 'mobile' => $this->request->getPost('mobile')[$i], - 'designation' => $this->request->getPost('designation')[$i] + 'name' => $sanitized_post_data['name'][$i], + 'email' => $sanitized_post_data['email'][$i], + 'mobile' => $sanitized_post_data['mobile'][$i], + 'designation' => $sanitized_post_data['designation'][$i] ]; - $contacts = $this->levelContactModel->insert($data); + $contacts = $this->levelContactModel->insert($sanitized_post_data_for_level); } } if($update){ - $branchData = $this->insurerBranchModel->where('insurer_id', $this->request->getPost('insurer_id'))->findAll(); + $branchData = $this->insurerBranchModel->where('insurer_id', $sanitized_post_data['insurer_id'])->findAll(); echo json_encode(array("status" => true , 'data' => $branchData, 'edit')); }else{ echo json_encode(array("status" => false, 'edit')); @@ -594,6 +843,74 @@ class MasterController extends AdminController { $this->myLogger->logme('error','TPA general info function called'); + $rules = [ + + // ====================== + // TPA Basic Details + // ====================== + 'name' => [ + 'rules' => 'required|trim|min_length[2]', + 'errors' => [ + 'required' => 'TPA name is required', + 'min_length' => 'TPA name must be at least 2 characters' + ] + ], + + 'short_name' => [ + 'rules' => 'required|trim|min_length[3]', + 'errors' => [ + 'required' => 'TPA short name is required', + 'min_length' => 'Short name must be at least 3 characters', + ] + ], + + 'network_hospitals' => [ + 'rules' => 'required|valid_url', + 'errors' => [ + 'required' => 'Network hospitals URL is required', + 'valid_url' => 'Please enter a valid URL' + ] + ], + 'tpa_logo' => [ + 'rules' => 'if_exist|is_image[tpa_logo]|max_size[tpa_logo,200]|ext_in[tpa_logo,jpg,jpeg,png]', + 'errors' => [ + 'is_image' => 'TPA logo must be an image', + 'max_size' => 'TPA logo should not exceed 200 KB', + 'ext_in' => 'Allowed logo types: jpg, jpeg, png' + ] + ], + + 'fc' => [ + 'rules' => 'if_exist|is_image[fc]|max_size[fc,500]|ext_in[fc,jpg,jpeg,png]', + 'errors' => [ + 'is_image' => 'Front card must be an image', + 'max_size' => 'Front card image should not exceed 500 KB', + 'ext_in' => 'Allowed types: jpg, jpeg, png' + ] + ], + + 'bc' => [ + 'rules' => 'if_exist|is_image[bc]|max_size[bc,500]|ext_in[bc,jpg,jpeg,png]', + 'errors' => [ + 'is_image' => 'Back card must be an image', + 'max_size' => 'Back card image should not exceed 500 KB', + 'ext_in' => 'Allowed types: jpg, jpeg, png' + ] + ], + ]; + + + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } + $data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + $uploadFilePath = ROOTPATH . 'public/uploads/logo/'; $file_name = file_Upload($this->request->getFile('tpa_logo'), $uploadFilePath); @@ -603,18 +920,18 @@ class MasterController extends AdminController $back_card_file_name = file_Upload($this->request->getFile('bc'), $template_bg_path); - $eCardTemplate = $this->request->getPost('ecard_content'); - $data = $this->request->getPost(); - $data['created_by'] = get_session_userid(); - $data['tpa_logo'] = $file_name; - $data['front_card'] = $front_card_file_name; - $data['back_card'] = $back_card_file_name; - $data['network_hospitals'] = $this->request->getPost('network_hospitals'); + $eCardTemplate = $sanitized_post_data['ecard_content']; - $insert = $this->tpaModel->insert($data); + $insert_data['created_by'] = get_session_userid(); + $insert_data['tpa_logo'] = $file_name; + $insert_data['front_card'] = $front_card_file_name; + $insert_data['back_card'] = $back_card_file_name; + $insert_data['network_hospitals'] = $sanitized_post_data['network_hospitals']; + + $insert = $this->tpaModel->insert($insert_data); - $tpa_name = (string) $this->request->getPost('name'); - $short_name = (string) $this->request->getPost('short_name'); + $tpa_name = (string) $sanitized_post_data['name']; + $short_name = (string) $sanitized_post_data['short_name']; $filename = strtolower(str_replace(' ', '_', $short_name)) . '.html'; $file_directory = WRITEPATH . 'e_card_template/'; @@ -629,10 +946,10 @@ class MasterController extends AdminController header('Content-type:text/html; charset=utf-8'); // Write the HTML content to the file - $data = file_put_contents($file_path, $eCardTemplate); + $html_data = file_put_contents($file_path, $eCardTemplate); - if ($data !== false) { + if ($html_data !== false) { $this->myLogger->logme('error', 'TPA: {tpa}, e-Card HTML template file saved successfully: {data}, filepath is: {path}', ['data' => $filename, 'tpa' => $tpa_name, 'path' => $file_path]); } else { $this->myLogger->logme('error', 'TPA: {tpa}, e-Card HTML template file unable to save: {data}', ['data' => $filename, 'tpa' => $tpa_name]); @@ -651,28 +968,129 @@ class MasterController extends AdminController { $this->myLogger->logme('error','TPA branch CREATE function called'); + $rules = [ + + // ====================== + // Branch Details + // ====================== + 'branch_name' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'Branch name is required' + ] + ], + + 'branch_code' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'Branch code is required' + ] + ], + + 'address1' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'Address Line 1 is required' + ] + ], + + 'state' => [ + 'rules' => 'required|is_natural_no_zero', + 'errors' => [ + 'required' => 'State is required' + ] + ], + + 'district' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'District is required' + ] + ], + + 'city' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'City is required' + ] + ], + + 'pincode' => [ + 'rules' => 'required|numeric|exact_length[6]', + 'errors' => [ + 'required' => 'Pincode is required', + 'numeric' => 'Pincode must contain only numbers', + 'exact_length' => 'Pincode must be exactly 6 digits' + ] + ], + + // ====================== + // Contact Details (Array) + // ====================== + 'name.*' => [ + 'rules' => 'required|trim|min_length[2]', + 'errors' => [ + 'required' => 'Contact name is required', + 'min_length' => 'Contact name must be at least 2 characters' + ] + ], + + 'designation.*' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'Designation is required' + ] + ], + + 'email.*' => [ + 'rules' => 'required|valid_email', + 'errors' => [ + 'required' => 'Email is required', + 'valid_email' => 'Invalid email format' + ] + ], + + 'mobile.*' => [ + 'rules' => 'required|numeric|exact_length[10]', + 'errors' => [ + 'required' => 'Mobile number is required', + 'numeric' => 'Mobile must contain only digits', + 'exact_length' => 'Mobile number must be exactly 10 digits' + ] + ], + ]; + + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } $data = $this->request->getPost(); - $data['created_by'] = get_session_userid(); - $insert = $this->tpaBranchModel->insert($data); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + $sanitized_post_data['created_by'] = get_session_userid(); + $insert = $this->tpaBranchModel->insert($sanitized_post_data); if($insert){ - for ($i = 0; $i < count($this->request->getPost('name')); $i++) { + for ($i = 0; $i < count($sanitized_post_data['name']); $i++) { // Prepare data to insert - $data = [ + $sanitized_post_data_for_level = [ 'contact_type' => 'tpa', 'ref_id' => $insert, 'created_by' => get_session_userid(), - 'name' => $this->request->getPost('name')[$i], - 'email' => $this->request->getPost('email')[$i], - 'mobile' => $this->request->getPost('mobile')[$i], - 'designation' => $this->request->getPost('designation')[$i] + 'name' => $sanitized_post_data['name'][$i], + 'email' => $sanitized_post_data['email'][$i], + 'mobile' => $sanitized_post_data['mobile'][$i], + 'designation' => $sanitized_post_data['designation'][$i] ]; - $contacts = $this->levelContactModel->insert($data); + $contacts = $this->levelContactModel->insert($sanitized_post_data_for_level); } } if($insert){ - $branchData = $this->tpaBranchModel->where('tpa_id', $this->request->getPost('tpa_id'))->findAll(); + $branchData = $this->tpaBranchModel->where('tpa_id', $sanitized_post_data['tpa_id'])->findAll(); echo json_encode(array("status" => true , 'data' => $branchData)); }else{ echo json_encode(array("status" => false)); @@ -715,6 +1133,74 @@ class MasterController extends AdminController public function editTPAGeneralInfo() { $this->myLogger->logme('error','edit TPA general info function called'); + $rules = [ + + // ====================== + // TPA Basic Details + // ====================== + 'name' => [ + 'rules' => 'required|trim|min_length[2]', + 'errors' => [ + 'required' => 'TPA name is required', + 'min_length' => 'TPA name must be at least 2 characters' + ] + ], + + 'short_name' => [ + 'rules' => 'required|trim|min_length[3]', + 'errors' => [ + 'required' => 'TPA short name is required', + 'min_length' => 'Short name must be at least 3 characters', + ] + ], + + 'network_hospitals' => [ + 'rules' => 'required|valid_url', + 'errors' => [ + 'required' => 'Network hospitals URL is required', + 'valid_url' => 'Please enter a valid URL' + ] + ], + 'tpa_logo' => [ + 'rules' => 'if_exist|is_image[tpa_logo]|max_size[tpa_logo,200]|ext_in[tpa_logo,jpg,jpeg,png]', + 'errors' => [ + 'is_image' => 'TPA logo must be an image', + 'max_size' => 'TPA logo should not exceed 200 KB', + 'ext_in' => 'Allowed logo types: jpg, jpeg, png' + ] + ], + + 'fc' => [ + 'rules' => 'if_exist|is_image[fc]|max_size[fc,500]|ext_in[fc,jpg,jpeg,png]', + 'errors' => [ + 'is_image' => 'Front card must be an image', + 'max_size' => 'Front card image should not exceed 500 KB', + 'ext_in' => 'Allowed types: jpg, jpeg, png' + ] + ], + + 'bc' => [ + 'rules' => 'if_exist|is_image[bc]|max_size[bc,500]|ext_in[bc,jpg,jpeg,png]', + 'errors' => [ + 'is_image' => 'Back card must be an image', + 'max_size' => 'Back card image should not exceed 500 KB', + 'ext_in' => 'Allowed types: jpg, jpeg, png' + ] + ], + ]; + + + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } + $data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + $uploadFilePath = ROOTPATH . 'public/uploads/logo/'; $file_name = file_Upload($this->request->getFile('tpa_logo'), $uploadFilePath); @@ -723,29 +1209,29 @@ class MasterController extends AdminController $front_card_file_name = file_Upload($this->request->getFile('fc'), $template_bg_path); $back_card_file_name = file_Upload($this->request->getFile('bc'), $template_bg_path); - $id = $this->request->getPost('PrimaryKey'); - $data = $this->request->getPost(); - $data['updated_by'] = get_session_userid(); + $id = $sanitized_post_data['PrimaryKey']; + + $update_data['updated_by'] = get_session_userid(); if(!empty($file_name)){ - $data['tpa_logo'] = $file_name; + $update_data['tpa_logo'] = $file_name; } if(!empty($front_card_file_name)){ - $data['front_card'] = $front_card_file_name; + $update_data['front_card'] = $front_card_file_name; } if(!empty($back_card_file_name)){ - $data['back_card'] = $back_card_file_name; + $update_data['back_card'] = $back_card_file_name; } - $data['network_hospitals'] = $this->request->getPost('network_hospitals'); - $update = $this->tpaModel->update($id,$data); + $update_data['network_hospitals'] = $sanitized_post_data['network_hospitals']; + $update = $this->tpaModel->update($id,$update_data); - $tpa_name = (string) $this->request->getPost('name'); - $short_name = (string) $this->request->getPost('short_name'); - $eCardTemplate = $this->request->getPost('ecard_content'); + $tpa_name = (string) $sanitized_post_data['name']; + $short_name = (string) $sanitized_post_data['short_name']; + $eCardTemplate = $sanitized_post_data['ecard_content']; $filename = strtolower(str_replace(' ', '_', $short_name)) . '.html'; $file_directory = WRITEPATH . 'e_card_template/'; @@ -760,10 +1246,10 @@ class MasterController extends AdminController header('Content-type:text/html; charset=utf-8'); // Write the HTML content to the file - $data = file_put_contents($file_path, $eCardTemplate); + $html_data = file_put_contents($file_path, $eCardTemplate); - if ($data !== false) { + if ($html_data !== false) { $this->myLogger->logme('error', 'TPA: {tpa}, e-Card HTML template file saved successfully: {data}, filepath is: {path}', ['data' => $filename, 'tpa' => $tpa_name, 'path' => $file_path]); } else { $this->myLogger->logme('error', 'TPA: {tpa}, e-Card HTML template file unable to save: {data}', ['data' => $filename, 'tpa' => $tpa_name]); @@ -772,7 +1258,7 @@ class MasterController extends AdminController if($update){ - echo json_encode(array("status" => true , 'data' => $data)); + echo json_encode(array("status" => true , 'data' => $update_data)); }else{ echo json_encode(array("status" => false)); } @@ -795,9 +1281,110 @@ class MasterController extends AdminController public function editTPABranch() { $this->myLogger->logme('error','TPA branch CREATE function called'); - $id = $this->request->getPost('PrimaryKey'); + $rules = [ + + // ====================== + // Branch Details + // ====================== + 'branch_name' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'Branch name is required' + ] + ], + + 'branch_code' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'Branch code is required' + ] + ], + + 'address1' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'Address Line 1 is required' + ] + ], + + 'state' => [ + 'rules' => 'required|is_natural_no_zero', + 'errors' => [ + 'required' => 'State is required' + ] + ], + + 'district' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'District is required' + ] + ], + + 'city' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'City is required' + ] + ], + + 'pincode' => [ + 'rules' => 'required|numeric|exact_length[6]', + 'errors' => [ + 'required' => 'Pincode is required', + 'numeric' => 'Pincode must contain only numbers', + 'exact_length' => 'Pincode must be exactly 6 digits' + ] + ], + + // ====================== + // Contact Details (Array) + // ====================== + 'name.*' => [ + 'rules' => 'required|trim|min_length[2]', + 'errors' => [ + 'required' => 'Contact name is required', + 'min_length' => 'Contact name must be at least 2 characters' + ] + ], + + 'designation.*' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'Designation is required' + ] + ], + + 'email.*' => [ + 'rules' => 'required|valid_email', + 'errors' => [ + 'required' => 'Email is required', + 'valid_email' => 'Invalid email format' + ] + ], + + 'mobile.*' => [ + 'rules' => 'required|numeric|exact_length[10]', + 'errors' => [ + 'required' => 'Mobile number is required', + 'numeric' => 'Mobile must contain only digits', + 'exact_length' => 'Mobile number must be exactly 10 digits' + ] + ], + ]; + + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } $data = $this->request->getPost(); - $update = $this->tpaBranchModel->update($id, $data); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + $id = $sanitizeInputArrayAdvanced['PrimaryKey']; + $update = $this->tpaBranchModel->update($id, $sanitized_post_data); // print_r($this->request->getPost('name[]')); // print_r($this->request->getPost('email[]')); @@ -809,18 +1396,18 @@ class MasterController extends AdminController foreach ($contactsToDelete as $contact) { $this->levelContactModel->delete($contact->id); } - for ($i = 0; $i < count($this->request->getPost('name')); $i++) { + for ($i = 0; $i < count($sanitized_post_data['name']); $i++) { // Prepare data to update - $data = [ + $sanitized_post_data_for_level = [ 'contact_type' => 'tpa', 'ref_id' => $id, 'created_by' => get_session_userid(), - 'name' => $this->request->getPost('name')[$i], - 'email' => $this->request->getPost('email')[$i], - 'mobile' => $this->request->getPost('mobile')[$i], - 'designation' => $this->request->getPost('designation')[$i] + 'name' => $sanitized_post_data['name'][$i], + 'email' => $sanitized_post_data['email'][$i], + 'mobile' => $sanitized_post_data['mobile'][$i], + 'designation' => $sanitized_post_data['designation'][$i] ]; - $contacts = $this->levelContactModel->insert($data); + $contacts = $this->levelContactModel->insert($sanitized_post_data_for_level); } } @@ -926,10 +1513,28 @@ class MasterController extends AdminController { $this->myLogger->logme('error','KYC Entity Type general info function called'); + $rules = [ + 'name' => [ + 'rules' => 'required', + 'errors' => [ + 'required' => 'KYC Entity Type Name is required' + ] + ], + ]; + + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } $data = $this->request->getPost(); - $data['created_by'] = get_session_userid(); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + $sanitized_post_data['created_by'] = get_session_userid(); - $insert = $this->kycEntityTypeModel->insert($data); + $insert = $this->kycEntityTypeModel->insert($sanitized_post_data); if($insert){ $kyc_data = $this->kycEntityTypeModel->where(['id' => $insert, 'is_active' => 1])->first(); echo json_encode(array("status" => true , 'data' => $kyc_data)); @@ -942,20 +1547,40 @@ class MasterController extends AdminController { $this->myLogger->logme('error','Kyc Docs CREATE function called'); + $rules = [ + 'file_name' => [ + 'rules' => 'required', + 'errors' => [ + 'required' => 'KYC Docs File Name is required' + ] + ], + ]; + + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } + $data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + // print_r($data);die; - if($data['kyc_type_id'] == ''){ + if($sanitized_post_data['kyc_type_id'] == ''){ // PrimaryKey - $data['kyc_type_id'] =$data['PrimaryKey']; + $sanitized_post_data['kyc_type_id'] =$data['PrimaryKey']; } // print_r($data);die; - $data['created_by'] = get_session_userid(); - $insert = $this->kycDocsModel->insert($data); + $sanitized_post_data['created_by'] = get_session_userid(); + $insert = $this->kycDocsModel->insert($sanitized_post_data); if($insert){ - $kycDocsData = $this->kycDocsModel->where('kyc_type_id', $data['kyc_type_id'])->where('is_active',1)->findAll(); + $kycDocsData = $this->kycDocsModel->where('kyc_type_id', $sanitized_post_data['kyc_type_id'])->where('is_active',1)->findAll(); echo json_encode(array("status" => true , 'data' => $kycDocsData)); }else{ echo json_encode(array("status" => false)); @@ -999,12 +1624,31 @@ class MasterController extends AdminController public function editKYCInfo() { $this->myLogger->logme('error','edit KYC general info function called'); - $id = $this->request->getPost('PrimaryKey'); - $data = $this->request->getPost(); - $data['updated_by'] = get_session_userid(); - $update = $this->kycEntityTypeModel->update($id,$data); + $rules = [ + 'file_name' => [ + 'rules' => 'required', + 'errors' => [ + 'required' => 'KYC Docs File Name is required' + ] + ], + ]; + + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } + + $data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + $id = $sanitized_post_data['PrimaryKey']; + $sanitized_post_data['updated_by'] = get_session_userid(); + $update = $this->kycEntityTypeModel->update($id,$sanitized_post_data); if($update){ - echo json_encode(array("status" => true , 'data' => $data)); + echo json_encode(array("status" => true , 'data' => $sanitized_post_data)); }else{ echo json_encode(array("status" => false)); } @@ -1138,11 +1782,97 @@ class MasterController extends AdminController public function createPolicyType() { $this->myLogger->logme('error','Policy Type CREATE function called'); + $rules = [ + 'policy_type' => [ + 'rules' => 'required|trim|min_length[2]', + 'errors' => [ + 'required' => 'Policy type name is required', + 'min_length' => 'Policy type name must be at least 2 characters' + ] + ], + + 'bap' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'BAP is required' + ] + ], + + 'allocg' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'Category is required' + ] + ], + + 'alloci' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'BAP category is required' + ] + ], + + + 'ebp' => [ + 'rules' => 'permit_empty|numeric|greater_than_equal_to[0]', + 'errors' => [ + 'numeric' => 'Group base premium must be numeric', + 'greater_than_equal_to' => 'Value cannot be negative' + ] + ], + + 'etp' => [ + 'rules' => 'permit_empty|numeric|greater_than_equal_to[0]', + 'errors' => [ + 'numeric' => 'Group third-party premium must be numeric', + 'greater_than_equal_to' => 'Value cannot be negative' + ] + ], + + 'etep' => [ + 'rules' => 'permit_empty|numeric|greater_than_equal_to[0]', + 'errors' => [ + 'numeric' => 'Group terrorism premium must be numeric', + 'greater_than_equal_to' => 'Value cannot be negative' + ] + ], + + 'iep' => [ + 'rules' => 'permit_empty|numeric|greater_than_equal_to[0]', + 'errors' => [ + 'numeric' => 'Individual base premium must be numeric', + 'greater_than_equal_to' => 'Value cannot be negative' + ] + ], + + 'itp' => [ + 'rules' => 'permit_empty|numeric|greater_than_equal_to[0]', + 'errors' => [ + 'numeric' => 'Individual third-party premium must be numeric', + 'greater_than_equal_to' => 'Value cannot be negative' + ] + ], + + 'itep' => [ + 'rules' => 'permit_empty|numeric|greater_than_equal_to[0]', + 'errors' => [ + 'numeric' => 'Individual terrorism premium must be numeric', + 'greater_than_equal_to' => 'Value cannot be negative' + ] + ], + ]; + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } $data = $this->request->getPost(); - - $data['created_by'] = get_session_userid(); - $insert = $this->policyTypeModel->insert($data); - + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + $sanitized_post_data['created_by'] = get_session_userid(); + $insert = $this->policyTypeModel->insert($sanitized_post_data); if($insert){ $policyTypeData = $this->policyTypeModel->where('id', $insert)->first(); echo json_encode(array("status" => true , 'data' => $policyTypeData)); @@ -1175,12 +1905,101 @@ class MasterController extends AdminController public function editPolicyType() { $this->myLogger->logme('error','edit Policy general info function called'); - $id = $this->request->getPost('PrimaryKey'); - $data = $this->request->getPost(); - $data['updated_by'] = get_session_userid(); - $update = $this->policyTypeModel->update($id,$data); + $rules = [ + 'policy_type' => [ + 'rules' => 'required|trim|min_length[2]', + 'errors' => [ + 'required' => 'Policy type name is required', + 'min_length' => 'Policy type name must be at least 2 characters' + ] + ], + + 'bap' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'BAP is required' + ] + ], + + 'allocg' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'Category is required' + ] + ], + + 'alloci' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'BAP category is required' + ] + ], + + + 'ebp' => [ + 'rules' => 'permit_empty|numeric|greater_than_equal_to[0]', + 'errors' => [ + 'numeric' => 'Group base premium must be numeric', + 'greater_than_equal_to' => 'Value cannot be negative' + ] + ], + + 'etp' => [ + 'rules' => 'permit_empty|numeric|greater_than_equal_to[0]', + 'errors' => [ + 'numeric' => 'Group third-party premium must be numeric', + 'greater_than_equal_to' => 'Value cannot be negative' + ] + ], + + 'etep' => [ + 'rules' => 'permit_empty|numeric|greater_than_equal_to[0]', + 'errors' => [ + 'numeric' => 'Group terrorism premium must be numeric', + 'greater_than_equal_to' => 'Value cannot be negative' + ] + ], + + 'iep' => [ + 'rules' => 'permit_empty|numeric|greater_than_equal_to[0]', + 'errors' => [ + 'numeric' => 'Individual base premium must be numeric', + 'greater_than_equal_to' => 'Value cannot be negative' + ] + ], + + 'itp' => [ + 'rules' => 'permit_empty|numeric|greater_than_equal_to[0]', + 'errors' => [ + 'numeric' => 'Individual third-party premium must be numeric', + 'greater_than_equal_to' => 'Value cannot be negative' + ] + ], + + 'itep' => [ + 'rules' => 'permit_empty|numeric|greater_than_equal_to[0]', + 'errors' => [ + 'numeric' => 'Individual terrorism premium must be numeric', + 'greater_than_equal_to' => 'Value cannot be negative' + ] + ], + ]; + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } + $data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + + $id = $sanitized_post_data['PrimaryKey']; + $sanitized_post_data['updated_by'] = get_session_userid(); + $update = $this->policyTypeModel->update($id,$sanitized_post_data); if($update){ - echo json_encode(array("status" => true , 'data' => $data)); + echo json_encode(array("status" => true , 'data' => $sanitized_post_data)); }else{ echo json_encode(array("status" => false)); } @@ -1347,12 +2166,74 @@ class MasterController extends AdminController public function createCDMasterData() { $this->myLogger->logme("error", 'Create CD Master Data API called.'); - $data = $this->request->getPost(); + $rules = [ + + // ====================== + // Client / Insurer Mapping + // ====================== + 'client_id' => [ + 'rules' => 'required|is_natural_no_zero', + 'errors' => [ + 'required' => 'Client is required' + ] + ], + + 'insurer_id' => [ + 'rules' => 'required|is_natural_no_zero', + 'errors' => [ + 'required' => 'Insurer is required' + ] + ], + + 'insurer_branch_id' => [ + 'rules' => 'required|is_natural_no_zero', + 'errors' => [ + 'required' => 'Insurer branch is required' + ] + ], + + // ====================== + // CD Account Details + // ====================== + 'opening_date' => [ + 'rules' => 'required|valid_date[Y-m-d]', + 'errors' => [ + 'required' => 'Opening date is required', + 'valid_date' => 'Opening date must be in YYYY-MM-DD format' + ] + ], + + 'cd_ac_no' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'CD account number is required' + ] + ], + + 'opening_bal' => [ + 'rules' => 'required|numeric|greater_than_equal_to[0]', + 'errors' => [ + 'required' => 'Opening amount is required', + 'numeric' => 'Opening amount must be numeric', + 'greater_than_equal_to' => 'Opening amount cannot be negative' + ] + ], + ]; + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } + $data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); $this->myLogger->logme("error", 'Received POST data: ' . json_encode($data)); - $id = $data['PrimaryKey'] ?? null; - $date = (string) ($data['opening_date'] ?? ''); - $data['opening_date'] = date('Y-m-d', strtotime($date)); + $id = $sanitized_post_data['PrimaryKey'] ?? null; + $date = (string) ($sanitized_post_data['opening_date'] ?? ''); + $sanitized_post_data['opening_date'] = date('Y-m-d', strtotime($date)); $this->myLogger->logme("error", 'Formatted opening_date: ' . $data['opening_date']); $loggedInUserID = get_session_userid(); @@ -1362,9 +2243,9 @@ class MasterController extends AdminController if (empty($id)) { $cd_acc_count = $this->CDMasterModel->where('is_active', 1) - ->where('client_id', $data['client_id']) - ->where('insurer_id', $data['insurer_id']) - ->where('insurer_branch_id', $data['insurer_branch_id']) + ->where('client_id', $sanitized_post_data['client_id']) + ->where('insurer_id', $sanitized_post_data['insurer_id']) + ->where('insurer_branch_id', $sanitized_post_data['insurer_branch_id']) ->countAllResults(); if($cd_acc_count > 0){ @@ -1372,19 +2253,19 @@ class MasterController extends AdminController } $this->myLogger->logme("error", 'Performing INSERT operation.'); - $insert = $this->CDMasterModel->insert($data); + $insert = $this->CDMasterModel->insert($sanitized_post_data); $this->myLogger->logme("error", 'Insert result: ' . json_encode($insert)); if ($insert) { $cd_tranction_data = [ - 'amount' => $data['opening_bal'], + 'amount' => $sanitized_post_data['opening_bal'], 'sub_type_id' => 7, - 'client_id' => $data['client_id'], + 'client_id' => $sanitized_post_data['client_id'], 'client_policy_id' => null, - 'cd_ac_no' => $data['cd_ac_no'], + 'cd_ac_no' => $sanitized_post_data['cd_ac_no'], 'endorsement_no' => null, - 'insurer_id' => $data['insurer_id'], + 'insurer_id' => $sanitized_post_data['insurer_id'], 'description' => 'Opening Amount', 'transaction_type' => 'Credit', 'event_name' => null, @@ -1400,9 +2281,9 @@ class MasterController extends AdminController $this->myLogger->logme("error", 'Inserted CD Master data: ' . json_encode($cd_master_data)); $cd_master_full_data = $this->CDMasterModel->where('is_active', 1) - ->where('client_id', $data['client_id']) - ->where('insurer_id', $data['insurer_id']) - ->where('insurer_branch_id', $data['insurer_branch_id']) + ->where('client_id', $sanitized_post_data['client_id']) + ->where('insurer_id', $sanitized_post_data['insurer_id']) + ->where('insurer_branch_id', $sanitized_post_data['insurer_branch_id']) ->findAll(); return $this->respond([ @@ -1427,7 +2308,7 @@ class MasterController extends AdminController // === UPDATE === $this->myLogger->logme("error", 'Performing UPDATE operation for ID: ' . $id); - $updated = $this->CDMasterModel->where('id', $id)->set($data)->update(); + $updated = $this->CDMasterModel->where('id', $id)->set($sanitized_post_data)->update(); $this->myLogger->logme("error", 'Update result: ' . json_encode($updated)); $existingData = $this->CDMasterModel->where('is_active', 1)->where('id', $id)->first(); @@ -1465,27 +2346,89 @@ class MasterController extends AdminController public function editCDMasterData($id = null) { + $this->myLogger->logme("error", 'Edit CD Master Data API called.'); + $rules = [ - $id = $this->request->getPost('PrimaryKey'); - $date = (string) $this->request->getPost('opening_date'); - $data = $this->request->getPost(); - $data['opening_date'] = date('Y-m-d', strtotime($date)); + // ====================== + // Client / Insurer Mapping + // ====================== + 'client_id' => [ + 'rules' => 'required|is_natural_no_zero', + 'errors' => [ + 'required' => 'Client is required' + ] + ], + + 'insurer_id' => [ + 'rules' => 'required|is_natural_no_zero', + 'errors' => [ + 'required' => 'Insurer is required' + ] + ], + + 'insurer_branch_id' => [ + 'rules' => 'required|is_natural_no_zero', + 'errors' => [ + 'required' => 'Insurer branch is required' + ] + ], + + // ====================== + // CD Account Details + // ====================== + 'opening_date' => [ + 'rules' => 'required|valid_date[Y-m-d]', + 'errors' => [ + 'required' => 'Opening date is required', + 'valid_date' => 'Opening date must be in YYYY-MM-DD format' + ] + ], + + 'cd_ac_no' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'CD account number is required' + ] + ], + + 'opening_bal' => [ + 'rules' => 'required|numeric|greater_than_equal_to[0]', + 'errors' => [ + 'required' => 'Opening amount is required', + 'numeric' => 'Opening amount must be numeric', + 'greater_than_equal_to' => 'Opening amount cannot be negative' + ] + ], + ]; + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } + $data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + $id = $sanitized_post_data['PrimaryKey']; + $date = (string) $sanitized_post_data['opening_date']; + $sanitized_post_data['opening_date'] = date('Y-m-d', strtotime($date)); if ($data) { - $insert = $this->CDMasterModel->where('id', $id)->set($data)->update(); + $insert = $this->CDMasterModel->where('id', $id)->set($sanitized_post_data)->update(); - $data = $this->CDMasterModel->where('id', $id)->first(); + $get_data = $this->CDMasterModel->where('id', $id)->first(); $cd_transaction_updated_data = [ - 'balance' => $data['opening_bal'], - 'amount' => $data['opening_bal'] + 'balance' => $get_data['opening_bal'], + 'amount' => $get_data['opening_bal'] ]; $cd_tranction = $this->clientDepositModel - ->where('client_id', $data['client_id']) - ->where('insurer_id', $data['insurer_id']) - ->where('cd_ac_no', $data['cd_ac_no']) + ->where('client_id', $sanitized_post_data['client_id']) + ->where('insurer_id', $sanitized_post_data['insurer_id']) + ->where('cd_ac_no', $sanitized_post_data['cd_ac_no']) ->where('sub_type', 7) ->set($cd_transaction_updated_data)->update(); @@ -1731,35 +2674,72 @@ class MasterController extends AdminController { // return $this->respond($this->request->getPost()); $template_id = $this->request->getPost('template_id'); + + $rules = [ + 'policy_type' => [ + 'rules' => 'required|is_natural_no_zero', + 'errors' => [ + 'required' => 'Policy type is required' + ] + ], + + 'event' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'Event is required' + ] + ], + + + 'json_data' => [ + 'rules' => 'required', + 'errors' => [ + 'required' => 'Template mapping data is required' + ] + ], + ]; + + if (! $this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } + $data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + + - $data = [ - 'insurer_id' => $this->request->getPost('insurer_id'), - 'policy_type_id' => $this->request->getPost('policy_type'), - 'event_name' => $this->request->getPost('event'), + $fetch_data = [ + 'insurer_id' => $sanitized_post_data['insurer_id'], + 'policy_type_id' => $sanitized_post_data['policy_type'], + 'event_name' => $sanitized_post_data['event'], 'type_name' => 'export', - 'jsoncolumns' => $this->request->getPost('json_data'), + 'jsoncolumns' => $sanitized_post_data['json_data'], 'is_active' => 1, 'created_by' => get_session_userid(), ]; if($template_id){ - $update = $this->insurerTemplateModel->where('id', $template_id)->set($data)->update(); + $update = $this->insurerTemplateModel->where('id', $template_id)->set($fetch_data)->update(); if($update){ - return $this->respond(['status' => true, 'message' => 'Template updated successfully', $data]); + return $this->respond(['status' => true, 'message' => 'Template updated successfully', $fetch_data]); }else{ - return $this->respond(['status' => true, 'message' => 'Failed to update template', $data]); + return $this->respond(['status' => true, 'message' => 'Failed to update template', $fetch_data]); } }else{ - $insert = $this->insurerTemplateModel->insert($data); + $insert = $this->insurerTemplateModel->insert($fetch_data); if($insert){ - return $this->respond(['status' => true, 'message' => 'Template created successfully', $data]); + return $this->respond(['status' => true, 'message' => 'Template created successfully', $fetch_data]); }else{ - return $this->respond(['status' => true, 'message' => 'Failed to create template', $data]); + return $this->respond(['status' => true, 'message' => 'Failed to create template', $fetch_data]); } } @@ -2161,13 +3141,34 @@ class MasterController extends AdminController if ($method === 'post') { - $id = $this->request->getPost('pk') ?? null; - $data = $this->request->getPost(); + + $rules = [ + 'branch_name' => [ + 'rules' => 'required', + 'errors' => [ + 'required' => 'Branch Name is required' + ] + ] + ]; + if (! $this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } + + $data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + $id = $sanitized_post_data['pk'] ?? null; + unset($sanitized_post_data['pk']); + if (empty($id)) { - $update_status = $nhanceBranchModel->insert($data); + $update_status = $nhanceBranchModel->insert($sanitized_post_data); } else { - $update_status = $nhanceBranchModel->where('id', $id)->set($data)->update(); + $update_status = $nhanceBranchModel->where('id', $id)->set($sanitized_post_data)->update(); } if ($update_status) { @@ -2243,13 +3244,34 @@ class MasterController extends AdminController if ($method === 'post') { - $id = $this->request->getPost('pk') ?? null; - $data = $this->request->getPost(); + + $rules = [ + 'vehicle_type' => [ + 'rules' => 'required', + 'errors' => [ + 'required' => 'Vehicle Type is required' + ] + ] + ]; + + if (! $this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } + + $data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + $id = $sanitized_post_data['pk'] ?? null; + unset($sanitized_post_data['pk']); if (empty($id)) { - $update_status = $vehicleTypeModel->insert($data); + $update_status = $vehicleTypeModel->insert($sanitized_post_data); } else { - $update_status = $vehicleTypeModel->where('id', $id)->set($data)->update(); + $update_status = $vehicleTypeModel->where('id', $id)->set($sanitized_post_data)->update(); } if ($update_status) { @@ -2257,14 +3279,14 @@ class MasterController extends AdminController 'status' => true, 'code' => 200, 'message' => 'Vehicle Type Master updated successfully', - 'data' => $data + 'data' => $sanitized_post_data ], 200); } else { return $this->respond([ 'status' => false, 'code' => 400, 'message' => 'Failed to update', - 'data' => $data + 'data' => $sanitized_post_data ], 200); } @@ -2324,13 +3346,62 @@ class MasterController extends AdminController if ($method === 'post') { - $id = $this->request->getPost('pk') ?? null; - $data = $this->request->getPost(); + $rules = [ + // ====================== + // RTO Office Name + // ====================== + 'rto_name' => [ + 'rules' => 'required|trim|min_length[3]|max_length[100]|alpha_numeric_space', + 'errors' => [ + 'required' => 'RTO Office Name is required', + 'min_length' => 'RTO Office Name must be at least 3 characters' + ] + ], + // ====================== + // RTO Code (2 digits only) + // ====================== + 'rto_code' => [ + 'rules' => 'required|exact_length[2]|numeric', + 'errors' => [ + 'required' => 'RTO Code is required', + 'exact_length' => 'RTO Code must be exactly 2 digits', + 'numeric' => 'RTO Code must contain only numbers' + ] + ], + // ====================== + // RTO State (2 letters only) + // ====================== + 'rto_state' => [ + 'rules' => 'required|exact_length[2]|alpha', + 'errors' => [ + 'required' => 'RTO State is required', + 'exact_length' => 'RTO State must be exactly 2 letters', + 'alpha' => 'RTO State must contain only alphabets' + ] + ], + + ]; + + if (! $this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } + + + $data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + $id = $sanitized_post_data['pk'] ?? null; + unset($sanitized_post_data['pk']); + if (empty($id)) { - $update_status = $rtoModel->insert($data); + $update_status = $rtoModel->insert($sanitized_post_data); } else { - $update_status = $rtoModel->where('id', $id)->set($data)->update(); + $update_status = $rtoModel->where('id', $id)->set($sanitized_post_data)->update(); } if ($update_status) { @@ -2338,14 +3409,14 @@ class MasterController extends AdminController 'status' => true, 'code' => 200, 'message' => 'RTO Master updated successfully', - 'data' => $data + 'data' => $sanitized_post_data ], 200); } else { return $this->respond([ 'status' => false, 'code' => 400, 'message' => 'Failed to update', - 'data' => $data + 'data' => $sanitized_post_data ], 200); } @@ -2405,47 +3476,172 @@ class MasterController extends AdminController if ($this->request->getMethod() === 'post') { - $id = $this->request->getPost('pk'); - $data = $this->request->getPost(); + $rules = [ + 'manager_id' => [ + 'rules' => 'required|integer', + 'errors' => [ + 'required' => 'Manager is required', + 'integer' => 'Invalid Manager selected' + ] + ], + 'name' => [ + 'rules' => 'required|min_length[3]|max_length[100]|alpha_space', + 'errors' => [ + 'required' => 'Name is required', + 'min_length' => 'Name must be at least 3 characters', + 'max_length' => 'Name cannot exceed 100 characters', + 'alpha_space'=> 'Name can contain only letters and spaces' + ] + ], + 'pos_code' => [ + 'rules' => 'required|alpha_numeric|max_length[20]', + 'errors' => [ + 'required' => 'POS Code is required', + 'alpha_numeric' => 'POS Code must be alphanumeric', + 'max_length' => 'POS Code cannot exceed 20 characters' + ] + ], + 'email' => [ + 'rules' => 'required|valid_email', + 'errors' => [ + 'required' => 'Email is required', + 'valid_email' => 'Enter a valid email address' + ] + ], + 'mobile' => [ + 'rules' => 'required|numeric|exact_length[10]', + 'errors' => [ + 'required' => 'Mobile number is required', + 'numeric' => 'Mobile number must contain only digits', + 'exact_length' => 'Mobile number must be exactly 10 digits' + ] + ], + 'address' => [ + 'rules' => 'required|min_length[5]', + 'errors' => [ + 'required' => 'Address is required', + 'min_length' => 'Address must be at least 5 characters' + ] + ], + 'city' => [ + 'rules' => 'required|alpha_space', + 'errors' => [ + 'required' => 'City is required', + 'alpha_space' => 'City must contain only letters and spaces' + ] + ], + 'state' => [ + 'rules' => 'required|alpha_space', + 'errors' => [ + 'required' => 'State is required', + 'alpha_space' => 'State must contain only letters and spaces' + ] + ], + 'pincode' => [ + 'rules' => 'required|numeric|exact_length[6]', + 'errors' => [ + 'required' => 'Pincode is required', + 'numeric' => 'Pincode must contain only digits', + 'exact_length' => 'Pincode must be exactly 6 digits' + ] + ], + 'aadhar' => [ + 'rules' => 'required|numeric|exact_length[12]', + 'errors' => [ + 'required' => 'Aadhaar number is required', + 'numeric' => 'Aadhaar must contain only digits', + 'exact_length' => 'Aadhaar must be exactly 12 digits' + ] + ], + 'pan' => [ + 'rules' => 'required|regex_match[/^[A-Z]{5}[0-9]{4}[A-Z]{1}$/]', + 'errors' => [ + 'required' => 'PAN number is required', + 'regex_match' => 'Enter a valid PAN number (ABCDE1234F)' + ] + ], + 'gst' => [ + 'rules' => 'permit_empty|max_length[15]', + 'errors' => [ + 'max_length' => 'GST number cannot exceed 15 characters' + ] + ], + 'aadhar_file_name' => [ + 'rules' => 'permit_empty|uploaded[aadhar_file_name]|max_size[aadhar_file_name,5120]|ext_in[aadhar_file_name,pdf,jpg,jpeg,png]', + 'errors' => [ + 'uploaded' => 'Invalid Aadhaar file', + 'max_size' => 'Aadhaar file size should not exceed 5MB', + 'ext_in' => 'Aadhaar must be PDF or image (jpg, jpeg, png)' + ] + ], + 'pan_file_name' => [ + 'rules' => 'permit_empty|uploaded[pan_file_name]|max_size[pan_file_name,5120]|ext_in[pan_file_name,pdf,jpg,jpeg,png]', + 'errors' => [ + 'uploaded' => 'Invalid PAN file', + 'max_size' => 'PAN file size should not exceed 5MB', + 'ext_in' => 'PAN must be PDF or image (jpg, jpeg, png)' + ] + ], + 'certificate_file_name' => [ + 'rules' => 'permit_empty|uploaded[certificate_file_name]|max_size[certificate_file_name,5120]|ext_in[certificate_file_name,pdf,jpg,jpeg,png]', + 'errors' => [ + 'uploaded' => 'Invalid Certificate file', + 'max_size' => 'Certificate file size should not exceed 5MB', + 'ext_in' => 'Certificate must be PDF or image (jpg, jpeg, png)' + ] + ], + ]; - unset($data['pk']); + if (! $this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } + + $data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + $id = $sanitized_post_data['pk'] ?? null; + unset($sanitized_post_data['pk']); try { // Certificate $certificate = $this->uploadPOSFile('certificate_file_name', 'pos_certificate_files'); - if ($certificate !== null) { $data['certificate_file_name'] = $certificate; } else { unset($data['certificate_file_name']); } + if ($certificate !== null) { $sanitized_post_data['certificate_file_name'] = $certificate; } else { unset($sanitized_post_data['certificate_file_name']); } // PAN file $panFile = $this->uploadPOSFile('pan_file_name', 'pos_certificate_files'); - if ($panFile !== null) { $data['pan_file_name'] = $panFile; } else { unset($data['pan_file_name']);} + if ($panFile !== null) { $sanitized_post_data['pan_file_name'] = $panFile; } else { unset($sanitized_post_data['pan_file_name']);} // Aadhaar file $aadharFile = $this->uploadPOSFile('aadhar_file_name', 'pos_certificate_files'); - if ($aadharFile !== null) { $data['aadhar_file_name'] = $aadharFile; } else { unset($data['aadhar_file_name']);} + if ($aadharFile !== null) { $sanitized_post_data['aadhar_file_name'] = $aadharFile; } else { unset($sanitized_post_data['aadhar_file_name']);} } catch (\RuntimeException $e) { - return $this->respond([ 'status' => false, 'code' => 400, 'message' => $e->getMessage(), 'data' => $data ], 400); + return $this->respond([ 'status' => false, 'code' => 400, 'message' => $e->getMessage(), 'data' => $sanitized_post_data ], 400); } - foreach ($data as $k => $v) { + foreach ($sanitized_post_data as $k => $v) { if ($v === '' || $v === null) { - unset($data[$k]); + unset($sanitized_post_data[$k]); } } // INSERT / UPDATE if (empty($id)) { - $status = $posModel->insert($data); + $status = $posModel->insert($sanitized_post_data); } else { - $status = $posModel->update($id, $data); + $status = $posModel->update($id, $sanitized_post_data); } if ($status) { - return $this->respond([ 'status' => true, 'code' => 200, 'message' => 'POS updated successfully', 'data' => $data ], 200); + return $this->respond([ 'status' => true, 'code' => 200, 'message' => 'POS updated successfully', 'data' => $sanitized_post_data ], 200); } - return $this->respond([ 'status' => false, 'code' => 400, 'message' => 'Failed to update', 'data' => $data ], 400); + return $this->respond([ 'status' => false, 'code' => 400, 'message' => 'Failed to update', 'data' => $sanitized_post_data ], 400); } elseif ($method === 'get') { diff --git a/app/Controllers/PayoutController.php b/app/Controllers/PayoutController.php index bba35e99..bf992d88 100644 --- a/app/Controllers/PayoutController.php +++ b/app/Controllers/PayoutController.php @@ -281,13 +281,17 @@ class PayoutController extends BaseController //... Payout-invoice Mapping - Save/update/soft Delete/Hard Delete Data public function saveInvoice() { - $json = $this->request->getJSON(true); - // print_rr($json);die(); - - if (!$json) { + $raw_json = $this->request->getJSON(true); + + // 1. Check if the JSON was actually valid/parsed before sanitizing + if (is_null($raw_json)) { return $this->response->setJSON(['error' => 'Invalid JSON','message' => 'Invalid JSON received.'])->setStatusCode(400); } + // 2. Sanitize the data + $json = sanitizeInputArrayAdvanced($raw_json); + + // 3. Now you can safely use $json (even if it is an empty array) $id = $json['invoice_id'] ?? null; try { diff --git a/app/Controllers/PolicyTransactionController.php b/app/Controllers/PolicyTransactionController.php index 81eede97..723a171e 100644 --- a/app/Controllers/PolicyTransactionController.php +++ b/app/Controllers/PolicyTransactionController.php @@ -917,12 +917,14 @@ // policy Transaction Create function start public function createInceptionPolicy() { - $post_data = $this->request->getPost() ?? []; + $post_data = $this->request->getPost(); + $post_data = $post_data ? sanitizeInputArrayAdvanced($post_data) : []; + $this->myLogger->logme('error', 'Policy Trancaction form data : '. json_encode($post_data)); - $id = $this->request->getPost('id'); + $id = $post_data['id'] ?? null; $data = $this->preparePolicyData(); - $data['cd_ac_pk'] = $this->request->getPost('cd_ac_no'); + $data['cd_ac_pk'] = $post_data['cd_ac_no']; $data['issuer'] = 2; $data['status'] = 'completed'; $this->myLogger->logme('error', 'Policy Trancaction modified form data ( insert data ) : '. json_encode($data)); @@ -937,7 +939,8 @@ private function preparePolicyData() { - $data = $this->request->getPost(); + $request_data = $this->request->getPost(); + $data = sanitizeInputArrayAdvanced($request_data); $file_data = $this->request->getFiles() ?? null; $data['file_data'] = $file_data ?? null; @@ -2249,9 +2252,10 @@ public function createEndorsementPolicy() { - $id = $this->request->getPost('id'); + // $id = $this->request->getPost('id'); $data = $this->preparePolicyTransactionData(); $data['status'] = 'completed'; + $id = $data['id'] ?? null; // print_r($data); die; if (!$id) { @@ -2263,8 +2267,8 @@ private function preparePolicyTransactionData() { - $data = $this->request->getPost(); - + $request_post_data = $this->request->getPost(); + $data = sanitizeInputArrayAdvanced($request_post_data); // echo '
';
             // print_r($data); 
             // die;
@@ -3253,10 +3257,12 @@
             $client_policy_id = (!isset($client_policy_id) || $client_policy_id === '' || $client_policy_id === null) ? 0 : $client_policy_id;
             $user_id = (!isset($user_id) || $user_id === '' || $user_id === null) ? 0 : $user_id;
             if ($this->request->is('post')) {
-                $isFromDashboard = $this->request->getPost("is_dashboard");
+                $request_post_data   = $this->request->getPost();
+                $sanitized_post_data = sanitizeInputArrayAdvanced($request_post_data);
+                $isFromDashboard = $sanitized_post_data["is_dashboard"];
 
                 if (isset($isFromDashboard) && !empty($isFromDashboard) && $isFromDashboard == 1) {
-                    $ids = $this->request->getPost('ids');
+                    $ids = $sanitized_post_data['ids'];
 
                     $ids = array_filter(explode(',', $ids));
 
@@ -4224,10 +4230,12 @@
             // echo 'scbsc';die();
             if ($this->request->is('post')) {
                 // $jsonData = (array)$this->request->getJSON();
-                $customer_id = $this->request->getPost('customer_id');
-                $policy_id = $this->request->getPost('policy_id');
-                $cus_doc_name = $this->request->getPost('cus_doc_name');
-                $policy_doc_name = $this->request->getPost('policy_doc_name');
+                $request_data   = $this->request->getPost();
+                $data = sanitizeInputArrayAdvanced($request_data);
+                $customer_id = $data['customer_id'];
+                $policy_id = $data['policy_id'];
+                $cus_doc_name = $data['cus_doc_name'];
+                $policy_doc_name = $data['policy_doc_name'];
                 $pt_files = [];
                 $kyc_files = [];
                 $batch_files = [];
diff --git a/app/Controllers/ThzController.php b/app/Controllers/ThzController.php
index df886d2a..713a8fb7 100644
--- a/app/Controllers/ThzController.php
+++ b/app/Controllers/ThzController.php
@@ -63,7 +63,98 @@ class ThzController extends BaseController
     public function ticketSave()
     {
         try {
-            $data = $this->request->getPost();
+            $rules = [
+                    'client_id' => [
+                        'rules'  => 'permit_empty|integer',
+                        'errors' => [
+                            'integer' => 'Invalid client selected'
+                        ]
+                    ],
+
+                    'mobile' => [
+                        'rules'  => 'required|regex_match[/^[0-9]{10}$/]',
+                        'errors' => [
+                            'required'     => 'Mobile number is required',
+                            'regex_match'  => 'Mobile number must be exactly 10 digits'
+                        ]
+                    ],
+
+                    'name' => [
+                        'rules'  => 'required|min_length[3]|max_length[100]|alpha_space',
+                        'errors' => [
+                            'required'   => 'Name is required',
+                            'min_length' => 'Name must be at least 3 characters',
+                            'alpha_space'=> 'Name can contain only letters and spaces'
+                        ]
+                    ],
+
+                    'email' => [
+                        'rules'  => 'required|valid_email|max_length[150]',
+                        'errors' => [
+                            'required'    => 'Email is required',
+                            'valid_email' => 'Please enter a valid email address'
+                        ]
+                    ],
+
+                    'empcode' => [
+                        'rules'  => 'permit_empty|max_length[50]',
+                        'errors' => [
+                            'max_length' => 'Employee code is too long'
+                        ]
+                    ],
+
+                    'ticket_type' => [
+                        'rules'  => 'required|in_list[Sales,Service]',
+                        'errors' => [
+                            'required' => 'Ticket Type is required',
+                            'in_list'  => 'Invalid Ticket Type selected'
+                        ]
+                    ],
+
+                    'assign_to' => [
+                        'rules'  => 'permit_empty|integer',
+                        'errors' => [
+                            'integer' => 'Invalid assignee selected'
+                        ]
+                    ],
+
+                    'subject' => [
+                        'rules'  => 'required|min_length[5]|max_length[150]',
+                        'errors' => [
+                            'required'   => 'Subject is required',
+                            'min_length' => 'Subject must be at least 5 characters',
+                            'max_length' => 'Subject cannot exceed 150 characters'
+                        ]
+                    ],
+
+                    'message' => [
+                        'rules'  => 'required|min_length[10]|max_length[1500]',
+                        'errors' => [
+                            'required'   => 'Message is required',
+                            'min_length' => 'Message must be at least 10 characters',
+                            'max_length' => 'Message cannot exceed 1500 characters'
+                        ]
+                    ],
+                    'status' => [
+                        'rules'  => 'permit_empty|in_list[Open,In Progress,Resolved,Closed]',
+                        'errors' => [
+                            'in_list' => 'Invalid ticket status'
+                        ]
+                    ],
+            ];
+
+            if (!$this->validate($rules)) {
+                return $this->response->setStatusCode(400)->setJSON([
+                    'status' => false,
+                    'message' => 'Input validation failed',
+                    'code' => 400,
+                    'errors' => $this->validator->getErrors()
+                ]);
+            }
+
+            $request_post_data = $this->request->getPost();
+            $data = sanitizeInputArrayAdvanced($request_post_data);
+                
             $references   = "";
             if (!empty($data['thz_id'])) {
 
@@ -157,7 +248,30 @@ class ThzController extends BaseController
     {
 
         try {
-            $data = $this->request->getPost();
+            
+            $rules = [
+                'notes' => [
+                    'rules'  => 'required|string|min_length[1]|max_length[1500]',
+                    'errors' => [
+                        'required'   => 'Notes is required',
+                        'string'     => 'Notes must be valid text',
+                        'min_length' => 'Notes cannot be empty',
+                        'max_length' => 'Notes cannot exceed 1500 characters'
+                    ]
+                ],
+            ];
+
+            if (!$this->validate($rules)) {
+                return $this->response->setStatusCode(400)->setJSON([
+                    'status' => false,
+                    'message' => 'Input validation failed',
+                    'code' => 400,
+                    'errors' => $this->validator->getErrors()
+                ]);
+            }
+
+            $request_post_data = $this->request->getPost();
+            $data = sanitizeInputArrayAdvanced($request_post_data);
 
             $data['notes_type'] = $data['notes_type'] ?? 'External';
 
diff --git a/app/Controllers/TicketController.php b/app/Controllers/TicketController.php
index 05ceb883..7dee25b6 100644
--- a/app/Controllers/TicketController.php
+++ b/app/Controllers/TicketController.php
@@ -1122,8 +1122,130 @@ class TicketController extends BaseController
 
     public function createTicket()
     {
-        $ticket_data = $this->request->getPost();
-        $ticket_data = $this->formatDateForClaim($ticket_data);
+        $rules = [
+            'emp_code' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Employee Code is required']
+            ],
+
+            'emp_name' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Employee Name is required']
+            ],
+
+            'insured_name' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Insured Name is required']
+            ],
+
+            'relationship' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Relationship is required']
+            ],
+
+            'emp_mobile' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Employee Mobile is required']
+            ],
+
+            'emp_mail' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Employee Email is required']
+            ],
+
+            'client_name' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Client Name is required']
+            ],
+
+            'insurer_id' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Insurer is required']
+            ],
+
+            'client_policy_id' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Policy is required']
+            ],
+
+            'claim_status_id' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Claim Status is required']
+            ],
+
+            'priority' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Priority is required']
+            ],
+
+            'mode_of_intimation' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Mode of Intimation is required']
+            ],
+
+            'claim_type' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Claim Type is required']
+            ],
+
+            'hospital_name' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Hospital Name is required']
+            ],
+
+            'hospital_address' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Hospital Address is required']
+            ],
+
+            'hospital_city' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Hospital City is required']
+            ],
+
+            'hospital_state' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Hospital State is required']
+            ],
+
+            'hospital_pin_code' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Hospital Pincode is required']
+            ],
+
+            'hospital_phone_no' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Hospital Phone Number is required']
+            ],
+
+            'doa' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Date of Admission is required']
+            ],
+
+            'dod' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Date of Discharge is required']
+            ],
+
+            'claim_amount' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Claim Amount is required']
+            ],
+        ];
+
+        if (!$this->validate($rules)) {
+            return $this->response->setStatusCode(400)->setJSON([
+                'status' => false,
+                'message' => 'Input validation failed',
+                'code' => 400,
+                'errors' => $this->validator->getErrors()
+            ]);
+        }
+
+        $request_data = $this->request->getPost();
+        $sanitized_data = sanitizeInputArrayAdvanced($request_data);
+        $ticket_data = $this->formatDateForClaim($sanitized_data);
         // $ticket_data = $this->getLastMatchedStatus($ticket_data, );
         // print_rr($ticket_data); die;
 
@@ -1183,9 +1305,132 @@ class TicketController extends BaseController
 
     public function updateTicket()
     {
+
+        $rules = [
+            'emp_code' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Employee Code is required']
+            ],
+
+            'emp_name' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Employee Name is required']
+            ],
+
+            'insured_name' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Insured Name is required']
+            ],
+
+            'relationship' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Relationship is required']
+            ],
+
+            'emp_mobile' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Employee Mobile is required']
+            ],
+
+            'emp_mail' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Employee Email is required']
+            ],
+
+            'client_name' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Client Name is required']
+            ],
+
+            'insurer_id' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Insurer is required']
+            ],
+
+            'client_policy_id' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Policy is required']
+            ],
+
+            'claim_status_id' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Claim Status is required']
+            ],
+
+            'priority' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Priority is required']
+            ],
+
+            'mode_of_intimation' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Mode of Intimation is required']
+            ],
+
+            'claim_type' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Claim Type is required']
+            ],
+
+            'hospital_name' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Hospital Name is required']
+            ],
+
+            'hospital_address' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Hospital Address is required']
+            ],
+
+            'hospital_city' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Hospital City is required']
+            ],
+
+            'hospital_state' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Hospital State is required']
+            ],
+
+            'hospital_pin_code' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Hospital Pincode is required']
+            ],
+
+            'hospital_phone_no' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Hospital Phone Number is required']
+            ],
+
+            'doa' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Date of Admission is required']
+            ],
+
+            'dod' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Date of Discharge is required']
+            ],
+
+            'claim_amount' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Claim Amount is required']
+            ],
+        ];
+
+        if (!$this->validate($rules)) {
+            return $this->response->setStatusCode(400)->setJSON([
+                'status' => false,
+                'message' => 'Input validation failed',
+                'code' => 400,
+                'errors' => $this->validator->getErrors()
+            ]);
+        }
+        
+        $request_data = $this->request->getPost();
+        $sanitized_data = sanitizeInputArrayAdvanced($request_data);
+        $ticket_data = $this->formatDateForClaim($sanitized_data);
         $ticket_id = $this->request->getPost('ticket_master_id');
-        $ticket_data = $this->request->getPost();
-        $ticket_data = $this->formatDateForClaim($ticket_data);
         $old_ticket_data = $this->ticketMasterModel->where('id', $ticket_id)->where('is_active', 1)->first();
         $ticket_data['claim_status_id'] = $this->getLastMatchedStatus($ticket_data, $old_ticket_data);
         // print_rr($ticket_data); die;
@@ -1250,7 +1495,49 @@ class TicketController extends BaseController
     {
         //action 1 is create. action 2 is edit and action 3 is delete
         if ($action == 1) {
-            $received_data = $this->request->getPost();
+                $rules = [
+                    'template_name' => [
+                        'rules'  => 'required',
+                        'errors' => [
+                            'required' => 'Template Name is required'
+                        ]
+                    ],
+                    'ticket_type' => [
+                        'rules'  => 'required',
+                        'errors' => [
+                            'required' => 'Policy Type is required'
+                        ]
+                    ],
+                    'trigger_type' => [
+                        'rules'  => 'required',
+                        'errors' => [
+                            'required' => 'Trigger Type is required'
+                        ]
+                    ],
+                    'subject' => [
+                        'rules'  => 'required',
+                        'errors' => [
+                            'required' => 'Subject is required'
+                        ]
+                    ],
+                    'mail_content' => [
+                        'rules'  => 'required',
+                        'errors' => [
+                            'required' => 'Mail Content is required'
+                        ]
+                    ]
+                ];
+                 if (!$this->validate($rules)) {
+                    return $this->response->setStatusCode(400)->setJSON([
+                        'status' => false,
+                        'message' => 'Input validation failed',
+                        'code' => 400,
+                        'errors' => $this->validator->getErrors()
+                    ]);
+                }
+                $data   = $this->request->getPost();
+                $received_data = sanitizeInputArrayAdvanced($data);
+
             if (isset($received_data['id']) && $received_data['id'] != '') {
                 $status = $this->ticketMailTemplateModel->save($received_data);
                 if ($status) {
@@ -3016,6 +3303,70 @@ class TicketController extends BaseController
 
     public function uploadClaimMisFile()
     {
+
+        $filename = '';
+        $fileSize = '';
+
+            //validate uploaded file
+            $validated = $this->validate([
+                'file' => [
+                    'uploaded[file]',
+                    'mime_in[file,application/vnd.ms-excel,application/vnd.openxmlformats-officedocument.spreadsheetml.sheet,application/vnd.oasis.opendocument.spreadsheet]',
+                    'max_size[file,16384]',
+                ],
+            ]);
+            
+            if ($validated) 
+            {
+                    
+                    $file = $this->request->getFile('file');
+                    if (!$file) {
+                        $this->myLogger->logme("error", 'File not found');
+                        return $this->respond(['status' => false, 'code' => 400, 'message' => 'File not found'], 400);
+                    }
+
+                    $is_moved = $file->move(WRITEPATH . 'uploads/claims_mis/');
+                
+                    if ($is_moved) {
+                        $filename = file_Upload_for_lead($file, $file_path);
+                        $fileSize = $file->getSize(); // File size in bytes
+                        $fileSize = $fileSize / (1024 * 1024); // Convert to MB
+
+                        $this->myLogger->logme("error", 'File move successful');
+                        
+                            $request_data   = $this->request->getPost();
+                            $data = sanitizeInputArrayAdvanced($request_data);
+
+                            if(isset($data['from_date']) && !empty($data['from_date'])){
+                                $data['from_date'] = change_date_format($data['from_date'], 'd/m/Y', 'Y-m-d');
+                            }
+
+                            if(isset($data['to_date']) && !empty($data['to_date'])){
+                                $data['to_date'] = change_date_format($data['to_date'], 'd/m/Y', 'Y-m-d');
+                            }
+                            if(!empty($file_name)){
+                                $data['file_name'] = $file;
+                            }
+
+                            $response = $this->claimmisFileModel->insert($data);
+                        
+                            if($response){
+                                return $this->respond(['status'=>true, 'code'=>200, 'message'=>'MIS file uploaded successfully'], 200);
+                            }else{
+                                return $this->respond(['status'=>true, 'code'=>500, 'message'=>'Failed to upload'], 200);
+                            }
+                        
+                    } else {
+                        $this->myLogger->logme("error", 'File move failed');
+                        return $this->respond(['status' => false, 'code' => 500, 'message' => 'File move failed'], 500);
+                    }
+
+            } else {
+                $this->myLogger->logme("error", 'Upload failed Invalid file');
+                return $this->respond(['status' => false, 'code' => 404, 'message' => 'Invalid file'], 404);
+            }
+
+        /*** OLD CODE KEEP it Safe 
         $file = $this->request->getFile('file');
         $data = $this->request->getPost();
 
@@ -3041,6 +3392,7 @@ class TicketController extends BaseController
         }else{
             return $this->respond(['status'=>true, 'code'=>500, 'message'=>'Failed to upload'], 200);
         }
+        ****/
     }
 
     public function downloadClaimMisFile()
diff --git a/app/Controllers/UserController.php b/app/Controllers/UserController.php
index 668144a6..daaadb9f 100755
--- a/app/Controllers/UserController.php
+++ b/app/Controllers/UserController.php
@@ -83,7 +83,114 @@ class UserController extends AdminController
             return redirect()->to(base_url('/user/list'));
         } else {
 
-            $userData = $this->request->getPost();
+            // $userData = $this->request->getPost();
+            $data      = $this->request->getPost();
+            $userData  = sanitizeInputArrayAdvanced($data);
+            $rules = [
+
+                // ======================
+                // Nhance Branch
+                // ======================
+                'nhance_branch_id' => [
+                    'rules'  => 'required|integer',
+                    'errors' => [
+                        'required' => 'Nhance Branch is required',
+                        'integer'  => 'Invalid Nhance Branch selected'
+                    ]
+                ],
+
+                // ======================
+                // Reporting Manager
+                // ======================
+                'rm_id' => [
+                    'rules'  => 'required|integer',
+                    'errors' => [
+                        'required' => 'Reporting Manager is required',
+                        'integer'  => 'Invalid Reporting Manager selected'
+                    ]
+                ],
+
+                // ======================
+                // Employee Code
+                // ======================
+                'emp_code' => [
+                    'rules'  => 'required|alpha_numeric|min_length[3]|max_length[20]|is_unique[user_profiles.emp_code,id,{PrimaryKey}]',
+                    'errors' => [
+                        'required'      => 'Employee Code is required',
+                        'alpha_numeric' => 'Employee Code must be alphanumeric',
+                        'min_length'    => 'Employee Code must be at least 3 characters',
+                        'max_length'    => 'Employee Code cannot exceed 20 characters',
+                        'is_unique'     => 'Employee Code already exists'
+                    ]
+                ],
+
+                // ======================
+                // First Name
+                // ======================
+                'first_name' => [
+                    'rules'  => 'required|alpha_space|min_length[2]|max_length[100]',
+                    'errors' => [
+                        'required'    => 'Name is required',
+                        'alpha_space' => 'Name can contain only letters and spaces',
+                        'min_length'  => 'Name must be at least 2 characters',
+                        'max_length'  => 'Name cannot exceed 100 characters'
+                    ]
+                ],
+
+                // ======================
+                // Email
+                // ======================
+                'email' => [
+                    'rules'  => 'required|valid_email|is_unique[user_profiles.email,id,{PrimaryKey}]',
+                    'errors' => [
+                        'required'    => 'Email is required',
+                        'valid_email' => 'Please enter a valid email address',
+                        'is_unique'   => 'Email already exists'
+                    ]
+                ],
+
+                // ======================
+                // Mobile
+                // ======================
+                'mobile' => [
+                    'rules'  => 'required|regex_match[/^[6-9][0-9]{9}$/]|is_unique[user_profiles.mobile,id,{PrimaryKey}]',
+                    'errors' => [
+                        'required'     => 'Mobile number is required',
+                        'regex_match'  => 'Enter a valid 10-digit mobile number starting with 6, 7, 8, or 9',
+                        'is_unique'    => 'Mobile number already exists'
+                    ]
+                ],
+
+                // ======================
+                // Role
+                // ======================
+                'role' => [
+                    'rules'  => 'required|integer',
+                    'errors' => [
+                        'required' => 'User Role is required',
+                        'integer'  => 'Invalid User Role selected'
+                    ]
+                ],
+
+                // ======================
+                // Team (Multiple select)
+                // ======================
+                'team' => [
+                    'rules'  => 'required',
+                    'errors' => [
+                        'required' => 'At least one User Team must be selected'
+                    ]
+                ],
+            ];
+            if (!$this->validate($rules)) {
+                return $this->response->setStatusCode(400)->setJSON([
+                    'status' => false,
+                    'message' => 'Input validation failed',
+                    'code' => 400,
+                    'errors' => $this->validator->getErrors()
+                ]);
+            }
+
             $userData['created_by'] =  get_session_userid();
             $temp_team = $userData['team'];
             unset($userData['team']);
@@ -167,9 +274,116 @@ class UserController extends AdminController
             return redirect()->to(base_url('/user/list'));
         } else {
             // echo ":/ in 163";
-            $id = $this->request->getPost('PrimaryKey');
-            $teams = $this->request->getPost('team');
-            $userData = $this->request->getPost();
+            $rules = [
+
+                // ======================
+                // Nhance Branch
+                // ======================
+                'nhance_branch_id' => [
+                    'rules'  => 'required|integer',
+                    'errors' => [
+                        'required' => 'Nhance Branch is required',
+                        'integer'  => 'Invalid Nhance Branch selected'
+                    ]
+                ],
+
+                // ======================
+                // Reporting Manager
+                // ======================
+                'rm_id' => [
+                    'rules'  => 'required|integer',
+                    'errors' => [
+                        'required' => 'Reporting Manager is required',
+                        'integer'  => 'Invalid Reporting Manager selected'
+                    ]
+                ],
+
+                // ======================
+                // Employee Code
+                // ======================
+                'emp_code' => [
+                    'rules'  => 'required|alpha_numeric|min_length[3]|max_length[20]|is_unique[user_profiles.emp_code,id,{PrimaryKey}]',
+                    'errors' => [
+                        'required'      => 'Employee Code is required',
+                        'alpha_numeric' => 'Employee Code must be alphanumeric',
+                        'min_length'    => 'Employee Code must be at least 3 characters',
+                        'max_length'    => 'Employee Code cannot exceed 20 characters',
+                        'is_unique'     => 'Employee Code already exists'
+                    ]
+                ],
+
+                // ======================
+                // First Name
+                // ======================
+                'first_name' => [
+                    'rules'  => 'required|alpha_space|min_length[2]|max_length[100]',
+                    'errors' => [
+                        'required'    => 'Name is required',
+                        'alpha_space' => 'Name can contain only letters and spaces',
+                        'min_length'  => 'Name must be at least 2 characters',
+                        'max_length'  => 'Name cannot exceed 100 characters'
+                    ]
+                ],
+
+                // ======================
+                // Email
+                // ======================
+                'email' => [
+                    'rules'  => 'required|valid_email|is_unique[user_profiles.email,id,{PrimaryKey}]',
+                    'errors' => [
+                        'required'    => 'Email is required',
+                        'valid_email' => 'Please enter a valid email address',
+                        'is_unique'   => 'Email already exists'
+                    ]
+                ],
+
+                // ======================
+                // Mobile
+                // ======================
+                'mobile' => [
+                    'rules'  => 'required|regex_match[/^[6-9][0-9]{9}$/]|is_unique[user_profiles.mobile,id,{PrimaryKey}]',
+                    'errors' => [
+                        'required'     => 'Mobile number is required',
+                        'regex_match'  => 'Enter a valid 10-digit mobile number starting with 6, 7, 8, or 9',
+                        'is_unique'    => 'Mobile number already exists'
+                    ]
+                ],
+
+                // ======================
+                // Role
+                // ======================
+                'role' => [
+                    'rules'  => 'required|integer',
+                    'errors' => [
+                        'required' => 'User Role is required',
+                        'integer'  => 'Invalid User Role selected'
+                    ]
+                ],
+
+                // ======================
+                // Team (Multiple select)
+                // ======================
+                'team' => [
+                    'rules'  => 'required',
+                    'errors' => [
+                        'required' => 'At least one User Team must be selected'
+                    ]
+                ],
+            ];
+            if (!$this->validate($rules)) {
+                return $this->response->setStatusCode(400)->setJSON([
+                    'status' => false,
+                    'message' => 'Input validation failed',
+                    'code' => 400,
+                    'errors' => $this->validator->getErrors()
+                ]);
+            }
+            
+            $data      = $this->request->getPost();
+            $userData  = sanitizeInputArrayAdvanced($data);
+            $id = $userData['PrimaryKey'];
+            $teams = $userData['team'];
+            
             unset($userData['csrf_test_name']);
             unset($userData['PrimaryKey']);
 
@@ -594,29 +808,100 @@ class UserController extends AdminController
             
             // add/update
             if ($method === 'post') {
-                $data = $this->request->getPost();
-                $id = !empty($data['PrimaryKey']) ? $data['PrimaryKey'] : null;
+
+                $rules = [
+                    // ======================
+                    // Partner Name
+                    // ======================
+                    'name' => [
+                        'rules'  => 'required|alpha_space|min_length[2]|max_length[100]',
+                        'errors' => [
+                            'required'    => 'Partner name is required',
+                            'alpha_space' => 'Partner name can contain only letters and spaces',
+                            'min_length'  => 'Partner name must be at least 2 characters',
+                            'max_length'  => 'Partner name cannot exceed 100 characters'
+                        ]
+                    ],
+                    // ======================
+                    // Mobile Number
+                    // ======================
+                    'mobile' => [
+                        'rules'  => 'required|regex_match[/^[6-9][0-9]{9}$/]',
+                        'errors' => [
+                            'required'    => 'Mobile number is required',
+                            'regex_match' => 'Enter a valid 10-digit mobile number starting with 6, 7, 8, or 9',
+                        ]
+                    ],
+
+                    // ======================
+                    // Email
+                    // ======================
+                    'email' => [
+                        'rules'  => 'required|valid_email',
+                        'errors' => [
+                            'required'    => 'Email is required',
+                            'valid_email' => 'Please enter a valid email address',
+                        ]
+                    ],
+                    // ======================
+                    // Retention Rate
+                    // ======================
+                     'retention_rate' => [
+        'rules'  => [
+            'required',
+            'regex_match[/^(100(\.0{1,2})?|([0-9]{1,2})(\.[0-9]{1,2})?)$/]'
+        ],
+        'errors' => [
+            'required'    => 'Retention Rate is required',
+            'regex_match' => 'Retention Rate must be between 0 and 100 with up to 2 decimal places'
+        ]
+        ],
+                    // ======================
+                    // Nhance Branch
+                    // ======================
+                    'nhance_branch_id' => [
+                        'rules'  => 'required|integer',
+                        'errors' => [
+                            'required' => 'Nhance Branch is required',
+                            'integer'  => 'Invalid Nhance Branch selected'
+                        ]
+                    ],
+                ];
+                if (! $this->validate($rules)) {
+                return $this->response->setStatusCode(400)->setJSON([
+                    'status'  => false,
+                    'message' => 'Input validation failed',
+                    'code'    => 400,
+                    'errors'  => $this->validator->getErrors()
+                ]);
+            }
+
+
+                $data           = $this->request->getPost();
+                $sanitized_post_data = sanitizeInputArrayAdvanced($data);
+                $id = !empty($sanitized_post_data['PrimaryKey']) ? $sanitized_post_data['PrimaryKey'] : null;
+                unset($sanitized_post_data['pk']); 
                 
                 // don't forgot same means just unset the key because partner_staff some UNIQUE KEY sets in table thats why
                 if ($id) {
                     $existing = $this->partnerStaffModel->find((int)$id);
                     if ($existing) {
-                        if ($data['email'] === $existing['email']) { unset($data['email']); }
-                        if ($data['mobile'] === $existing['mobile']) { unset($data['mobile']); }
+                        if ($sanitized_post_data['email'] === $existing['email']) { unset($sanitized_post_data['email']); }
+                        if ($sanitized_post_data['mobile'] === $existing['mobile']) { unset($sanitized_post_data['mobile']); }
                     }
                 }
 
                 $errors = [];
 
                 // Check Email Duplicate (if it wasn't unset)
-                if (isset($data['email'])) {
-                    $count = $this->partnerStaffModel->where('email', $data['email'])->countAllResults();
+                if (isset($sanitized_post_data['email'])) {
+                    $count = $this->partnerStaffModel->where('email', $sanitized_post_data['email'])->countAllResults();
                     if ($count > 0) $errors['email'] = "This email is already taken by another user.";
                 }
 
                 // Check Mobile Duplicate (if it wasn't unset)
-                if (isset($data['mobile'])) {
-                    $count = $this->partnerStaffModel->where('mobile', $data['mobile'])->countAllResults();
+                if (isset($sanitized_post_data['mobile'])) {
+                    $count = $this->partnerStaffModel->where('mobile', $sanitized_post_data['mobile'])->countAllResults();
                     if ($count > 0) $errors['mobile'] = "This mobile is already taken by another user.";
                 }
 
@@ -632,14 +917,14 @@ class UserController extends AdminController
                 // --- Save/Update ---
                 if ($id) {
                     $text   = "update";            
-                    $data['updated_by'] =  get_session_userid();
+                    $sanitized_post_data['updated_by'] =  get_session_userid();
                     
-                    $result = $this->partnerStaffModel->update($id, $data);
+                    $result = $this->partnerStaffModel->update($id, $sanitized_post_data);
                 } else {
                     $text = "create";
-                    $data['role_id'] = 1;
-                    $data['created_by'] = get_session_userid();
-                    $id = $this->partnerStaffModel->insert($data);
+                    $sanitized_post_data['role_id'] = 1;
+                    $sanitized_post_data['created_by'] = get_session_userid();
+                    $id = $this->partnerStaffModel->insert($sanitized_post_data);
                     if($id){
                         $details['manager_id'] = $id;
                         $details['updated_by'] =  get_session_userid();
diff --git a/app/Controllers/VidalApiController.php b/app/Controllers/VidalApiController.php
index a6c45242..0c0bc293 100644
--- a/app/Controllers/VidalApiController.php
+++ b/app/Controllers/VidalApiController.php
@@ -112,7 +112,7 @@ class VidalApiController extends BaseController
         ];
     }
 
-    public function  SubmitClaim ($claimId = 515)
+    public function  SubmitClaim ($claimId = null) //515
     {
         helper('api');
 
diff --git a/app/Filters/AuthMVC.php b/app/Filters/AuthMVC.php
index efda2976..e5826b6b 100755
--- a/app/Filters/AuthMVC.php
+++ b/app/Filters/AuthMVC.php
@@ -23,10 +23,8 @@ class AuthMVC implements FilterInterface
         // }
 
         // Fingerprint validation
-        $fp = hash('sha256', 
-            $request->getUserAgent()->getAgentString() . '|' . $request->getIPAddress()
-        );
-
+        $fp = generateFingerprint()
+        // log_message('error',$fp);
         if (session()->get('fingerprint') !== $fp) {
             return AuthLogout::logout();
         }
diff --git a/app/Helpers/JWTToken.php b/app/Helpers/JWTToken.php
index 73978ddb..311182d4 100755
--- a/app/Helpers/JWTToken.php
+++ b/app/Helpers/JWTToken.php
@@ -38,6 +38,7 @@ class JWTToken
            
             }else{
                 $models = new LevelContactModel();
+                $id = $request_data['post_hr_id'];
                 $models->update($id, $data);
 
             }
diff --git a/app/Helpers/utility_helper.php b/app/Helpers/utility_helper.php
index 5295224b..9e7f4791 100755
--- a/app/Helpers/utility_helper.php
+++ b/app/Helpers/utility_helper.php
@@ -1036,3 +1036,34 @@ if (!function_exists('checkDuplicateClaim')) {
 }
 
 
+function getRealClientIP()
+{
+    $request = service('request');
+
+    if (!empty($_SERVER['HTTP_CF_CONNECTING_IP'])) {
+        return $_SERVER['HTTP_CF_CONNECTING_IP'];
+    }
+
+    if (!empty($_SERVER['HTTP_X_FORWARDED_FOR'])) {
+        return explode(',', $_SERVER['HTTP_X_FORWARDED_FOR'])[0];
+    }
+
+    return $request->getIPAddress();
+}
+
+function generateFingerprint()
+{
+    $request = service('request');
+
+    $ua = $request->getUserAgent()->getAgentString();
+    $ip = getRealClientIP();
+
+    // Use only subnet (first 3 blocks) to tolerate IP change
+    $ipParts = explode('.', $ip);
+    $ipSubnet = $ipParts[0] . '.' . $ipParts[1] . '.' . $ipParts[2];
+
+    // $secret = env('app.sessionFingerprintSalt');
+
+    // return hash('sha256', $ua . '|' . $ipSubnet . '|' . $secret);
+    return hash('sha256', $ua . '|' . $ipSubnet );
+}
diff --git a/app/Views/UserList.php b/app/Views/UserList.php
index e1f0f127..28cde270 100755
--- a/app/Views/UserList.php
+++ b/app/Views/UserList.php
@@ -684,7 +684,7 @@ table.dataTable tbody td {
                             
- +
@@ -1134,6 +1134,16 @@ table.dataTable tbody td { console.error("Response Headers:", xhr.getAllResponseHeaders()); console.error("Error Thrown:", error); console.error("Status:", status); + if (xhr.status === 400) { + let response = JSON.parse(xhr.responseText); + if (response.errors) { + $.each(response.errors, function (field, message) { + toastr.warning(message, 'Validation Error'); + }); + } else { + toastr.warning(response.message || 'Validation failed', 'Warning'); + } + }else{toastr.error('Server error occurred.', 'Error');} } }); @@ -1333,7 +1343,16 @@ table.dataTable tbody td { }, error: function(xhr) { console.log("Error: " + xhr.statusText); - toastr.error('Server error occurred.', 'Error'); + if (xhr.status === 400) { + let response = JSON.parse(xhr.responseText); + if (response.errors) { + $.each(response.errors, function (field, message) { + toastr.warning(message, 'Validation Error'); + }); + } else { + toastr.warning(response.message || 'Validation failed', 'Warning'); + } + }else{toastr.error('Server error occurred.', 'Error');} }, complete: function() { btn.disabled = false; @@ -1395,6 +1414,16 @@ table.dataTable tbody td { error: function(xhr) { console.log("Error: " + xhr.statusText); toastr.error('Server error occurred.', 'Error'); + if (xhr.status === 400) { + let response = JSON.parse(xhr.responseText); + if (response.errors) { + $.each(response.errors, function (field, message) { + toastr.warning(message, 'Validation Error'); + }); + } else { + toastr.warning(response.message || 'Validation failed', 'Warning'); + } + }else{toastr.error('Server error occurred.', 'Error');} }, complete: function() { btn.disabled = false; diff --git a/app/Views/add_image_list.php b/app/Views/add_image_list.php index a69924ea..c91db897 100755 --- a/app/Views/add_image_list.php +++ b/app/Views/add_image_list.php @@ -126,7 +126,7 @@ table.dataTable thead th {
- +
@@ -227,7 +227,15 @@ table.dataTable thead th { switch (xhr.status) { case 400: - msg = xhr.responseJSON?.message || 'Bad Request — Invalid input.'; + let response = xhr.responseJSON || JSON.parse(xhr.responseText); + if (response.errors) { + $.each(response.errors, function (field, message) { + toastr.warning(message, 'Validation Error'); + }); + } else { + toastr.warning(response.message || 'Validation failed', 'Warning'); + } + msg = response.message || 'Bad Request — Invalid input.'; break; case 401: msg = 'Unauthorized — Please log in again.'; diff --git a/app/Views/bds_dump_file_list.php b/app/Views/bds_dump_file_list.php index 2c243dcd..bd6e23ff 100644 --- a/app/Views/bds_dump_file_list.php +++ b/app/Views/bds_dump_file_list.php @@ -197,6 +197,14 @@ // Handle error response console.error('Upload failed:', error); console.error('Upload failed:', error); + if (xhr.status === 400) { + var response = JSON.parse(xhr.responseText); + toastr.warning(response.message || 'Validation failed', 'Warning'); + } + if (xhr.status === 500) { + var response = JSON.parse(xhr.responseText); + toastr.warning(response.message || 'Validation failed', 'Warning'); + } }, complete: function() { // Reset button state diff --git a/app/Views/cd_master_add_modal.php b/app/Views/cd_master_add_modal.php index 9089d35f..84de0dd8 100644 --- a/app/Views/cd_master_add_modal.php +++ b/app/Views/cd_master_add_modal.php @@ -204,6 +204,16 @@ console.error(status, error); $('.loader').fadeOut(); $('.loader-mask').delay(350).fadeOut('slow'); + if (xhr.status === 400) { + let response = JSON.parse(xhr.responseText); + if (response.errors) { + $.each(response.errors, function (field, message) { + toastr.warning(message, 'Validation Error'); + }); + } else { + toastr.warning(response.message || 'Validation failed', 'Warning'); + } + } toastr.error('An error occurred while adding the CD account number.', 'ERROR'); } }); diff --git a/app/Views/claim_mis_file_list.php b/app/Views/claim_mis_file_list.php index 4ce6d111..fc636bcb 100644 --- a/app/Views/claim_mis_file_list.php +++ b/app/Views/claim_mis_file_list.php @@ -236,6 +236,14 @@ // Handle error response console.error('Upload failed:', error); console.error('Upload failed:', error); + if (xhr.status === 400) { + var response = JSON.parse(xhr.responseText); + toastr.warning(response.message || 'Validation failed', 'Warning'); + } + if (xhr.status === 500) { + var response = JSON.parse(xhr.responseText); + toastr.warning(response.message || 'Validation failed', 'Warning'); + } }, complete: function() { // Reset button state diff --git a/app/Views/client_basic_info.php b/app/Views/client_basic_info.php index f3ac5144..625efc1e 100755 --- a/app/Views/client_basic_info.php +++ b/app/Views/client_basic_info.php @@ -81,7 +81,7 @@ input:checked + .slider:before { style="border-radius:25px; border:1px solid #00999E;padding:10px;color:#00999E;" alt="avatar"/> -
+
( Image dimensions 100 x 100 pixels and size of 200KB. )

@@ -324,7 +324,7 @@ input:checked + .slider:before { $.each(res.data, function (index, item) { var row = ` ${item.file_name} -
+ @@ -349,7 +349,16 @@ input:checked + .slider:before { $('.loader').fadeOut(); $('.loader-mask').delay(350).fadeOut('slow'); $submitButton.prop('disabled', false); - if (xhr.status === 404) { + if (xhr.status === 400) { + let response = JSON.parse(xhr.responseText); + if (response.errors) { + $.each(response.errors, function (field, message) { + toastr.warning(message, 'Validation Error'); + }); + } else { + toastr.warning(response.message || 'Validation failed', 'Warning'); + } + } else if (xhr.status === 404) { toastr.warning('Resource not found', 'Warning'); } else if (xhr.status === 500) { toastr.warning('Internal server error', 'Warning'); diff --git a/app/Views/client_branch.php b/app/Views/client_branch.php index 01ff9597..99ddb30f 100755 --- a/app/Views/client_branch.php +++ b/app/Views/client_branch.php @@ -281,7 +281,7 @@ $(document).ready(function() { `; } - + }); $('#branch_list').append(branchTable); } diff --git a/app/Views/client_kyc.php b/app/Views/client_kyc.php index e68543e2..f2d9adac 100755 --- a/app/Views/client_kyc.php +++ b/app/Views/client_kyc.php @@ -304,7 +304,8 @@ ${item.file_name} - + diff --git a/app/Views/client_kyc_2.php b/app/Views/client_kyc_2.php index 5032e615..28e22522 100755 --- a/app/Views/client_kyc_2.php +++ b/app/Views/client_kyc_2.php @@ -36,6 +36,7 @@
diff --git a/app/Views/client_kyc_other_table.php b/app/Views/client_kyc_other_table.php index 04bcce83..119c7831 100644 --- a/app/Views/client_kyc_other_table.php +++ b/app/Views/client_kyc_other_table.php @@ -4,7 +4,7 @@ - + diff --git a/app/Views/client_kyc_primary_table.php b/app/Views/client_kyc_primary_table.php index 4373a373..20317d97 100644 --- a/app/Views/client_kyc_primary_table.php +++ b/app/Views/client_kyc_primary_table.php @@ -7,7 +7,7 @@ - + diff --git a/app/Views/client_kyc_single_table.php b/app/Views/client_kyc_single_table.php index 58d1b68c..0b67be02 100644 --- a/app/Views/client_kyc_single_table.php +++ b/app/Views/client_kyc_single_table.php @@ -48,6 +48,7 @@ name="file_name" id="kyc_docs_file_" class="form-control edit-file-input" + accept=".pdf,.jpg,.jpeg,.png" style="box-shadow:none!important; outline:none!important; border:none; height:unset!important;padding: 0px !important;background: transparent !important;"> diff --git a/app/Views/client_policy.php b/app/Views/client_policy.php index 88e2300e..c558e0e1 100755 --- a/app/Views/client_policy.php +++ b/app/Views/client_policy.php @@ -832,7 +832,16 @@ input:checked + .slider_blue::before { setTimeout(function() { $('.loader').fadeOut(); $('.loader-mask').delay(350).fadeOut('slow'); - if (xhr.status === 404) { + if (xhr.status === 400) { + let response = JSON.parse(xhr.responseText); + if (response.errors) { + $.each(response.errors, function (field, message) { + toastr.warning(message, 'Validation Error'); + }); + } else { + toastr.warning(response.message || 'Validation failed', 'Warning'); + } + } else if (xhr.status === 404) { //console.log('Resource not found', 'Warning'); } else if (xhr.status === 500) { //console.log('Internal server error', 'Warning'); diff --git a/app/Views/employee_data_list.php b/app/Views/employee_data_list.php index 517adfa5..fb404134 100755 --- a/app/Views/employee_data_list.php +++ b/app/Views/employee_data_list.php @@ -548,8 +548,16 @@ console.error('Response Text: ', xhr.responseText); } - toastr.warning('Error uploading file', 'WARNING'); - console.error('Upload error:', error); + if (xhr.status === 400) { + let response = JSON.parse(xhr.responseText); + if (response.errors) { + $.each(response.errors, function (field, message) { + toastr.warning(message, 'Validation Error'); + }); + } else { + toastr.warning(response.message || 'Validation failed', 'Warning'); + } + }else{ toastr.warning('Error uploading file', 'WARNING'); } }, complete: function() { $('.loader').fadeOut(); diff --git a/app/Views/faq_list.php b/app/Views/faq_list.php index 9a4d6d8c..4c095b0c 100644 --- a/app/Views/faq_list.php +++ b/app/Views/faq_list.php @@ -326,6 +326,18 @@ }, error: function () { $('.loader, .loader-mask').fadeOut(); + if (xhr.status === 400) { + let response = JSON.parse(xhr.responseText); + if (response.errors) { + $.each(response.errors, function (field, message) { + toastr.warning(message, 'Validation Error'); + }); + } else { + toastr.warning(response.message || 'Validation failed', 'Warning'); + } + }else{ + toastr.error("Something went wrong!", 'Error'); + } } }); } diff --git a/app/Views/frontend_content_list.php b/app/Views/frontend_content_list.php index ce3db484..c88484f3 100644 --- a/app/Views/frontend_content_list.php +++ b/app/Views/frontend_content_list.php @@ -449,7 +449,18 @@ }, error: function () { $('.loader, .loader-mask').fadeOut(); - } + if (xhr.status === 400) { + let response = JSON.parse(xhr.responseText); + if (response.errors) { + $.each(response.errors, function (field, message) { + toastr.warning(message, 'Validation Error'); + }); + } else { + toastr.warning(response.message || 'Validation failed', 'Warning'); + } + }else{ + toastr.error("Something went wrong!", 'Error'); + } }); } diff --git a/app/Views/insurer_basic_info.php b/app/Views/insurer_basic_info.php index f7834580..aadc43d3 100755 --- a/app/Views/insurer_basic_info.php +++ b/app/Views/insurer_basic_info.php @@ -254,6 +254,16 @@ input:checked + .slider:before { $('.loader').fadeOut(); $('.loader-mask').delay(350).fadeOut('slow'); console.log('Something Wrong!', 'warning'); + if (xhr.status === 400) { + let response = JSON.parse(xhr.responseText); + if (response.errors) { + $.each(response.errors, function (field, message) { + toastr.warning(message, 'Validation Error'); + }); + } else { + toastr.warning(response.message || 'Validation failed', 'Warning'); + } + } } }); } diff --git a/app/Views/insurer_export_templete.php b/app/Views/insurer_export_templete.php index a92543a4..81f6fba6 100755 --- a/app/Views/insurer_export_templete.php +++ b/app/Views/insurer_export_templete.php @@ -305,7 +305,7 @@ window.location.reload(); }, - error: function(xhr, status, error) { + error: function (xhr, status, error) { $('.loader').fadeOut(); $('.loader-mask').delay(350).fadeOut('slow'); @@ -323,14 +323,37 @@ console.error('Response headers:', xhr.getAllResponseHeaders()); console.error('Response URL:', xhr.responseURL); - // Example of throwing a detailed error for further handling - throw new Error(`AJAX Request failed: - Status: ${status}, - Error: ${error}, - Status Code: ${xhr.status}, - Status Text: ${xhr.statusText}, - Response: ${xhr.responseText} - `); + // Handle validation errors (CI4) + if (xhr.status === 400) { + + let response = null; + + try { + response = JSON.parse(xhr.responseText); + } catch (e) { + toastr.error('Invalid server response', 'Error'); + return; + } + + if (response.errors) { + $.each(response.errors, function (field, message) { + toastr.warning(message, 'Validation Error'); + }); + } else { + toastr.warning(response.message || 'Validation failed', 'Warning'); + } + + return; + } + + // Handle server errors + if (xhr.status >= 500) { + toastr.error('Server error. Please try again later.', 'Error'); + return; + } + + // Fallback + toastr.error('Unexpected error occurred.', 'Error'); }, complete: function() { $('.loader').fadeOut(); diff --git a/app/Views/kyc_docs.php b/app/Views/kyc_docs.php index 8b9a703c..3c6631e5 100755 --- a/app/Views/kyc_docs.php +++ b/app/Views/kyc_docs.php @@ -254,6 +254,16 @@ $(document).ready(function () { setTimeout(function() { $('.loader').fadeOut(); $('.loader-mask').delay(350).fadeOut('slow'); + if (xhr.status === 400) { + let response = JSON.parse(xhr.responseText); + if (response.errors) { + $.each(response.errors, function (field, message) { + toastr.warning(message, 'Validation Error'); + }); + } else { + toastr.warning(response.message || 'Validation failed', 'Warning'); + } + } toastr.warning('Something Wrong!', 'warning'); }, 1000); } @@ -296,6 +306,16 @@ $(document).ready(function () { setTimeout(function() { $('.loader').fadeOut(); $('.loader-mask').delay(350).fadeOut('slow'); + if (xhr.status === 400) { + let response = JSON.parse(xhr.responseText); + if (response.errors) { + $.each(response.errors, function (field, message) { + toastr.warning(message, 'Validation Error'); + }); + } else { + toastr.warning(response.message || 'Validation failed', 'Warning'); + } + } toastr.warning('Something Wrong!', 'warning'); }, 1000); } diff --git a/app/Views/leads_form.php b/app/Views/leads_form.php index 52902934..364a2da4 100644 --- a/app/Views/leads_form.php +++ b/app/Views/leads_form.php @@ -1646,7 +1646,7 @@ console.log('Form is Empty', 'Warning'); return; } - + var salse_person_id = $("#salse_person_id").val(); console.log('salse_person_id : ', salse_person_id); @@ -1701,6 +1701,16 @@ console.error(status, error); $('.loader').fadeOut(); $('.loader-mask').delay(350).fadeOut('slow'); + if (xhr.status === 400) { + let response = JSON.parse(xhr.responseText); + if (response.errors) { + $.each(response.errors, function (field, message) { + toastr.warning(message, 'Validation Error'); + }); + } else { + toastr.warning(response.message || 'Validation failed', 'Warning'); + } + } } }); }); diff --git a/app/Views/leads_form_handler.php b/app/Views/leads_form_handler.php index 563c5933..10924bf5 100644 --- a/app/Views/leads_form_handler.php +++ b/app/Views/leads_form_handler.php @@ -553,7 +553,7 @@ if (isset($selected_lead_type)) { let isFirstField = container.childElementCount === 0; // Check if it's the first field let placeholder = isFirstField ? 'First file must be Demography.' : ''; - let accept = isFirstField ? '.xls,.xlsx' : ''; + let accept = isFirstField ? '.xls,.xlsx' : '.xls,.xlsx,.pdf,.jpg,.jpeg,.png'; if(selected_lead_form_type != 1){ diff --git a/app/Views/leads_non_eb.php b/app/Views/leads_non_eb.php index df5d5a9a..2f59fe29 100644 --- a/app/Views/leads_non_eb.php +++ b/app/Views/leads_non_eb.php @@ -628,6 +628,16 @@ console.error(status, error); $('.loader').fadeOut(); $('.loader-mask').delay(350).fadeOut('slow'); + if (xhr.status === 400) { + let response = JSON.parse(xhr.responseText); + if (response.errors) { + $.each(response.errors, function (field, message) { + toastr.warning(message, 'Validation Error'); + }); + } else { + toastr.warning(response.message || 'Validation failed', 'Warning'); + } + } } }); }); diff --git a/app/Views/nhance_branch_list.php b/app/Views/nhance_branch_list.php index 29700edd..11725ff2 100644 --- a/app/Views/nhance_branch_list.php +++ b/app/Views/nhance_branch_list.php @@ -283,6 +283,16 @@ console.error(xhr.responseText); $('.loader').fadeOut(); $('.loader-mask').delay(350).fadeOut('slow'); + if (xhr.status === 400) { + let response = JSON.parse(xhr.responseText); + if (response.errors) { + $.each(response.errors, function (field, message) { + toastr.warning(message, 'Validation Error'); + }); + } else { + toastr.warning(response.message || 'Validation failed', 'Warning'); + } + } }); } diff --git a/app/Views/policy_transaction_inception_list.php b/app/Views/policy_transaction_inception_list.php index 14e54f2b..37166f8a 100644 --- a/app/Views/policy_transaction_inception_list.php +++ b/app/Views/policy_transaction_inception_list.php @@ -1030,7 +1030,7 @@ function addHTMLInput(data = null, container_id = 'dynamic-form-container')
- +
x @@ -1216,7 +1216,7 @@ function addHTMLInputForVehicleFileUpload(data = null, container_id = 'dynamic-f
- +
x diff --git a/app/Views/policy_transaction_inception_list_2.php b/app/Views/policy_transaction_inception_list_2.php index 99ef4eb2..c7172902 100644 --- a/app/Views/policy_transaction_inception_list_2.php +++ b/app/Views/policy_transaction_inception_list_2.php @@ -1013,7 +1013,7 @@ function addHTMLInput(data = null)
- +
x @@ -1192,7 +1192,7 @@ function addHTMLInputForVehicleFileUpload(data = null)
- +
x diff --git a/app/Views/pos_list.php b/app/Views/pos_list.php index 2c1c1af5..d94e45c2 100644 --- a/app/Views/pos_list.php +++ b/app/Views/pos_list.php @@ -175,21 +175,21 @@
- +
- +
- +
@@ -363,6 +363,16 @@ }, error: function () { $('.loader, .loader-mask').fadeOut(); + if (xhr.status === 400) { + let response = JSON.parse(xhr.responseText); + if (response.errors) { + $.each(response.errors, function (field, message) { + toastr.warning(message, 'Validation Error'); + }); + } else { + toastr.warning(response.message || 'Validation failed', 'Warning'); + } + } } }); } diff --git a/app/Views/retail_endorsement_list.php b/app/Views/retail_endorsement_list.php index d01de408..97a163a3 100755 --- a/app/Views/retail_endorsement_list.php +++ b/app/Views/retail_endorsement_list.php @@ -312,6 +312,16 @@ error: function(xhr) { toastr.error("Something went wrong!", 'Error'); console.error(xhr.responseText); + if (xhr.status === 400) { + let response = JSON.parse(xhr.responseText); + if (response.errors) { + $.each(response.errors, function (field, message) { + toastr.warning(message, 'Validation Error'); + }); + } else { + toastr.warning(response.message || 'Validation failed', 'Warning'); + } + } }, complete: function() { btn.disabled = false; diff --git a/app/Views/rfq/multi_files.php b/app/Views/rfq/multi_files.php index 09ba89ab..bea6da48 100644 --- a/app/Views/rfq/multi_files.php +++ b/app/Views/rfq/multi_files.php @@ -7,7 +7,7 @@ $increment = 1; foreach ($lead_edit_data["multi_file_data"] as $index => $value) { $isFirstField = ($index === 0); $placeholder = $isFirstField ? 'First file must be Demography.' : ''; - $accept = $isFirstField ? '.xls,.xlsx' : ''; + $accept = $isFirstField ? '.xls,.xlsx' : '.xls,.xlsx,.pdf,.jpg,.jpeg,.png'; $displayIndex = $index + 1; ?> diff --git a/app/Views/rto_master_list.php b/app/Views/rto_master_list.php index f95d688b..3c8c912a 100644 --- a/app/Views/rto_master_list.php +++ b/app/Views/rto_master_list.php @@ -243,6 +243,16 @@ console.error(xhr.responseText); $('.loader').fadeOut(); $('.loader-mask').delay(350).fadeOut('slow'); + if (xhr.status === 400) { + let response = JSON.parse(xhr.responseText); + if (response.errors) { + $.each(response.errors, function (field, message) { + toastr.warning(message, 'Validation Error'); + }); + } else { + toastr.warning(response.message || 'Validation failed', 'Warning'); + } + } }); } diff --git a/app/Views/test_members_list.php b/app/Views/test_members_list.php index 4f880091..b09c362d 100644 --- a/app/Views/test_members_list.php +++ b/app/Views/test_members_list.php @@ -715,8 +715,19 @@ document.addEventListener("DOMContentLoaded", function () { console.error('Response Text: ', xhr.responseText); } - toastr.warning('Error uploading file', 'WARNING'); - console.error('Upload error:', error); + if (xhr.status === 400) { + let response = JSON.parse(xhr.responseText); + if (response.errors) { + $.each(response.errors, function (field, message) { + toastr.warning(message, 'Validation Error'); + }); + } else { + toastr.warning(response.message || 'Validation failed', 'Warning'); + } + }else{ toastr.warning('Error uploading file', 'WARNING'); } + + // toastr.warning('Error uploading file', 'WARNING'); + // console.error('Upload error:', error); }, complete: function() { $('.loader').fadeOut(); diff --git a/app/Views/thz_list.php b/app/Views/thz_list.php index dde7ad77..84d8f4cf 100644 --- a/app/Views/thz_list.php +++ b/app/Views/thz_list.php @@ -506,7 +506,17 @@ beccause = dataTables_length and dataTables_paginate need in same line thats why } }, error: function(xhr) { - toastr.error("Something went wrong!", 'Error'); + if (xhr.status === 400) { + let response = JSON.parse(xhr.responseText); + if (response.errors) { + $.each(response.errors, function (field, message) { + toastr.warning(message, 'Validation Error'); + }); + } else { + toastr.warning(response.message || 'Validation failed', 'Warning'); + } + }else{ + toastr.error("Something went wrong!", 'Error');} console.error(xhr.responseText); }, complete: function() { diff --git a/app/Views/thz_notes.php b/app/Views/thz_notes.php index 959a1633..91c916b8 100644 --- a/app/Views/thz_notes.php +++ b/app/Views/thz_notes.php @@ -571,7 +571,16 @@ data-backdrop="static" } }, error: function(xhr) { - toastr.error("Something went wrong!", 'Error'); + if (xhr.status === 400) { + let response = JSON.parse(xhr.responseText); + if (response.errors) { + $.each(response.errors, function (field, message) { + toastr.warning(message, 'Validation Error'); + }); + } else { + toastr.warning(response.message || 'Validation failed', 'Warning'); + } + }else{ toastr.error("Something went wrong!", 'Error'); } console.error(xhr.responseText); }, complete: function() { @@ -619,8 +628,19 @@ data-backdrop="static" } }, error: function(xhr) { - toastr.error("Something went wrong!", 'Error'); - console.error(xhr.responseText); + if (xhr.status === 400) { + let response = JSON.parse(xhr.responseText); + if (response.errors) { + $.each(response.errors, function (field, message) { + toastr.warning(message, 'Validation Error'); + }); + } else { + toastr.warning(response.message || 'Validation failed', 'Warning'); + } + }else{ + toastr.error("Something went wrong!", 'Error'); + console.error(xhr.responseText); + } }, complete: function() { btn.disabled = false;} }); diff --git a/app/Views/ticket_mail_template.php b/app/Views/ticket_mail_template.php index e55956db..9cda359e 100644 --- a/app/Views/ticket_mail_template.php +++ b/app/Views/ticket_mail_template.php @@ -434,7 +434,16 @@ setTimeout(function() { $('.loader').fadeOut(); $('.loader-mask').delay(350).fadeOut('slow'); - toastr.error('Something Wrong!', 'warning'); + if (xhr.status === 400) { + let response = JSON.parse(xhr.responseText); + if (response.errors) { + $.each(response.errors, function (field, message) { + toastr.warning(message, 'Validation Error'); + }); + } else { + toastr.warning(response.message || 'Validation failed', 'Warning'); + } + } else{toastr.error('Something Wrong!', 'warning');} }, 1000); } }); diff --git a/app/Views/tpa_basic_info.php b/app/Views/tpa_basic_info.php index 9830c520..b0ee3724 100755 --- a/app/Views/tpa_basic_info.php +++ b/app/Views/tpa_basic_info.php @@ -328,6 +328,17 @@ $('.loader').fadeOut(); $('.loader-mask').delay(350).fadeOut('slow'); console.log('Something Wrong!', 'warning'); + // Handle validation errors (CI4) + if (xhr.status === 400) { + let response = JSON.parse(xhr.responseText); + if (response.errors) { + $.each(response.errors, function (field, message) { + toastr.warning(message, 'Validation Error'); + }); + } else { + toastr.warning(response.message || 'Validation failed', 'Warning'); + } + } }, 1000); } }); diff --git a/app/Views/tpa_branch.php b/app/Views/tpa_branch.php index 4237421b..d3da93aa 100755 --- a/app/Views/tpa_branch.php +++ b/app/Views/tpa_branch.php @@ -478,6 +478,16 @@ $(document).ready(function () { setTimeout(function() { $('.loader').fadeOut(); $('.loader-mask').delay(350).fadeOut('slow'); + if (xhr.status === 400) { + let response = JSON.parse(xhr.responseText); + if (response.errors) { + $.each(response.errors, function (field, message) { + toastr.warning(message, 'Validation Error'); + }); + } else { + toastr.warning(response.message || 'Validation failed', 'Warning'); + } + } toastr.warning('Something Wrong!', 'warning'); }, 1000); }, diff --git a/app/Views/vehicle_details.php b/app/Views/vehicle_details.php index df98d9d2..f4bb4e27 100644 --- a/app/Views/vehicle_details.php +++ b/app/Views/vehicle_details.php @@ -222,7 +222,7 @@ $(document).ready(function() { $.each(res.data, function(index, item) { var row = ` ${item.file_name} - + @@ -247,7 +247,16 @@ $(document).ready(function() { $('.loader').fadeOut(); $('.loader-mask').delay(350).fadeOut('slow'); $submitButton.prop('disabled', false); - if (xhr.status === 404) { + if (xhr.status === 400) { + let response = JSON.parse(xhr.responseText); + if (response.errors) { + $.each(response.errors, function (field, message) { + toastr.warning(message, 'Validation Error'); + }); + } else { + toastr.warning(response.message || 'Validation failed', 'Warning'); + } + } else if (xhr.status === 404) { toastr.warning('Resource not found', 'Warning'); } else if (xhr.status === 500) { toastr.warning('Internal server error', 'Warning'); diff --git a/app/Views/vehicle_master_list.php b/app/Views/vehicle_master_list.php index f4b29f8e..b153b534 100644 --- a/app/Views/vehicle_master_list.php +++ b/app/Views/vehicle_master_list.php @@ -787,6 +787,16 @@ $("#vehicle_form").submit(function(event) { console.error(status, error); $('.loader').fadeOut(); $('.loader-mask').delay(350).fadeOut('slow'); + if (xhr.status === 400) { + let response = JSON.parse(xhr.responseText); + if (response.errors) { + $.each(response.errors, function (field, message) { + toastr.warning(message, 'Validation Error'); + }); + } else { + toastr.warning(response.message || 'Validation failed', 'Warning'); + } + } } }); }); diff --git a/app/Views/vehicle_type_list.php b/app/Views/vehicle_type_list.php index 4c7bbb09..53456a0f 100644 --- a/app/Views/vehicle_type_list.php +++ b/app/Views/vehicle_type_list.php @@ -581,7 +581,7 @@
- +
diff --git a/app/Views/vehicle_type_master_list.php b/app/Views/vehicle_type_master_list.php index a2001b8c..984f4ecc 100755 --- a/app/Views/vehicle_type_master_list.php +++ b/app/Views/vehicle_type_master_list.php @@ -222,6 +222,16 @@ console.error(xhr.responseText); $('.loader').fadeOut(); $('.loader-mask').delay(350).fadeOut('slow'); + if (xhr.status === 400) { + let response = JSON.parse(xhr.responseText); + if (response.errors) { + $.each(response.errors, function (field, message) { + toastr.warning(message, 'Validation Error'); + }); + } else { + toastr.warning(response.message || 'Validation failed', 'Warning'); + } + } }); } diff --git a/app/Views/view_rfq.php b/app/Views/view_rfq.php index 01d8aed9..5d332d35 100644 --- a/app/Views/view_rfq.php +++ b/app/Views/view_rfq.php @@ -7345,7 +7345,7 @@ function appendMultiFileData(data) { let isFirstField = container.childElementCount === 0; // Check if it's the first field let placeholder = isFirstField ? 'First file must be Demography.' : ''; - let accept = isFirstField ? '.xls,.xlsx' : ''; + let accept = isFirstField ? '.xls,.xlsx' : '.xls,.xlsx,.pdf,.jpg,.jpeg,.png'; if(isFirstField == 1){