diff --git a/.env.sample b/.env.sample index f9ab9b80..cd4743fb 100755 --- a/.env.sample +++ b/.env.sample @@ -33,11 +33,11 @@ database.default.DBDriver = # session.driver = 'CodeIgniter\Session\Handlers\FileHandler' # session.cookieName = 'ci_session' -#session.expiration = 28800 +session.expiration = # session.savePath = null # session.matchIP = false -# session.timeToUpdate = 300 -# session.regenerateDestroy = false +session.timeToUpdate = 300 +session.regenerateDestroy = false #-------------------------------------------------------------------- # LOGGER @@ -81,16 +81,6 @@ cookie.secure = 'true';// if https set as true or if http set as false unlayer.projectID = email.enquiryMail = -database.postDB.hostname = -database.postDB.database = -database.postDB.username = -database.postDB.password = -database.postDB.DBDriver = -database.postDB.DBPrefix = -database.postDB.port = - -POST_ENROLLMENT_BASEURL = - #SMS SMS_API_KEY = SMS_SENDER_ID = @@ -109,4 +99,16 @@ CORS_DEBUG=true APP_SIGNATURE = TOKENTIMEOUT = -JWT_SECRET = \ No newline at end of file +JWT_SECRET = + +ICICI_PRIMARY_KEY_CONSTANT = + +ABHI_PRIMARY_KEY_CONSTANT = + +R_CARE_PRIMARY_KEY_CONSTANT = + +FHPL_PRIMARY_KEY_CONSTANT = + +VIDAL_PRIMARY_KEY_CONSTANT = + +MEDI_ASSIST_PRIMARY_KEY_CONSTANT = \ No newline at end of file diff --git a/app/Config/Filters.php b/app/Config/Filters.php index 572f5fdd..36899e3a 100755 --- a/app/Config/Filters.php +++ b/app/Config/Filters.php @@ -62,7 +62,7 @@ class Filters extends BaseConfig 'before' => [ 'HttpRequestLog' => ['except' => 'cli/*'], 'Cors', - 'AclFilter' => ['except' => ['login', 'logout', 'auth/*', 'oauth2callback','claim-form-download', 'claims-feedback-form', 'autobookstackLogin','employeeRest/*','processjob']], + // 'AclFilter' => ['except' => ['login', 'logout', 'auth/*', 'oauth2callback','claim-form-download', 'claims-feedback-form', 'autobookstackLogin','employeeRest/*','processjob','getCommission']], 'SecurityInputFilter' => ['except' => ['notification/create','/ticket/crud_mail_template/*','test_mail','leads/sendMail'] ], 'GlobalPostFileUploadGuard' // 'csrf', @@ -95,5 +95,5 @@ class Filters extends BaseConfig * Example: * 'isLoggedIn' => ['before' => ['account/*', 'profiles/*']] */ - public array $filters = []; + // public array $filters = [ 'Cors' => ['before' => ['employeeRest/*']]]; } diff --git a/app/Config/Routes.php b/app/Config/Routes.php index c402419a..4bf4b954 100755 --- a/app/Config/Routes.php +++ b/app/Config/Routes.php @@ -427,6 +427,7 @@ $routes->group("/util", ["filter" => "authMVC"], function ($routes) { $routes->get('checkDuplicateCdAccount', 'MasterController::checkDuplicateCdAccount'); $routes->get('proceedExcelFileDataValidation', 'EmployeeController::proceedExcelFileDataValidation'); $routes->get('checkTpaApiEnable', 'EmployeeRestController::checkTpaApiEnable'); + $routes->get('generateDemographyDataTable', 'LeadsController::generateDemographyDataTable'); }); $routes->post("policy_tranction/sendInstallmentRemainderMail","PolicyTransactionController::sendInstallmentRemainderMail"); @@ -525,7 +526,6 @@ $routes->cli('cli/check_env', 'MasterController::checkEnv'); $routes->cli('cli/enrollOpendAndClose', 'DashboardController::updatePolicyEnrollmentStatus'); $routes->cli("cli/sendCroneRemainderMail", "DashboardController::sendCroneRemainderMail"); $routes->cli('cli/update-emp-policy-status', 'ClientController::updateEmpAndPolicyStatus'); -$routes->cli('cli/update-emp-policy-status', 'ClientController::updateEmpAndPolicyStatus'); $routes->cli('cli/insurerRFQRemainder', 'LeadsController::remainderForQcr'); $routes->cli('cli/sendMailWithAutoQuery','TicketController::sendMailWithAutoQuery'); $routes->cli('cli/MediAssit-ClaimStatusUpdate','MediAssistApiController::ClaimStatusUpdate'); @@ -770,12 +770,12 @@ $routes->get('fetchUHIDDetails','ICICILombardController::fetchUHIDDetails'); //Third party - testing route - +$routes->get('FhplGetBenefDetails','FhplApiController::FhplGetBenefDetails'); $routes->get('EcardRequest','VidalApiController::EcardRequest'); $routes->get('HospitalNetwork','MediAssistApiController::HospitalNetwork'); $routes->get('VidalGetBenefDetails','VidalApiController::VidalGetBenefDetails'); -$routes->get('ClaimDetail','VidalApiController::ClaimDetail'); -$routes->get('SubmitClaim','MediAssistApiController::SubmitClaim'); +$routes->get('ClaimDetail','FhplApiController::ClaimDetail'); +$routes->get('SubmitClaim','FhplApiController::SubmitClaim'); $routes->get('IntimateClaim','MediAssistApiController::IntimateClaim'); $routes->get('IRSubmission','MediAssistApiController::IRSubmission'); $routes->get('ClaimStatusUpdate','MediAssistApiController::ClaimStatusUpdate'); diff --git a/app/Controllers/AppContentManagementController.php b/app/Controllers/AppContentManagementController.php index 54f8cbb0..a7032a4c 100755 --- a/app/Controllers/AppContentManagementController.php +++ b/app/Controllers/AppContentManagementController.php @@ -59,8 +59,48 @@ class AppContentManagementController extends AdminController // add and edit public function add_advertise_image() { try { + + $data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + $id = ((int) $sanitized_post_data['add_image_id']) ?? null; + + $rules = [ + 'client_id' => [ + 'rules' => 'required|integer', + 'errors' => [ + 'required' => 'Client is required', + 'integer' => 'Invalid client selected' + ] + ], + ]; + $rules['advertise_image'] = [ + 'rules' => ($id === 0 ? 'uploaded[advertise_image]|' : '') // required only for ADD + . 'is_image[advertise_image]' + . '|mime_in[advertise_image,image/jpg,image/jpeg,image/png]' + . '|max_size[advertise_image,200]' + . '|min_dims[advertise_image,1640,664]' + . '|max_dims[advertise_image,1640,664]', + 'errors' => [ + 'uploaded' => 'Image is required', + 'is_image' => 'File must be an image', + 'mime_in' => 'Only JPG, JPEG, PNG allowed', + 'max_size' => 'Image size must not exceed 200 KB', + 'min_dims' => 'Image dimensions must be exactly 1640x664 pixels', + 'max_dims' => 'Image dimensions must be exactly 1640x664 pixels', + ] + ]; + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } + + $file = $this->request->getFile('advertise_image'); - $client_id = $this->request->getPost('client_id'); + $client_id = $sanitized_post_data['client_id'] ?? null; //1) original file name for vaildations $fileName = $file->getClientName(); //original file name for vaildations $existing = $this->addImgModel->where('name', $fileName)->where('client_id', $fileName)->where('is_active', 1)->first(); @@ -80,13 +120,13 @@ class AppContentManagementController extends AdminController $file->move($uploadPath, $fileName); - $id = $this->request->getPost('add_image_id'); - $data = ['name' => $fileName,'client_id'=>$client_id]; + $id = $sanitized_post_data['add_image_id'] ?? null; + $details = ['name' => $fileName,'client_id'=>$client_id]; if ($id == 0) { - $this->addImgModel->insert($data); + $this->addImgModel->insert($details); } else { - $this->addImgModel->update($id, $data); + $this->addImgModel->update($id, $details); } return $this->respond(['status' => true, 'message' => 'Image saved successfully.']); @@ -143,8 +183,56 @@ class AppContentManagementController extends AdminController if ($this->request->getMethod() === 'post') { - $id = $this->request->getPost('fe_id'); - $data = $this->request->getPost(); + $rules = [ + 'type' => [ + 'rules' => 'required|max_length[255]', + 'errors' => [ + 'required' => 'Type is required', + 'max_length' => 'Type cannot exceed 255 characters' + ] + ], + 'content_section' => [ + 'rules' => 'required|max_length[255]', + 'errors' => [ + 'required' => 'Content Section is required', + 'max_length' => 'Content Section cannot exceed 255 characters' + ] + ], + 'heading' => [ + 'rules' => 'required|max_length[255]', + 'errors' => [ + 'required' => 'Heading is required', + 'max_length' => 'Heading cannot exceed 255 characters' + ] + ], + 'content' => [ + 'rules' => 'required|max_length[5000]', + 'errors' => [ + 'required' => 'Content is required', + 'max_length' => 'Content cannot exceed 5000 characters' + ] + ], + 'notes' => [ + 'rules' => 'required|max_length[1500]', + 'errors' => [ + 'required' => 'Notes are required', + 'max_length' => 'Notes cannot exceed 1500 characters' + ] + ] + ]; + + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } + $request_post_data = $this->request->getPost(); + $data = sanitizeInputArrayAdvanced($request_post_data); + $id = $data['fe_id']; + unset($data['fe_id']); @@ -231,8 +319,30 @@ class AppContentManagementController extends AdminController try { // --- 1. POST: CREATE OR UPDATE --- if ($method === 'post') { - $id = $this->request->getPost('faq_id'); - $data = array_filter($this->request->getPost(), fn($v) => $v !== '' && $v !== null); + $rules = [ + 'category' => [ + 'rules' => 'required', + 'errors' => [ + 'required' => 'Category is required' + ] + ], + 'question' => [ + 'rules' => 'required', + 'errors' => [ + 'required' => 'Question is required' + ] + ], + 'answer' => [ + 'rules' => 'required', + 'errors' => [ + 'required' => 'Answer is required' + ] + ] + ]; + $request_post_data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($request_post_data); + $data = array_filter($sanitized_post_data, fn($v) => $v !== '' && $v !== null); + $id = $data['faq_id']; if (empty($id)) { $status = $this->faqModel->insert($data); diff --git a/app/Controllers/BDSReportController.php b/app/Controllers/BDSReportController.php index 84702df7..902da3e7 100644 --- a/app/Controllers/BDSReportController.php +++ b/app/Controllers/BDSReportController.php @@ -191,10 +191,13 @@ class BDSReportController extends AdminController return $this->loadLayout('irba_report', $data); } else { - $fromDate = $this->request->getPost('fromDate'); - $toDate = $this->request->getPost('toDate'); - $category = $this->request->getPost('category'); - $report_type = $this->request->getPost('report_type'); + $request_post_data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($request_post_data); + + $fromDate = $sanitized_post_data['fromDate'] ?? null; + $toDate = $sanitized_post_data['toDate'] ?? null; + $category = $sanitized_post_data['category'] ?? null; + $report_type = $sanitized_post_data['report_type'] ?? null; // log_message('error',json_encode($_POST));die(); if ($report_type == 'insurer') { $life = $category == 'life' ? 1 : 0; @@ -937,11 +940,13 @@ class BDSReportController extends AdminController return $this->loadLayout('renewal_search', $data); } else { - $fromDate = $this->request->getPost('fromDate'); - $toDate = $this->request->getPost('toDate'); - $client_id = $this->request->getPost('client_id'); - $client_type = $this->request->getPost('client_type'); - $issuer_branch = $this->request->getPost('issuer_branch'); + $request_post_data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($request_post_data); + $fromDate = $sanitized_post_data['fromDate'] ?? null; + $toDate = $sanitized_post_data['toDate'] ?? null; + $client_id = $sanitized_post_data['client_id'] ?? null; + $client_type = $sanitized_post_data['client_type'] ?? null; + $issuer_branch = $sanitized_post_data['issuer_branch'] ?? null; $data['issuer_branch'] = $this->nhanceBranchModel->where('is_active', 1)->findAll(); $data['client_type'] = [1 => 'Group', 2 => 'Individual']; diff --git a/app/Controllers/ClientController.php b/app/Controllers/ClientController.php index 385d1adf..47f5b5fb 100755 --- a/app/Controllers/ClientController.php +++ b/app/Controllers/ClientController.php @@ -660,18 +660,25 @@ class ClientController extends AdminController } // In your controller - public function deposit($id = null, $requestFrom = null, $policyId = null) + public function deposit($ClientId = null, $requestFrom = null, $policyId = null) { $headerData['tab_name'] = 'Client Deposit'; $headerData['page_name'] = 'Clients'; - $data['clientName'] = $this->clientModel->where('id', (int)$id)->find(); - $data['clientData'] = $this->clientPolicyModel->getinsurerswithclientid($id, $policyId); + if (is_string($ClientId) && preg_match('/^[a-f0-9]{32}$/i', $ClientId)) + { + $data['clientName'] = $this->clientModel->where('md5(id)', $ClientId)->find(); + }else { + $data['clientName'] = $this->clientModel->where('id', $ClientId)->find(); + } - $data['depositsummary'] = $this->clientPolicyModel->getDepositlistsummary($id); + + $data['clientData'] = $this->clientPolicyModel->getinsurerswithclientid($ClientId, $policyId); + + $data['depositsummary'] = $this->clientPolicyModel->getDepositlistsummary($ClientId); // Fetch associated insurer names and balances - $balances = $this->clientPolicyModel->getBalances($id); + $balances = $this->clientPolicyModel->getBalances($ClientId); $data['balances'] = $balances; // dd($data); @@ -825,11 +832,11 @@ class ClientController extends AdminController // Retrieve form data from POST request $loggedInUserID = get_session_userid(); // print_rr($sanitized_post_data);die(); - $client_id = $sanitized_post_data['client_id']; - $insurer_id = $sanitized_post_data['insurer_id']; - $record_date = $sanitized_post_data['record_date']; - $cd_ac_pk = $sanitized_post_data['cd_ac_pk']; - $cd_ac_no = $sanitized_post_data['cd_ac_no']; + $client_id = $sanitized_post_data['client_id'] ?? null; + $insurer_id = $sanitized_post_data['insurer_id'] ?? null; + $record_date = $sanitized_post_data['record_date'] ?? null; + $cd_ac_pk = $sanitized_post_data['cd_ac_pk'] ?? null; + $cd_ac_no = $sanitized_post_data['cd_ac_no'] ?? null; @@ -849,15 +856,15 @@ class ClientController extends AdminController } $data = [ - 'amount' => $sanitized_post_data['amount'], - 'sub_type_id' => $sanitized_post_data['sub_type_id'], - 'client_id' => $sanitized_post_data['client_id'], + 'amount' => $sanitized_post_data['amount'] ?? null, + 'sub_type_id' => $sanitized_post_data['sub_type_id'] ?? null, + 'client_id' => $sanitized_post_data['client_id'] ?? null, 'client_policy_id' => null, 'cd_ac_no' => $cd_ac_no ?? null, 'cd_ac_pk' => $cd_ac_pk ?? null, 'endorsement_no' => null, - 'insurer_id' => $sanitized_post_data['insurer_id'], - 'description' => $sanitized_post_data['description'], + 'insurer_id' => $sanitized_post_data['insurer_id'] ?? null, + 'description' => $sanitized_post_data['description'] ?? null, 'transaction_type' => $sanitized_post_data['transaction_type'] ?: 'Credit', 'updated_by' => 1, 'record_date' => $record_date @@ -936,40 +943,104 @@ class ClientController extends AdminController public function createClientGeneralInfo() { - $this->myLogger->logme('error', 'Client general info function called'); + + $rules = [ + 'entity_type_id' => [ + 'rules' => 'required', + 'errors' => [ + 'required' => 'Entity Type is required', + ] + ], + 'client_name' => [ + 'rules' => 'required|alpha_space', + 'errors' => [ + 'required' => 'Client Name is required', + 'alpha_space' => 'Client Name can only contain alphabets and spaces.', + ] + ], + 'short_name' => [ + 'rules' => 'required|alpha', + 'errors' => [ + 'required' => 'Client Short Name is required', + 'alpha' => 'Client Short Name can only contain alphabets.', + ] + ], + 'pan' => [ + 'rules' => 'required|regex_match[/^[A-Z]{5}[0-9]{4}[A-Z]$/]', + 'errors' => [ + 'required' => 'PAN Number is required.', + 'regex_match' => 'Invalid PAN format. Example: ABCDE1234F' + ] + ], + 'hr_file_processed_by' => [ + 'rules' => 'required', + 'errors' => [ + 'required' => 'HR File Processed By is required.', + ] + ], + 'client_logo' => [ + 'rules' => [ + 'is_image[client_logo]', + 'max_size[client_logo,200]', // 200 KB + 'ext_in[client_logo,jpg,jpeg,png]', + 'max_dims[client_logo,100,100]', + ], + 'errors' => [ + 'is_image' => 'The uploaded file must be an image', + 'max_size' => 'File size should not exceed 200 KB', + 'ext_in' => 'Allowed file types: jpg, jpeg, png', + 'max_dims' => 'Image dimensions must be 100 x 100 pixels', + ] + ], + + ]; + + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } + + + $uploadFilePath = ROOTPATH . 'public/uploads/logo/'; $file_name = file_Upload($this->request->getFile('client_logo'), $uploadFilePath); $data = $this->request->getPost(); - $data['created_by'] = get_session_userid(); - $data['client_logo'] = $file_name; - $data['client_code'] = generate_client_code(); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + $sanitized_post_data['created_by'] = get_session_userid(); + $sanitized_post_data['client_logo'] = $file_name; + $sanitized_post_data['client_code'] = generate_client_code(); - if (!isset($data['is_download_btn'])) { - $data['is_download_btn'] = 0; - } elseif ($data['is_download_btn']) { - $data['is_download_btn'] = 1; + if (!isset($sanitized_post_data['is_download_btn'])) { + $sanitized_post_data['is_download_btn'] = 0; + } elseif ($sanitized_post_data['is_download_btn']) { + $sanitized_post_data['is_download_btn'] = 1; } - if (empty($data['parent_client_id'])) { - $data['parent_client_id'] = null; + if (empty($sanitized_post_data['parent_client_id'])) { + $sanitized_post_data['parent_client_id'] = null; } - $insert = $this->clientModel->insert($data); + $insertID = $this->clientModel->insert($sanitized_post_data); - if ($insert) { - $client_data = $this->clientModel->where(['id' => $insert, 'is_active' => 1])->first(); - - $client_id = $insert; - $default_template_creation = $this->createDefaultMailTemplate($client_id , $client_data); - if($default_template_creation == false){ - $this->myLogger->logme('error', 'Default Mail Template Creation Failed for Client ID: {data}', ['data' => $client_id]); + if ($insertID) { + + $client_info = $this->clientModel->where(['id' => $insertID, 'is_active' => 1])->first(); + + // Template Creation + if (!$this->createDefaultMailTemplate($insertID, $client_info)) { + $this->myLogger->logme('error', 'Default Mail Template Creation Failed for Client ID: ' . $insertID); } - return $this->respond(['status' => true, 'code' => 200, 'data' => $client_data], 200); - } else { - return $this->respond(['status' => false, 'code' => 404, 'message' => 'no data found'], 200); + + return $this->respond(['status' => true, 'code' => 200, 'data' => $client_info], 200); } + + return $this->respond(['status' => false, 'code' => 500, 'message' => 'Failed to create client'], 500); } public function editClientGeneralInfo() @@ -1009,7 +1080,7 @@ class ClientController extends AdminController - public function createClientKYCInfo() + public function createClientKYCInf() { $this->myLogger->logme('error', 'create Client kyc function called'); $data = $this->request->getPost(); @@ -1042,33 +1113,116 @@ class ClientController extends AdminController } } + /** Create Client KYC Documents V1 */ + public function createClientKYCInfo() + { + $this->myLogger->logme('error', 'Create Client KYC function called'); + + $rules = [ + 'file_name' => [ + 'rules' => 'uploaded[file_name]|max_size[file_name,5120]|ext_in[file_name,pdf,jpg,jpeg,png]', + 'errors' => [ + 'uploaded' => 'KYC document file is required', + 'max_size' => 'File size should not exceed 5MB', + 'ext_in' => 'Allowed file types: pdf, jpg, jpeg, png', + ] + ], + ]; + + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } + + $data = $this->request->getPost(); + $sanitized_data = sanitizeInputArrayAdvanced($data); + $form_type = $sanitized_data['form_type'] ?? null; + $uploadFilePath = WRITEPATH . 'uploads/client_kyc_documents'; + + unset($data['file_name']); + + $file = $this->request->getFile('file_name'); + + $fileName = file_Upload($file, $uploadFilePath); + + if (!empty($fileName)) { + $sanitized_data['file_name'] = $fileName; + } + + $sanitized_data['created_by'] = get_session_userid(); + + $insertID = $this->clientKYCDocsModel->insert($sanitized_data); + if ($insertID) { + if ($form_type === 'others') { + $kycDocs = $this->generateKycOthersTable($sanitized_data['client_id']); + } else { + $kycDocs = $this->generateKycPrimaryTable($sanitized_data['client_id']); + } + return $this->respond(['status' => true, 'code' => 200, 'data' => $kycDocs, 'file_name' => $file + ], 200); + } else { + return $this->respond(['status' => false, 'code' => 404, 'message' => 'Failed to upload KYC document'], 200); + } + } + + /** Edit Client KYC Documents V1 */ public function editClientKYCInfo() { + $this->myLogger->logme('error', 'Edit Client KYC function called'); + + $rules = [ + 'file_name' => [ + 'rules' => 'uploaded[file_name]|max_size[file_name,5120]|ext_in[file_name,pdf,jpg,jpeg,png]', + 'errors' => [ + 'uploaded' => 'KYC document file is required', + 'max_size' => 'File size should not exceed 5MB', + 'ext_in' => 'Allowed file types: pdf, jpg, jpeg, png', + ] + ], + ]; - $this->myLogger->logme('error', 'edit client kyc function called'); - $uploadFilePath = WRITEPATH . 'uploads/client_kyc_documents'; - $File = file_Upload($this->request->getFile('file_name'), $uploadFilePath); - $form_type = $this->request->getPost('form_type') ?? null; - - if (!empty($File)) { - $data['file_name'] = $File; + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); } - $id = $this->request->getPost('PrimaryKey'); - $data['client_id'] = $id; - $data['kyc_doc_type_id'] = $this->request->getPost('kyc_doc_id'); - $data['updated_by'] = get_session_userid(); - $insert = $this->clientKYCDocsModel->insert($data); - if ($insert) { - // $kycDocs = $this->clientKYCDocsModel->getKycDocsName($id); - if ($form_type == "others") { - $kycDocs = $this->generateKycOthersTable($this->request->getPost('client_id')); + $data = $this->request->getPost(); + $sanitized_data = sanitizeInputArrayAdvanced($data); + $form_type = $sanitized_data['form_type'] ?? null; + $uploadFilePath = WRITEPATH . 'uploads/client_kyc_documents'; + + unset($sanitized_data['file_name']); + + $file = $this->request->getFile('file_name'); + + $fileName = file_Upload($file, $uploadFilePath); + + if (!empty($fileName)) { + $sanitized_data['file_name'] = $fileName; + } + $id = $sanitized_data['PrimaryKey']; + $sanitized_data['client_id'] = $id; + $sanitized_data['kyc_doc_type_id'] = $this->request->getPost('kyc_doc_id'); + $sanitized_data['updated_by'] = get_session_userid(); + + $insertID = $this->clientKYCDocsModel->insert($sanitized_data); + if ($insertID) { + if ($form_type === 'others') { + $kycDocs = $this->generateKycOthersTable($sanitized_data['client_id']); } else { - $kycDocs = $this->generateKycPrimaryTable($this->request->getPost('client_id')); + $kycDocs = $this->generateKycPrimaryTable($sanitized_data['client_id']); } - return $this->respond(['status' => true, 'code' => 200, 'data' => $kycDocs], 200); + return $this->respond(['status' => true, 'code' => 200, 'data' => $kycDocs, 'file_name' => $file], 200); } else { - return $this->respond(['status' => false, 'code' => 404, 'message' => 'no data found'], 200); + return $this->respond(['status' => false, 'code' => 404, 'message' => 'Failed to upload KYC document'], 200); } } @@ -1095,12 +1249,33 @@ class ClientController extends AdminController } - + /** Client KYC Documents V2 */ public function createClientKYCInfo_2() { - $this->myLogger->logme('error', 'create Client kyc function called'); - $data = $this->request->getPost(); + $this->myLogger->logme('error', 'Create Client KYC V2 function called'); + + $rules = [ + 'file_name' => [ + 'rules' => 'uploaded[file_name]|max_size[file_name,5120]|ext_in[file_name,pdf,jpg,jpeg,png]', + 'errors' => [ + 'uploaded' => 'KYC document file is required', + 'max_size' => 'File size should not exceed 5MB', + 'ext_in' => 'Allowed file types: pdf, jpg, jpeg, png', + ] + ], + ]; + + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } + + $data = $this->request->getPost(); $uploadedFile = $this->request->getFile('file_name'); if ($uploadedFile && $uploadedFile->isValid() && !$uploadedFile->hasMoved()) { @@ -1108,34 +1283,78 @@ class ClientController extends AdminController } else { $this->myLogger->logme('error', 'File failed validation or was not uploaded.'); } + unset($data['file_name']); + $sanitized_data = sanitizeInputArrayAdvanced($data); + $form_type = $sanitized_data['form_type'] ?? null; + + $file = $this->request->getFile('file_name'); $uploadFilePath = WRITEPATH . 'uploads/client_kyc_documents'; + $fileName = file_Upload($file, $uploadFilePath); + + if (!empty($fileName)) { + $sanitized_data['file_name'] = $fileName; + } + + $sanitized_data['created_by'] = get_session_userid(); - $File = file_Upload($uploadedFile, $uploadFilePath); - $this->myLogger->logme('info', 'Result of file_Upload: ' . $File); + + + $this->myLogger->logme('info', 'Result of file_Upload: ' . $fileName); unset($data['file_name']); - if (!empty($File)) { $data['file_name'] = $File; } + $insertID = $this->clientKYCDocsModel->insert($sanitized_data); - $data['created_by'] = get_session_userid(); - $insert = $this->clientKYCDocsModel->insert($data); - - if ($insert) { - $html = $this->generateKycSingleTable($data['client_id']); - $dropdown = $this->fetch_dropdown($data['client_id']); - return $this->respond(['status' => true, 'code' => 200, 'file_name' => $File, 'html' => $html,'dropdown'=>$dropdown], 200); + if ($insertID) { + $html = $this->generateKycSingleTable($sanitized_data['client_id']); + $dropdown = $this->fetch_dropdown($sanitized_data['client_id']); + return $this->respond(['status' => true, 'code' => 200, 'file_name' => $fileName, 'html' => $html,'dropdown'=>$dropdown], 200); } else { $this->myLogger->logme('error', 'Database insert failed.'); return $this->respond(['status' => false, 'code' => 404, 'message' => 'Failed to add document'], 200); } } + /** Edit Client KYC Documents V2 */ public function editClientKYCInfo_2() { - $kyc_id = $this->request->getPost('id'); - $client_id = $this->request->getPost('client_id'); - $old_file_name = $this->request->getPost('old_file_name'); + $this->myLogger->logme('error', 'Edit Client KYC V2 function called'); + + $rules = [ + 'file_name' => [ + 'rules' => 'uploaded[file_name]|max_size[file_name,5120]|ext_in[file_name,pdf,jpg,jpeg,png]', + 'errors' => [ + 'uploaded' => 'KYC document file is required', + 'max_size' => 'File size should not exceed 5MB', + 'ext_in' => 'Allowed file types: pdf, jpg, jpeg, png', + ] + ], + ]; + + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } + + + $data = $this->request->getPost(); + unset($data['file_name']); + $sanitized_data = sanitizeInputArrayAdvanced($data); + $form_type = $sanitized_data['form_type'] ?? null; + $kyc_id = $sanitized_data['id'] ?? null; + $client_id = $sanitized_data['client_id'] ?? null; + $old_file_name = $sanitized_data['old_file_name'] ?? null; + + if (empty($kyc_id)) { + return $this->respond(['status' => false, 'message' => 'Missing KYC ID'], 400); + } + + $updateData = []; $uploadedFile = $this->request->getFile('file_name'); $new_file_name = null; $uploadFilePath = WRITEPATH . 'uploads/client_kyc_documents'; @@ -1143,12 +1362,11 @@ class ClientController extends AdminController if ($uploadedFile && $uploadedFile->isValid() && !$uploadedFile->hasMoved()) { - - $new_file_name = file_Upload($uploadedFile, $uploadFilePath); - - if (!empty($new_file_name)) { - - $updateData['file_name'] = $new_file_name; + $new_file_name = file_Upload($uploadedFile, $uploadFilePath); + if (!$new_file_name) { + return $this->respond(['status' => false, 'code' => 500, 'message' => 'New file upload failed on server.'], 200); + } + $updateData['file_name'] = $new_file_name; // Delete the old file from the storage if it exists // if (!empty($old_file_name)) { @@ -1158,56 +1376,64 @@ class ClientController extends AdminController // // Optionally delete from G-Drive here if applicable // } // } - } else { - // New file upload failed - return $this->respond(['status' => false, 'code' => 500, 'message' => 'New file upload failed on server.'], 200); - } + } - // 2. Perform the database update - if (!empty($updateData)) { - - $updateData['updated_by'] = get_session_userid(); - $update = $this->clientKYCDocsModel->update($kyc_id, $updateData); - $html = $this->generateKycSingleTable($client_id); - $dropdown = $this->fetch_dropdown($client_id); - - if ($update) { - return $this->respond(['status' => true, 'code' => 200, 'message' => 'Document updated successfully.','html' => $html,'dropdown' => $dropdown], 200); - } - } else { - + if (empty($updateData)) { return $this->respond(['status' => true, 'code' => 200, 'message' => 'No changes detected. Document remains the same.'], 200); } - + $updateData['updated_by'] = get_session_userid(); + + $update = $this->clientKYCDocsModel->update($kyc_id, $updateData); + + if ($update) { + return $this->respond([ + 'status' => true, + 'message' => 'Document updated successfully', + 'html' => $this->generateKycSingleTable($client_id), + 'dropdown' => $this->fetch_dropdown($client_id) + ], 200); + } + return $this->respond(['status' => false, 'code' => 404, 'message' => 'Database update failed or record not found.'], 200); } - - public function deleteClientKycDocs_2() + /** Delete Client KYC Documents V2 */ + public function deleteClientKycDocs_2() { - - $kyc_id = $this->request->getPost('id'); - $client_id = $this->request->getPost('client_id'); - // echo "KID".$kyc_id; - // echo "CID".$client_id; + $this->myLogger->logme('error', 'Delete Client KYC V2 function called'); + $data = $this->request->getPost(); + $sanitized_data = sanitizeInputArrayAdvanced($data); + $kyc_id = $sanitized_data['id'] ?? null; + $client_id = $sanitized_data['client_id'] ?? null; + $is_active = $sanitized_data['is_active'] ?? null; if (empty($kyc_id)) { return $this->respond(['status' => false, 'code' => 400, 'message' => 'Missing document ID.'], 200); } - $updateData['updated_by'] = get_session_userid(); - $updateData['is_active'] = $this->request->getPost('is_active'); + + + $updateData = [ + 'is_active' => (int) $is_active, + 'updated_by' => get_session_userid() + ]; + $delete = $this->clientKYCDocsModel->update($kyc_id, $updateData); - // $delete = 1; + if ($delete) { - $html = $this->generateKycSingleTable($client_id); - $dropdown = $this->fetch_dropdown($client_id); - return $this->respond(['status' => true, 'code' => 200, 'id' => $kyc_id, 'message' => 'Document successfully deactivated.','html' => $html,'dropdown' => $dropdown], 200); - } else { - return $this->respond(['status' => false, 'code' => 404, 'message' => 'Failed to update record (ID not found or DB error).'], 200); + return $this->respond([ + 'status' => true, + 'code' => 200, + 'id' => $kyc_id, + 'message' => 'Document successfully deactivated.', + 'html' => $this->generateKycSingleTable($client_id), + 'dropdown' => $this->fetch_dropdown($client_id) + ], 200); } + + return $this->respond(['status' => false, 'code' => 404, 'message' => 'Failed to update record (ID not found or DB error).'], 200); } public function fetch_dropdown($client_id) @@ -1365,31 +1591,123 @@ class ClientController extends AdminController { $this->myLogger->logme('error', 'Client branch CREATE function called'); - $data = $this->request->getPost(); - if (!isset($data['sez'])) { - $data['sez'] = 0; - } elseif ($data['sez']) { - $data['sez'] = 1; + $rules = [ + 'branch_name' => [ + 'rules' => 'required', + 'errors' => [ + 'required' => 'Branch Name is required', + ] + ], + 'branch_code' => [ + 'rules' => 'required', + 'errors' => [ + 'required' => 'Branch Code is required', + ] + ], + 'address1' => [ + 'rules' => 'required', + 'errors' => [ + 'required' => 'Address Line 1 is required', + ] + ], + 'state' => [ + 'rules' => 'required', + 'errors' => [ + 'required' => 'State is required', + ] + ], + 'district' => [ + 'rules' => 'required', + 'errors' => [ + 'required' => 'District is required.', + ] + ], + 'city' => [ + 'rules' => 'required', + 'errors' => [ + 'required' => 'City is required.', + ] + ], + 'pincode' => [ + 'rules' => 'required', + 'errors' => [ + 'required' => 'Pincode is required.', + ] + ], + 'gst' => [ + 'rules' => 'required|regex_match[/^\d{2}[A-Z]{5}\d{4}[A-Z]{1}[A-Z\d]{1}Z[A-Z\d]{1}$/]', + 'errors' => [ + 'required' => 'GST number is required', + 'regex_match' => 'Invalid GST Number. Example: 12ABCDE1234F5Z6' + ] + ], + 'name.*' => [ + 'rules' => 'required|alpha_space', + 'errors' => [ + 'required' => 'Contact name is required', + 'alpha_space' => 'Contact name may contain only letters and spaces' + ] + ], + 'designation.*' => [ + 'rules' => 'required|alpha_space', + 'errors' => [ + 'required' => 'Designation is required', + 'alpha_space' => 'Designation may contain only letters and spaces' + ] + ], + 'email.*' => [ + 'rules' => 'required|valid_email', + 'errors' => [ + 'required' => 'Email is required', + 'valid_email' => 'Please enter a valid email address' + ] + ], + 'mobile.*' => [ + 'rules' => 'required|numeric|exact_length[10]', + 'errors' => [ + 'required' => 'Mobile number is required', + 'numeric' => 'Mobile number must contain digits only', + 'exact_length' => 'Mobile number must be exactly 10 digits' + ] + ], + ]; + + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); } - $units = json_decode($data['units'], true) ?? []; + $data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + + if (!isset($sanitized_post_data['sez'])) { + $sanitized_post_data['sez'] = 0; + } elseif ($sanitized_post_data['sez']) { + $sanitized_post_data['sez'] = 1; + } + + $units = json_decode($sanitized_post_data['units'], true) ?? []; if (!is_array($units) || empty($units)) { - $client_data = $this->clientModel->where('id', $data['client_id'])->first(); - $default_unit = trim(($client_data['short_name'] ?? '') . '-' . ($data['branch_code'] ?? ''), '-'); - $data['units'] = json_encode([$default_unit]); + $client_data = $this->clientModel->where('id', $sanitized_post_data['client_id'])->first(); + $default_unit = trim(($client_data['short_name'] ?? '') . '-' . ($sanitized_post_data['branch_code'] ?? ''), '-'); + $sanitized_post_data['units'] = json_encode([$default_unit]); } - $data['created_by'] = get_session_userid(); + $sanitized_post_data['created_by'] = get_session_userid(); // before updating check if pre_branch_id is already existing in the current db - if(isset($data['pre_branch_id']) && !empty($data['pre_branch_id'])) + if(isset($sanitized_post_data['pre_branch_id']) && !empty($sanitized_post_data['pre_branch_id'])) { $existing_pre_branch = $this->clientBranchModel - ->where('pre_branch_id',$data['pre_branch_id']) + ->where('pre_branch_id',$sanitized_post_data['pre_branch_id']) //->where('id !=',$post_branch_id) ->first(); @@ -1405,26 +1723,39 @@ class ClientController extends AdminController - $insert = $this->clientBranchModel->insert($data); + $insert = $this->clientBranchModel->insert($sanitized_post_data); $post_branch_id = $insert; if ($insert) { - $level_contact_data = $this->request->getPost('level_contect_data'); - $level_contact_data = !empty($level_contact_data) ? json_decode($level_contact_data, true) : null; - $this->saveLevelContacts($level_contact_data, $insert); + + $level_contact_data_raw = $this->request->getPost('level_contect_data'); + $level_contact_data = []; + + if (!empty($level_contact_data_raw)) { + $level_contact_data_decoded = json_decode($level_contact_data_raw, true); + + if (json_last_error() === JSON_ERROR_NONE && is_array($level_contact_data_decoded)) { + $level_contact_data = sanitizeInputArrayAdvanced($level_contact_data_decoded); + } + } + + if (!empty($level_contact_data)) { + $this->saveLevelContacts($level_contact_data, $insert); + } + } - if($post_branch_id && isset($data['pre_branch_id']) && !empty($data['pre_branch_id'])) + if($post_branch_id && isset($sanitized_post_data['pre_branch_id']) && !empty($sanitized_post_data['pre_branch_id'])) { // need to update the client_branch in the pre - $result = $this->updatePreClientBranch($data['pre_branch_id'],$post_branch_id , "create"); + $result = $this->updatePreClientBranch($sanitized_post_data['pre_branch_id'],$post_branch_id , "create"); - log_message('error','Pre client_branch update result for pre_branch_id '.$data['pre_branch_id'].' and post_branch_id '.$post_branch_id.' is '.json_encode($result)); + log_message('error','Pre client_branch update result for pre_branch_id '.$sanitized_post_data['pre_branch_id'].' and post_branch_id '.$post_branch_id.' is '.json_encode($result)); } if ($insert) { - $branchData = $this->clientBranchModel->where('client_id', $this->request->getPost('client_id'))->findAll(); + $branchData = $this->clientBranchModel->where('client_id', $sanitized_post_data('client_id'))->findAll(); $branchData['role'] = get_role_id(); return $this->respond([ 'status' => true, @@ -1445,14 +1776,15 @@ class ClientController extends AdminController { $this->myLogger->logme('error', 'Client branch EDIT function called'); - $id = $this->request->getPost('branch_id_primarykey'); - $client_id = $this->request->getPost('client_id'); - $pre_branch_id = $this->request->getPost('pre_branch_id') ?? ''; + $data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + $id = $sanitized_post_data['branch_id_primarykey'] ?? null; + $client_id = $sanitized_post_data['client_id'] ?? null; + $pre_branch_id = $sanitized_post_data['pre_branch_id'] ?? ''; - $data = $this->request->getPost(); $data['pre_branch_id'] = $pre_branch_id; - $units = $this->request->getPost('units'); + $units = $sanitized_post_data['units'] ?? null; $emp_unit_count = 0; $rr_unit_count = 0; @@ -1463,9 +1795,9 @@ class ClientController extends AdminController $units = json_decode($list_of_branch_units['units']); if (!is_array($units) || empty($units)) { - $client_data = $this->clientModel->where('id', $data['client_id'])->first(); - $default_unit = trim(($client_data['short_name'] ?? '') . '-' . ($data['branch_code'] ?? ''), '-'); - $data['units'] = json_encode([$default_unit]); + $client_data = $this->clientModel->where('id', $sanitized_post_data['client_id'])->first(); + $default_unit = trim(($client_data['short_name'] ?? '') . '-' . ($sanitized_post_data['branch_code'] ?? ''), '-'); + $sanitized_post_data['units'] = json_encode([$default_unit]); } if (!empty($units)) { @@ -1481,7 +1813,7 @@ class ClientController extends AdminController $uncommonValues = []; if ($total_count > 0) { - $units = (string) $this->request->getPost('units'); // Assuming 'units' is an array + $units = (string) $sanitized_post_data('units'); // Assuming 'units' is an array $list_of_branch_units = $this->clientBranchModel->find((int)$id); $branch_units = json_decode($list_of_branch_units['units'], true); @@ -1503,22 +1835,22 @@ class ClientController extends AdminController } } - if (!isset($data['sez'])) { - $data['sez'] = 0; - } elseif ($data['sez']) { - $data['sez'] = 1; + if (!isset($sanitized_post_data['sez'])) { + $sanitized_post_data['sez'] = 0; + } elseif ($sanitized_post_data['sez']) { + $sanitized_post_data['sez'] = 1; } - $data['updated_by'] = get_session_userid(); + $sanitized_post_data['updated_by'] = get_session_userid(); $post_branch_id = $id; // before updating check if pre_branch_id is already existing in the current db - if(isset($data['pre_branch_id']) && !empty($data['pre_branch_id'])) + if(isset($sanitized_post_data['pre_branch_id']) && !empty($sanitized_post_data['pre_branch_id'])) { $existing_pre_branch = $this->clientBranchModel - ->where('pre_branch_id',$data['pre_branch_id']) + ->where('pre_branch_id',$sanitized_post_data['pre_branch_id']) ->where('id !=',$post_branch_id) ->first(); @@ -1532,16 +1864,16 @@ class ClientController extends AdminController } } - $insert = $this->clientBranchModel->update($id, $data); + $insert = $this->clientBranchModel->update($id, $sanitized_post_data); - if($post_branch_id && isset($data['pre_branch_id']) && !empty($data['pre_branch_id'])) + if($post_branch_id && isset($sanitized_post_data['pre_branch_id']) && !empty($sanitized_post_data['pre_branch_id'])) { // need to update the client_branch in the pre - $result = $this->updatePreClientBranch($data['pre_branch_id'],$post_branch_id , "update"); + $result = $this->updatePreClientBranch($sanitized_post_data['pre_branch_id'],$post_branch_id , "update"); - log_message('error','Pre client_branch update result for pre_branch_id '.$data['pre_branch_id'].' and post_branch_id '.$post_branch_id.' is '.json_encode($result)); + log_message('error','Pre client_branch update result for pre_branch_id '.$sanitized_post_data['pre_branch_id'].' and post_branch_id '.$post_branch_id.' is '.json_encode($result)); } @@ -1549,10 +1881,22 @@ class ClientController extends AdminController if ($insert) { + + $level_contact_data_raw = $this->request->getPost('level_contect_data'); + $level_contact_data = []; + + if (!empty($level_contact_data_raw)) { + $level_contact_data_decoded = json_decode($level_contact_data_raw, true); + + if (json_last_error() === JSON_ERROR_NONE && is_array($level_contact_data_decoded)) { + $level_contact_data = sanitizeInputArrayAdvanced($level_contact_data_decoded); + } + } + + if (!empty($level_contact_data)) { + $this->saveLevelContacts($level_contact_data, $insert); + } - $level_contact_data = $this->request->getPost('level_contect_data'); - $level_contact_data = !empty($level_contact_data) ? json_decode($level_contact_data, true) : null; - $this->saveLevelContacts($level_contact_data, $id); } if ($insert) { @@ -1567,7 +1911,7 @@ class ClientController extends AdminController 'total_count' => $total_count, 'uncommonValues' => $uncommonValues, 'message' => 'Client branch updated successfully', - 'response_data' => $this->request->getPost() + 'response_data' => $sanitized_post_data ], 200); } else { @@ -1627,8 +1971,7 @@ class ClientController extends AdminController } - - + /** here ci4 rules not implemented, because UI screen Fields are hide/show implemented thats why */ public function createClientPolicy() { @@ -1637,20 +1980,23 @@ class ClientController extends AdminController $this->myLogger->logme('error', 'Client policy CREATE function called'); - $policy_type_id = $this->request->getPost('policy_type_id'); - $client_branch_id = $this->request->getPost('client_branch_id'); - $client_id = $this->request->getPost('client_id'); - $base_policy = $this->request->getPost('base_policy'); + $request_post_data = $this->request->getPost(); + $$sanitized_post_data = sanitizeInputArrayAdvanced($request_post_data); + + $policy_type_id = $sanitized_post_data['policy_type_id'] ?? null; + $client_branch_id = $sanitized_post_data['client_branch_id'] ?? null; + $client_id = $sanitized_post_data['client_id'] ?? null; + $base_policy = $sanitized_post_data['base_policy'] ?? null; - $insurerValue = (string) $this->request->getPost('insurer'); + $insurerValue = (string) $sanitized_post_data['insurer'] ?? null; list($insurerBranchId, $insurerId) = explode('-', $insurerValue); - $data['insurer_branch_id'] = $insurerBranchId; - $data['insurer_id'] = $insurerId; + $sanitized_post_data['insurer_branch_id'] = $insurerBranchId; + $sanitized_post_data['insurer_id'] = $insurerId; - $tpaValue = (string) $this->request->getPost('tpa'); + $tpaValue = (string) $sanitized_post_data['tpa'] ?? null; if ($tpaValue === null || $tpaValue === '') { $tpaBranchId = null; @@ -1660,98 +2006,92 @@ class ClientController extends AdminController } - $data['client_id'] = $client_id; - $data['tpa_branch_id'] = $tpaBranchId; - $data['tpa_id'] = $tpaId; - $data['policy_type_id'] = $this->request->getPost('policy_type_id'); + $sanitized_post_data['client_id'] = $client_id; + $sanitized_post_data['tpa_branch_id'] = $tpaBranchId; + $sanitized_post_data['tpa_id'] = $tpaId; + $sanitized_post_data['policy_type_id'] = $sanitized_post_data['policy_type_id'] ?? null; - $data['no_of_lives'] = $this->request->getPost('no_of_lives'); - $data['policy_status'] = $this->request->getPost('policy_status'); - $data['no_of_employees'] = $this->request->getPost('no_of_employees'); - $data['earned_premium_date'] = change_date_format($this->request->getPost('earned_premium_date'), 'd-m-Y', 'Y-m-d') ?? null; - $data['claims_incurred_date'] = change_date_format($this->request->getPost('claims_incurred_date'), 'd-m-Y', 'Y-m-d') ?? null; - $data['incurred_claims_ratio'] = $this->request->getPost('incurred_claims_ratio'); - $data['no_lives_at_inception'] = $this->request->getPost('no_lives_at_inception'); - $data['premium_paid_at_inception'] = $this->request->getPost('premium_paid_at_inception'); - $data['claims_experience_for_last_3_years'] = $this->request->getPost('claims_experience_for_last_3_years'); - $data['earned_premium_amount'] = $this->request->getPost('earned_premium_amount'); - $data['claims_incurred_amount'] = $this->request->getPost('claims_incurred_amount'); - $data['base_policy'] = ($this->request->getPost('base_policy') === '' || $this->request->getPost('base_policy') == 0) ? null : $this->request->getPost('base_policy'); - $data['policy_status'] = 1; - $data['inception_type'] = $this->request->getPost('inception_type') ? 2 : 1; - $data['client_branch_id'] = $this->request->getPost('client_branch_id'); - $data['cd_ac_pk'] = $this->request->getPost('cd_ac_no'); - $data['gst'] = $this->request->getPost('gst'); - $data['disclaimer'] = $this->request->getPost('disclaimer'); - $data['is_member_modify_allowed'] = $this->request->getPost('is_member_modify_allowed') ? 1 : 0; - $data['enrolment_visibility'] = $this->request->getPost('enrolment_visibility') ? 1 : 0; - $data['is_lgbtq'] = $this->request->getPost('is_lgbtq') ? 1 : 0; - $data['wellness_plan_id'] = $this->request->getPost('wellness_plan_id'); - $data['wellness_vendor_id'] = $this->request->getPost('wellness_vendor_id'); - $data['wellness_vendor_id'] = !empty($data['wellness_vendor_id']) ? $data['wellness_vendor_id'] : null; + + $sanitized_post_data['earned_premium_date'] = change_date_format($sanitized_post_data['earned_premium_date'] ?? null, 'd-m-Y', 'Y-m-d') ?? null; + $sanitized_post_data['claims_incurred_date'] = change_date_format($sanitized_post_data['claims_incurred_date'] ?? null, 'd-m-Y', 'Y-m-d') ?? null; + + $sanitized_post_dataa['base_policy'] = ($sanitized_post_data['base_policy'] === '' || $sanitized_post_data['base_policy'] == 0) ? null : $sanitized_post_data['base_policy']; + $sanitized_post_data['policy_status'] = 1; + $sanitized_post_data['inception_type'] = $sanitized_post_data['inception_type'] ? 2 : 1; + + + + + $sanitized_post_data['is_member_modify_allowed'] = $sanitized_post_data['is_member_modify_allowed'] ?? null ? 1 : 0; + $sanitized_post_data['enrolment_visibility'] = $sanitized_post_data['enrolment_visibility'] ?? null ? 1 : 0; + $sanitized_post_data['is_lgbtq'] = $sanitized_post_data['is_lgbtq'] ?? null ? 1 : 0; + $sanitized_post_data['wellness_vendor_id'] = !empty($sanitized_post_data['wellness_vendor_id']) ? $sanitized_post_data['wellness_vendor_id'] : null; if ($policy_type_id == 1 || $policy_type_id == 2 || $policy_type_id == 6 || $policy_type_id == 7) { - $data['is_addon'] = 1; // Base Policy + $sanitized_post_data['is_addon'] = 1; // Base Policy } else if ($policy_type_id == 4 || $policy_type_id == 5) { - $data['is_addon'] = 2; // SI TOPUP + $sanitized_post_data['is_addon'] = 2; // SI TOPUP } else if ($policy_type_id == 3) { if ($base_policy) { - $data['is_addon'] = 3; // Dependent Addon + $sanitized_post_data['is_addon'] = 3; // Dependent Addon } else { - $data['is_addon'] = 1; + $sanitized_post_data['is_addon'] = 1; } } - $data['policy_start_date'] = change_date_format($this->request->getPost('policy_start_date'), 'd-m-Y', 'Y-m-d'); - $data['policy_end_date'] = change_date_format($this->request->getPost('policy_end_date'), 'd-m-Y', 'Y-m-d'); - $data['policy_no'] = $this->request->getPost('policy_no'); - if ($data['inception_type'] == 2) { - $data['open_date'] = change_date_format($this->request->getPost('open_date'), 'd-m-Y', 'Y-m-d'); - $data['close_date'] = change_date_format($this->request->getPost('close_date'), 'd-m-Y', 'Y-m-d'); + $sanitized_post_data['policy_start_date'] = change_date_format($sanitized_post_data['policy_start_date'] ?? null, 'd-m-Y', 'Y-m-d'); + $sanitized_post_data['policy_end_date'] = change_date_format($sanitized_post_data['policy_end_date'] ?? null, 'd-m-Y', 'Y-m-d'); + $sanitized_post_data['policy_no'] = $sanitized_post_data['policy_no'] ?? null; + if ($sanitized_post_data['inception_type'] == 2) { + $sanitized_post_data['open_date'] = change_date_format($sanitized_post_data['open_date'] ?? null, 'd-m-Y', 'Y-m-d'); + $sanitized_post_data['close_date'] = change_date_format($sanitized_post_data['close_date'] ?? null, 'd-m-Y', 'Y-m-d'); // $data['reminder_date'] = change_date_format($this->request->getPost('reminder_date'), 'd-m-Y', 'Y-m-d'); - $data['reminder_date'] = $this->request->getPost('reminder_date'); + $sanitized_post_data['reminder_date'] = $sanitized_post_data['reminder_date'] ?? null; } else { - $data['open_date'] = null; - $data['closedate'] = null; - $data['reminder_date'] = null; + $sanitized_post_data['open_date'] = null; + $sanitized_post_data['closedate'] = null; + $sanitized_post_data['reminder_date'] = null; } - $data['created_by'] = get_session_userid(); + $sanitized_post_data['created_by'] = get_session_userid(); - $insert = $this->clientPolicyModel->insert($data); + $insert = $this->clientPolicyModel->insert($sanitized_post_data); if ($insert) { - $clientPoliceData = $this->clientPolicyModel->getClientPolicyByClientId($this->request->getPost('client_id')); + $clientPoliceData = $this->clientPolicyModel->getClientPolicyByClientId($sanitized_post_data['client_id']); $clientPoliceData['role'] = get_role_id(); - return $this->respond(['status' => true, 'code' => 200, 'data' => $clientPoliceData, 'method' => 'CERATE', 'post_data' => $data], 200); + return $this->respond(['status' => true, 'code' => 200, 'data' => $clientPoliceData, 'client_id' => $client_id, 'method' => 'CERATE', 'post_data' => $insert_data], 200); } else { return $this->respond(['status' => false, 'code' => 404, 'message' => 'no data found'], 200); } } + /** here ci4 rules not implemented, because UI screen Fields are hide/show implemented thats why */ public function editClientPolicy() { $this->myLogger->logme('error', 'Client policy function called'); + $data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); - $id = $this->request->getPost('PrimaryKey'); - $client_id = $this->request->getPost('client_id'); - $policy_type_id = $this->request->getPost('policy_type_id'); - $base_policy = $this->request->getPost('base_policy'); + $id = $sanitized_post_data['PrimaryKey'] ?? null; + $client_id = $sanitized_post_data['client_id'] ?? null; + $policy_type_id = $sanitized_post_data['policy_type_id'] ?? null; + $base_policy = $sanitized_post_data['base_policy'] ?? null; - $insurerValue = (string) $this->request->getPost('insurer'); + $insurerValue = (string) $sanitized_post_data['insurer']; list($insurerBranchId, $insurerId) = explode('-', $insurerValue); - $data['insurer_branch_id'] = $insurerBranchId; - $data['insurer_id'] = $insurerId; + $sanitized_post_data['insurer_branch_id'] = $insurerBranchId ?? null; + $sanitized_post_data['insurer_id'] = $insurerId ?? null; - $tpaValue = (string) $this->request->getPost('tpa'); + $tpaValue = (string) $sanitized_post_data['tpa'] ?? null; if (!empty($tpaValue) || $tpaValue !== '') { list($tpaBranchId, $tpaId) = explode('-', $tpaValue); } else { @@ -1759,75 +2099,75 @@ class ClientController extends AdminController $tpaId = null; } - $data['tpa_branch_id'] = $tpaBranchId; - $data['client_id'] = $client_id; - $data['tpa_id'] = $tpaId; - $data['policy_type_id'] = $this->request->getPost('policy_type_id'); - $data['policy_no'] = $this->request->getPost('policy_no'); + $sanitized_post_data['tpa_branch_id'] = $tpaBranchId ?? null; + $sanitized_post_data['client_id'] = $client_id ?? null; + $sanitized_post_data['tpa_id'] = $tpaId ?? null; + $sanitized_post_data['policy_type_id'] = $sanitized_post_data['policy_type_id'] ?? null; + $sanitized_post_data['policy_no'] = $sanitized_post_data['policy_no'] ?? null; - $data['insured'] = $this->request->getPost('insured'); - $data['no_of_lives'] = $this->request->getPost('no_of_lives'); - $data['policy_status'] = $this->request->getPost('policy_status'); - $data['no_of_employees'] = $this->request->getPost('no_of_employees'); - $data['earned_premium_date'] = change_date_format($this->request->getPost('earned_premium_date'), 'd-m-Y', 'Y-m-d') ?? null; - $data['claims_incurred_date'] = change_date_format($this->request->getPost('claims_incurred_date'), 'd-m-Y', 'Y-m-d') ?? null; - $data['incurred_claims_ratio'] = $this->request->getPost('incurred_claims_ratio'); - $data['no_lives_at_inception'] = $this->request->getPost('no_lives_at_inception'); - $data['premium_paid_at_inception'] = $this->request->getPost('premium_paid_at_inception'); - $data['claims_experience_for_last_3_years'] = $this->request->getPost('claims_experience_for_last_3_years'); - $data['earned_premium_amount'] = $this->request->getPost('earned_premium_amount'); - $data['claims_incurred_amount'] = $this->request->getPost('claims_incurred_amount'); - $data['base_policy'] = ($this->request->getPost('base_policy') === '' || $this->request->getPost('base_policy') == 0) ? null : $this->request->getPost('base_policy'); - $data['policy_status'] = 1; - $data['inception_type'] = $this->request->getPost('inception_type') ? 2 : 1; - $data['enrolment_visibility'] = $this->request->getPost('enrolment_visibility') ? 1 : 0; - $data['client_branch_id'] = $this->request->getPost('client_branch_id'); - $data['cd_ac_pk'] = $this->request->getPost('cd_ac_no'); - $data['gst'] = $this->request->getPost('gst'); - $data['disclaimer'] = $this->request->getPost('disclaimer'); - $data['policy_start_date'] = change_date_format($this->request->getPost('policy_start_date'), 'd-m-Y', 'Y-m-d'); - $data['policy_end_date'] = change_date_format($this->request->getPost('policy_end_date'), 'd-m-Y', 'Y-m-d'); - $data['is_member_modify_allowed'] = $this->request->getPost('is_member_modify_allowed') ? 1 : 0; - $data['is_lgbtq'] = $this->request->getPost('is_lgbtq') ? 1 : 0; - $data['wellness_plan_id'] = $this->request->getPost('wellness_plan_id'); - $data['wellness_vendor_id'] = $this->request->getPost('wellness_vendor_id'); - $data['wellness_vendor_id'] = !empty($data['wellness_vendor_id']) ? $data['wellness_vendor_id'] : null; + // $sanitized_post_data['insured'] = $sanitized_post_data['insured']; + $sanitized_post_data['no_of_lives'] = $sanitized_post_data['no_of_lives'] ?? null; + $sanitized_post_data['policy_status'] = $sanitized_post_data['policy_status'] ?? null; + $sanitized_post_data['no_of_employees'] = $sanitized_post_data['no_of_employees'] ?? null; + $sanitized_post_data['earned_premium_date'] = change_date_format($sanitized_post_data['earned_premium_date'] ?? null, 'd-m-Y', 'Y-m-d') ?? null; + $sanitized_post_data['claims_incurred_date'] = change_date_format($sanitized_post_data['claims_incurred_date'] ?? null, 'd-m-Y', 'Y-m-d') ?? null; + $sanitized_post_data['incurred_claims_ratio'] = $sanitized_post_data['incurred_claims_ratio'] ?? null; + $sanitized_post_data['no_lives_at_inception'] = $sanitized_post_data['no_lives_at_inception'] ?? null; + $sanitized_post_data['premium_paid_at_inception'] = $sanitized_post_data['premium_paid_at_inception'] ?? null; + $sanitized_post_data['claims_experience_for_last_3_years'] = $sanitized_post_data['claims_experience_for_last_3_years'] ?? null; + $sanitized_post_data['earned_premium_amount'] = $sanitized_post_data['earned_premium_amount'] ?? null; + $sanitized_post_data['claims_incurred_amount'] = $sanitized_post_data['claims_incurred_amount'] ?? null; + $sanitized_post_data['base_policy'] = ($sanitized_post_data['base_policy'] === '' || $sanitized_post_data['base_policy'] == 0) ? null : $sanitized_post_data['base_policy']; + $sanitized_post_data['policy_status'] = 1; + $sanitized_post_data['inception_type'] = $sanitized_post_data['inception_type'] ?? null ? 2 : 1; + $sanitized_post_data['enrolment_visibility'] = $sanitized_post_data['enrolment_visibility'] ?? null ? 1 : 0; + $sanitized_post_data['client_branch_id'] = $sanitized_post_data['client_branch_id'] ?? null; + $sanitized_post_data['cd_ac_pk'] = $sanitized_post_data['cd_ac_no'] ?? null; + $sanitized_post_data['gst'] = $sanitized_post_data['gst'] ?? null; + $sanitized_post_data['disclaimer'] = $sanitized_post_data['disclaimer'] ?? null; + $sanitized_post_data['policy_start_date'] = change_date_format($sanitized_post_data['policy_start_date'] ?? null, 'd-m-Y', 'Y-m-d'); + $sanitized_post_data['policy_end_date'] = change_date_format($sanitized_post_data['policy_end_date'] ?? null, 'd-m-Y', 'Y-m-d'); + $sanitized_post_data['is_member_modify_allowed'] = $sanitized_post_data['is_member_modify_allowed'] ?? null ? 1 : 0; + $sanitized_post_data['is_lgbtq'] = $sanitized_post_data['is_lgbtq'] ?? null ? 1 : 0; + $sanitized_post_data['wellness_plan_id'] = $sanitized_post_data['wellness_plan_id'] ?? null; + $sanitized_post_data['wellness_vendor_id'] = $sanitized_post_data['wellness_vendor_id'] ?? null; + $sanitized_post_data['wellness_vendor_id'] = !empty($sanitized_post_data['wellness_vendor_id']) ? $sanitized_post_data['wellness_vendor_id'] : null; - if ($data['inception_type'] == 2) { - $data['open_date'] = change_date_format($this->request->getPost('open_date'), 'd-m-Y', 'Y-m-d'); - $data['close_date'] = change_date_format($this->request->getPost('close_date'), 'd-m-Y', 'Y-m-d'); - // $data['reminder_date'] = change_date_format($this->request->getPost('reminder_date'), 'd-m-Y', 'Y-m-d'); - $data['reminder_date'] = $this->request->getPost('reminder_date'); + if ($sanitized_post_data['inception_type'] == 2) { + $sanitized_post_data['open_date'] = change_date_format($sanitized_post_data['open_date'] ?? null, 'd-m-Y', 'Y-m-d'); + $sanitized_post_data['close_date'] = change_date_format($sanitized_post_data['close_date'] ?? null, 'd-m-Y', 'Y-m-d'); + // $sanitized_post_data['reminder_date'] = change_date_format($sanitized_post_data['reminder_date'), 'd-m-Y', 'Y-m-d'); + $sanitized_post_data['reminder_date'] = $sanitized_post_data['reminder_date'] ?? null; } else { - $data['open_date'] = null; - $data['close_date'] = null; - $data['reminder_date'] = null; + $sanitized_post_data['open_date'] = null; + $sanitized_post_data['close_date'] = null; + $sanitized_post_data['reminder_date'] = null; } if ($policy_type_id == 1 || $policy_type_id == 2 || $policy_type_id == 6 || $policy_type_id == 7) { - $data['is_addon'] = 1; // Base Policy + $sanitized_post_data['is_addon'] = 1; // Base Policy } else if ($policy_type_id == 4 || $policy_type_id == 5) { - $data['is_addon'] = 2; // SI TOPUP + $sanitized_post_data['is_addon'] = 2; // SI TOPUP } else if ($policy_type_id == 3) { if ($base_policy) { - $data['is_addon'] = 3; // Dependent Addon + $sanitized_post_data['is_addon'] = 3; // Dependent Addon } else { - $data['is_addon'] = 1; + $sanitized_post_data['is_addon'] = 1; } } - $policy_terms = $this->clientPolicyModel->where('id', $this->request->getPost('base_policy'))->first(); + $policy_terms = $this->clientPolicyModel->where('id', $sanitized_post_data['base_policy'])->first(); $old_client_policy_data = $this->clientPolicyModel->where('is_active', 1)->where('id', $id)->first(); - $data['updated_by'] = get_session_userid(); - $insert = $this->clientPolicyModel->update($id, $data); + $sanitized_post_data['updated_by'] = get_session_userid(); + $update = $this->clientPolicyModel->update($id, $sanitized_post_data); - if ($insert) { + if ($update) { $new_client_policy_data = $this->clientPolicyModel->where('is_active', 1)->where('id', $id)->first(); $policy_transaction_data = $this->policyTransactionModel->where('is_active', 1)->where('client_policy_id', $id)->countAllResults(); @@ -1841,7 +2181,7 @@ class ClientController extends AdminController ]]); } - return $this->respond(['status' => true, 'code' => 200, 'data' => $clientPoliceData, 'method' => 'EDIT'], 200); + return $this->respond(['status' => true, 'code' => 200, 'data' => $clientPoliceData, 'client_id' => $client_id, 'method' => 'EDIT'], 200); } else { return $this->respond(['status' => false, 'code' => 404, 'message' => 'no data found'], 200); } @@ -1917,36 +2257,39 @@ class ClientController extends AdminController // echo json_encode(['key' => $this->request->getPost()]); die; try { - $client_id = $this->request->getPost('client_id'); - $client_policy_id = $this->request->getPost('client_policy_id'); + $data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + + $client_id = $sanitized_post_data['client_id'] ?? null; + $client_policy_id = $sanitized_post_data['client_policy_id'] ?? null; $record = $this->clientPolicyModel->where('client_policy.id', $client_policy_id)->first(); - $premium_type = $this->request->getPost('premium_type'); + $premium_type = $sanitized_post_data['premium_type'] ?? null; if (!empty($client_id) && $client_id != null) { $client_policy_data = $this->clientPolicyModel->where('id', $client_policy_id)->first(); - $client_id = $client_policy_data['client_id']; + $client_id = $client_policy_data['client_id'] ?? null; } $branch_units = $this->getBranchUnitsByBranchId($record['client_branch_id']); $branch_units = json_decode($branch_units); - $policy_grid_id = $this->request->getPost('policy_grid_id'); - $rack_rate_name = $this->request->getPost('rack_rate_name'); + $policy_grid_id = $sanitized_post_data['policy_grid_id'] ?? null; + $rack_rate_name = $sanitized_post_data['rack_rate_name'] ?? null; $relation_data = [ - 'self' => $this->request->getPost('self') ?? 'NA', - 'spouse' => $this->request->getPost('spouse') ?? 'NA', - 'childrens' => $this->request->getPost('childrens') ?? 'NA', - 'parents' => $this->request->getPost('parents') ?? 'NA', - 'parents-in-law' => $this->request->getPost('parents-in-law') ?? 'NA', + 'self' => $sanitized_post_data['self'] ?? 'NA', + 'spouse' => $sanitized_post_data['spouse'] ?? 'NA', + 'childrens' => $sanitized_post_data['childrens'] ?? 'NA', + 'parents' => $sanitized_post_data['parents'] ?? 'NA', + 'parents-in-law' => $sanitized_post_data['parents-in-law'] ?? 'NA', ]; $relation_data_for_form_submit_check = [ $rack_rate_name => [ - 'self' => $this->request->getPost('self') ?? 'NA', - 'spouse' => $this->request->getPost('spouse') ?? 'NA', - 'childrens' => $this->request->getPost('childrens') ?? 'NA', - 'parents' => $this->request->getPost('parents') ?? 'NA', - 'parents-in-law' => $this->request->getPost('parents-in-law') ?? 'NA', + 'self' => $sanitized_post_data['self'] ?? 'NA', + 'spouse' => $sanitized_post_data['spouse'] ?? 'NA', + 'childrens' => $sanitized_post_data['childrens'] ?? 'NA', + 'parents' => $sanitized_post_data['parents'] ?? 'NA', + 'parents-in-law' => $sanitized_post_data['parents-in-law'] ?? 'NA', ] ]; @@ -1964,11 +2307,11 @@ class ClientController extends AdminController $jsonDataForRelation = json_encode($relation_data); $json_data_relation_data_for_form_submit_check = json_encode($relation_data_for_form_submit_check); - $si_or_bp = $this->request->getPost('si_or_bp'); - $basic_multiplier = str_replace(',', '', $this->request->getPost('basic_multiplier')); - $premium_multiplier = str_replace(',', '', $this->request->getPost('premium_multiplier')); - $multiplier = str_replace(',', '', $this->request->getPost('multiplier')); - $basic_pay = str_replace(',', '', $this->request->getPost('basic_pay')); + $si_or_bp = $sanitized_post_data['si_or_bp'] ?? null; + $basic_multiplier = str_replace(',', '', $sanitized_post_data['basic_multiplier']); + $premium_multiplier = str_replace(',', '', $sanitized_post_data['premium_multiplier']); + $multiplier = str_replace(',', '', $sanitized_post_data['multiplier']); + $basic_pay = str_replace(',', '', $sanitized_post_data['basic_pay']); $data = []; $data['client_id'] = $client_id; @@ -1990,16 +2333,16 @@ class ClientController extends AdminController if ($si_or_bp == '1') { - $premium = str_replace(',', '', $this->request->getPost('gpa_sum_premium[]')); - $sum_insure = str_replace(',', '', $this->request->getPost('gpa_sum_si[]')); - $multiplier = $this->request->getPost('gpa_sum_multiplier'); - $unit = $this->request->getPost('gpa_unit_1[]'); + $premium = str_replace(',', '', $sanitized_post_data['gpa_sum_premium[]']); + $sum_insure = str_replace(',', '', $sanitized_post_data['gpa_sum_si[]']); + $multiplier = $sanitized_post_data['gpa_sum_multiplier'] ?? null; + $unit = $sanitized_post_data['gpa_unit_1[]'] ?? null; for ($i = 0; $i < count($premium); $i++) { $data['si'] = $sum_insure[$i]; $data['premium'] = $premium[$i]; $data['multiplier'] = $multiplier; - $data['si_or_bp'] = $this->request->getPost('si_or_bp'); + $data['si_or_bp'] = $sanitized_post_data['si_or_bp'] ?? null; if (empty($unit) || !isset($unit[$i]) || empty($unit[$i])) { $data['unit'] = $branch_units[0]; } else { @@ -2010,11 +2353,11 @@ class ClientController extends AdminController } } else if ($si_or_bp == '3') { - $premium = str_replace(',', '', $this->request->getPost('gpa_sum_premium2[]')); - $sum_insure = str_replace(',', '', $this->request->getPost('gpa_sum_si2[]')); - $multiplier = $this->request->getPost('gpa_sum_multiplier2'); - $grade = $this->request->getPost('gpa_band[]'); - $unit = $this->request->getPost('gpa_unit_3[]'); + $premium = str_replace(',', '', $sanitized_post_data['gpa_sum_premium2[]']); + $sum_insure = str_replace(',', '', $sanitized_post_data['gpa_sum_si2[]']); + $multiplier = $sanitized_post_data['gpa_sum_multiplier2'] ?? null; + $grade = $sanitized_post_data['gpa_band[]'] ?? null; + $unit = $sanitized_post_data['gpa_unit_3[]'] ?? null; for ($i = 0; $i < count($premium); $i++) { @@ -2022,7 +2365,7 @@ class ClientController extends AdminController $data['premium'] = $premium[$i]; $data['grade'] = $grade[$i]; $data['multiplier'] = $multiplier; - $data['si_or_bp'] = $this->request->getPost('si_or_bp'); + $data['si_or_bp'] = $sanitized_post_data['si_or_bp'] ?? null; if (empty($unit) || !isset($unit[$i]) || empty($unit[$i])) { $data['unit'] = $branch_units[0]; } else { @@ -2033,17 +2376,17 @@ class ClientController extends AdminController } } else if ($si_or_bp == '2') { - $premium = str_replace(',', '', $this->request->getPost('gpa_basic_premium[]')); - $sum_insure = str_replace(',', '', $this->request->getPost('gpa_basic_si[]')); - $basic_pay = str_replace(',', '', $this->request->getPost('basic_pay[]')); - $unit = $this->request->getPost('gpa_unit[]'); + $premium = str_replace(',', '', $sanitized_post_data['gpa_basic_premium[]']); + $sum_insure = str_replace(',', '', $sanitized_post_data['gpa_basic_si[]']); + $basic_pay = str_replace(',', '', $sanitized_post_data['basic_pay[]']); + $unit = $sanitized_post_data['gpa_unit[]'] ?? null; for ($i = 0; $i < count($premium); $i++) { - $data['si_or_bp'] = $this->request->getPost('si_or_bp'); - $data['basic_multiplier'] = str_replace(',', '', $this->request->getPost('basic_multiplier')); - $data['multiplier'] = $this->request->getPost('premium_multiplier'); + $data['si_or_bp'] = $sanitized_post_data['si_or_bp'] ?? null; + $data['basic_multiplier'] = str_replace(',', '', $sanitized_post_data['basic_multiplier']); + $data['multiplier'] = $sanitized_post_data['premium_multiplier'] ?? null; $data['basic_pay'] = $basic_pay[$i]; $data['si'] = $sum_insure[$i]; $data['premium'] = $premium[$i]; @@ -2057,23 +2400,23 @@ class ClientController extends AdminController } } else { - $data['premium'] = str_replace(',', '', $this->request->getPost('gpa_basic_premium')); - $data['si'] = str_replace(',', '', $this->request->getPost('gpa_basic_si')); - $data['basic_multiplier'] = str_replace(',', '', $this->request->getPost('basic_multiplier')); - $data['multiplier'] = $this->request->getPost('premium_multiplier'); - $data['basic_pay'] = str_replace(',', '', $this->request->getPost('basic_pay')); - $data['si_or_bp'] = $this->request->getPost('si_or_bp'); + $data['premium'] = str_replace(',', '', $sanitized_post_data['gpa_basic_premium']); + $data['si'] = str_replace(',', '', $sanitized_post_data['gpa_basic_si']); + $data['basic_multiplier'] = str_replace(',', '', $sanitized_post_data['basic_multiplier']); + $data['multiplier'] = $sanitized_post_data['premium_multiplier'] ?? null; + $data['basic_pay'] = str_replace(',', '', $sanitized_post_data['basic_pay']); + $data['si_or_bp'] = $sanitized_post_data['si_or_bp'] ?? null; $policyPremium = $this->policyPremium1Model->insert($data); } - $data = $this->request->getPost(); + $data = $sanitized_post_data; $insert = true; } else if ($policy_grid_id == '2') { - $premium = $this->request->getPost('gpa_premium29[]'); - $sum_insure = $this->request->getPost('gpa_si29[]'); - $unit = $this->request->getPost('gpa_unit29[]'); + $premium = $sanitized_post_data['gpa_premium29[]'] ?? null; + $sum_insure = $sanitized_post_data['gpa_si29[]'] ?? null; + $unit = $sanitized_post_data['gpa_unit29[]'] ?? null; for ($i = 0; $i < count($premium); $i++) { $data['premium'] = str_replace(',', '', $premium[$i]); @@ -2086,13 +2429,13 @@ class ClientController extends AdminController $dataa = $this->policyPremium1Model->insert($data); } - $data = $this->request->getPost(); + $data = $sanitized_post_data; $insert = true; } else if ($policy_grid_id == '3') { - $premium = $this->request->getPost('3_premium[]'); - $sum_insure = $this->request->getPost('3_si[]'); - $unit = $this->request->getPost('3_unit[]'); + $premium = $sanitized_post_data['3_premium[]'] ?? null; + $sum_insure = $sanitized_post_data['3_si[]'] ?? null; + $unit = $sanitized_post_data['3_unit[]'] ?? null; for ($i = 0; $i < count($premium); $i++) { $data['premium'] = str_replace(',', '', $premium[$i]); @@ -2104,15 +2447,15 @@ class ClientController extends AdminController } $dataa = $this->policyPremium2Model->insert($data); } - $data = $this->request->getPost(); + $data = $sanitized_post_data; $insert = true; } else if ($policy_grid_id == '4') { - $premium = $this->request->getPost('4_premium[]'); - $sum_insure = $this->request->getPost('4_si'); - $age_from = $this->request->getPost('4_age_from[]'); - $age_to = $this->request->getPost('4_age_to[]'); - $unit = $this->request->getPost('4_unit[]'); + $premium = $sanitized_post_data['4_premium[]'] ?? null; + $sum_insure = $sanitized_post_data['4_si'] ?? null; + $age_from = $sanitized_post_data['4_age_from[]'] ?? null; + $age_to = $sanitized_post_data['4_age_to[]'] ?? null; + $unit = $sanitized_post_data['4_unit[]'] ?? null; for ($i = 0; $i < count($premium); $i++) { $data['premium'] = str_replace(',', '', $premium[$i]); @@ -2127,15 +2470,15 @@ class ClientController extends AdminController $dataa = $this->policyPremium2Model->insert($data); } - $data = $this->request->getPost(); + $data = $sanitized_post_data; $insert = true; } else if ($policy_grid_id == '5') { - $premium = $this->request->getPost('5_premium[]'); - $sum_insure = $this->request->getPost('5_si[]'); - $age_from = $this->request->getPost('5_age_from[]'); - $age_to = $this->request->getPost('5_age_to[]'); - $unit = $this->request->getPost('5_unit[]'); + $premium = $sanitized_post_data['5_premium[]'] ?? null; + $sum_insure = $sanitized_post_data['5_si[]']?? null; + $age_from = $sanitized_post_data['5_age_from[]']?? null; + $age_to = $sanitized_post_data['5_age_to[]']?? null; + $unit = $sanitized_post_data['5_unit[]']?? null; for ($i = 0; $i < count($premium); $i++) { $data['premium'] = str_replace(',', '', $premium[$i]); @@ -2151,15 +2494,15 @@ class ClientController extends AdminController $dataa = $this->policyPremium2Model->insert($data); } - $data = $this->request->getPost(); + $data = $sanitized_post_data; $insert = true; } else if ($policy_grid_id == '6') { - $premium = $this->request->getPost('6_premium[]'); - $sum_insure = $this->request->getPost('6_si'); - $age_from = $this->request->getPost('6_age_from[]'); - $age_to = $this->request->getPost('6_age_to[]'); - $unit = $this->request->getPost('6_unit[]'); + $premium = $sanitized_post_data['6_premium[]']?? null; + $sum_insure = $sanitized_post_data['6_si']?? null; + $age_from = $sanitized_post_data['6_age_from[]']?? null; + $age_to = $sanitized_post_data['6_age_to[]']?? null; + $unit = $sanitized_post_data['6_unit[]']?? null; for ($i = 0; $i < count($premium); $i++) { $data['premium'] = str_replace(',', '', $premium[$i]); @@ -2174,14 +2517,14 @@ class ClientController extends AdminController $dataa = $this->policyPremium2Model->insert($data); } - $data = $this->request->getPost(); + $data = $sanitized_post_data; $insert = true; } else if ($policy_grid_id == '7') { - $premium = $this->request->getPost('7_premium[]'); - $sum_insure = $this->request->getPost('7_si[]'); - $age_from = $this->request->getPost('7_age_from[]'); - $age_to = $this->request->getPost('7_age_to[]'); - $unit = $this->request->getPost('7_unit[]'); + $premium = $sanitized_post_data['7_premium[]'] ?? null; + $sum_insure = $sanitized_post_data['7_si[]'] ?? null; + $age_from = $sanitized_post_data['7_age_from[]'] ?? null; + $age_to = $sanitized_post_data['7_age_to[]'] ?? null; + $unit = $sanitized_post_data['7_unit[]'] ?? null; for ($i = 0; $i < count($premium); $i++) { $data['premium'] = str_replace(',', '', $premium[$i]); @@ -2196,13 +2539,13 @@ class ClientController extends AdminController $dataa = $this->policyPremium2Model->insert($data); } - $data = $this->request->getPost(); + $data = $sanitized_post_data; $insert = true; } else if ($policy_grid_id == '8') { - $premium = $this->request->getPost('8_premium[]'); - $sum_insure = $this->request->getPost('8_si[]'); - $grade = $this->request->getPost('8_grade[]'); - $unit = $this->request->getPost('8_unit[]'); + $premium = $sanitized_post_data['8_premium[]']?? null; + $sum_insure = $sanitized_post_data['8_si[]']?? null; + $grade = $sanitized_post_data['8_grade[]']?? null; + $unit = $sanitized_post_data['8_unit[]']?? null; for ($i = 0; $i < count($premium); $i++) { $data['premium'] = str_replace(',', '', $premium[$i]); @@ -2216,13 +2559,13 @@ class ClientController extends AdminController $dataa = $this->policyPremium2Model->insert($data); } - $data = $this->request->getPost(); + $data = $sanitized_post_data; $insert = true; } else if ($policy_grid_id == '9') { - $premium = $this->request->getPost('gpa_premium29[]'); - $sum_insure = $this->request->getPost('gpa_si29[]'); - $unit = $this->request->getPost('gpa_unit29[]'); + $premium = $sanitized_post_data['gpa_premium29[]']?? null; + $sum_insure = $sanitized_post_data['gpa_si29[]']?? null; + $unit = $sanitized_post_data['gpa_unit29[]']?? null; for ($i = 0; $i < count($premium); $i++) { $data['premium'] = str_replace(',', '', $premium[$i]); @@ -2235,14 +2578,14 @@ class ClientController extends AdminController $dataa = $this->policyPremium2Model->insert($data); } - $data = $this->request->getPost(); + $data = $sanitized_post_data; $insert = true; } else if ($policy_grid_id == '10') { - $premium = $this->request->getPost('10_premium[]'); - $sum_insure = $this->request->getPost('10_si[]'); - $age_from = $this->request->getPost('10_age_from[]'); - $age_to = $this->request->getPost('10_age_to[]'); - $unit = $this->request->getPost('10_unit[]'); + $premium = $sanitized_post_data['10_premium[]']?? null; + $sum_insure = $sanitized_post_data['10_si[]']?? null; + $age_from = $sanitized_post_data['10_age_from[]']?? null; + $age_to = $sanitized_post_data['10_age_to[]']?? null; + $unit = $sanitized_post_data['10_unit[]']?? null; for ($i = 0; $i < count($premium); $i++) { $data['premium'] = str_replace(',', '', $premium[$i]); @@ -2258,15 +2601,15 @@ class ClientController extends AdminController $policyPremium = $this->policyPremium2Model->insert($data); } - $data = $this->request->getPost(); + $data = $sanitized_post_data; $insert = true; } else if ($policy_grid_id == '11') { - $premium = $this->request->getPost('11_premium[]'); - $sum_insure = $this->request->getPost('11_si[]'); - $grade = $this->request->getPost('11_grade[]'); - $max_sum_insure = $this->request->getPost('11_max_si[]'); - $unit = $this->request->getPost('11_unit[]'); + $premium = $sanitized_post_data['11_premium[]']?? null; + $sum_insure = $sanitized_post_data['11_si[]']?? null; + $grade = $sanitized_post_data['11_grade[]']?? null; + $max_sum_insure = $sanitized_post_data['11_max_si[]']?? null; + $unit = $sanitized_post_data['11_unit[]']?? null; for ($i = 0; $i < count($premium); $i++) { $data['premium'] = str_replace(',', '', $premium[$i]); @@ -2281,14 +2624,14 @@ class ClientController extends AdminController $dataa = $this->policyPremium2Model->insert($data); } - $data = $this->request->getPost(); + $data = $sanitized_post_data; $insert = true; } else if ($policy_grid_id == '12') { - $premium = $this->request->getPost('12_premium[]'); - $sum_insure = $this->request->getPost('12_si[]'); - $relationship = $this->request->getPost('12_relationship[]'); - $unit = $this->request->getPost('12_unit[]'); + $premium = $sanitized_post_data['12_premium[]']?? null; + $sum_insure = $sanitized_post_data['12_si[]']?? null; + $relationship = $sanitized_post_data['12_relationship[]']?? null; + $unit = $sanitized_post_data['12_unit[]']?? null; for ($i = 0; $i < count($premium); $i++) { $data['premium'] = str_replace(',', '', $premium[$i]); @@ -2302,16 +2645,16 @@ class ClientController extends AdminController $dataa = $this->policyPremium2Model->insert($data); } - $data = $this->request->getPost(); + $data = $sanitized_post_data; $insert = true; } else if ($policy_grid_id == '13') { - $premium = $this->request->getPost('13_premium[]'); - $sum_insure = $this->request->getPost('13_si[]'); - $age_from = $this->request->getPost('13_age_from[]'); - $age_to = $this->request->getPost('13_age_to[]'); - $relationship = $this->request->getPost('13_relationship[]'); - $unit = $this->request->getPost('13_unit[]'); + $premium = $sanitized_post_data['13_premium[]']?? null; + $sum_insure = $sanitized_post_data['13_si[]']?? null; + $age_from = $sanitized_post_data['13_age_from[]']?? null; + $age_to = $sanitized_post_data['13_age_to[]']?? null; + $relationship = $sanitized_post_data['13_relationship[]']?? null; + $unit = $sanitized_post_data['13_unit[]']?? null; for ($i = 0; $i < count($premium); $i++) { $data['premium'] = str_replace(',', '', $premium[$i]); @@ -2327,7 +2670,7 @@ class ClientController extends AdminController $dataa = $this->policyPremium2Model->insert($data); } - $data = $this->request->getPost(); + $data = $sanitized_post_data; $insert = true; } @@ -2498,10 +2841,11 @@ class ClientController extends AdminController if(empty($params) && $this->request){ $data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); $files = $this->request->getFiles(); - $client_id = $data['client_id'] ?? null; - $vehicle_id = $data['vehicle_id'] ?? null; - $docs_name = $data['other_docs_name'] ?? null; + $client_id = $sanitized_post_data['client_id'] ?? null; + $vehicle_id = $sanitized_post_data['vehicle_id'] ?? null; + $docs_name = $sanitized_post_data['other_docs_name'] ?? null; }else { $client_id = $params['client_id'] ?? null; $vehicle_id = $params['vehicle_id'] ?? null; @@ -2552,8 +2896,8 @@ class ClientController extends AdminController if (!empty($insertedDocs)) { // Fetch all documents for the client $vehicleDocs = $this->clientKYCDocsModel - ->where('client_id', $data['client_id']) - ->where('vehicle_id', $data['vehicle_id']) + ->where('client_id', $sanitized_post_data['client_id']) + ->where('vehicle_id', $sanitized_post_data['vehicle_id']) ->findAll(); return $this->respond(['status' => true, 'code' => 200, 'vehicle_docs' => $vehicleDocs, 'inserted_docs' => $insertedDocs, 'message' => 'File uploaded successfully'], 200); } else { @@ -5192,12 +5536,72 @@ class ClientController extends AdminController public function createVehicleWithMinimalData() { + $rules = [ + 'Owner_type' => [ + 'rules' => 'required|in_list[1,2]', + 'errors' => [ + 'required' => 'Owner type is required', + 'in_list' => 'Invalid owner type selected' + ] + ], + 'vehicle_no' => [ + 'rules' => 'required|regex_match[/^[A-Z]{2}[0-9]{2}[A-Z]{1,2}[0-9]{4}$/]', + 'errors' => [ + 'required' => 'Vehicle number is required', + 'regex_match' => 'Invalid Vehicle Number. Example: TN22AB1234' + ] + ], + 'rc' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'RC Book number is required' + ] + ], + + 'type' => [ + 'rules' => 'required|is_natural_no_zero', + 'errors' => [ + 'required' => 'Vehicle type is required' + ] + ], + + 'description' => [ + 'rules' => 'required|is_natural_no_zero', + 'errors' => [ + 'required' => 'Vehicle description is required' + ] + ], + 'owner' => [ + 'rules' => 'required|is_natural_no_zero', + 'errors' => [ + 'required' => 'Owner is required' + ] + ], + + 'old_onwer' => [ + 'rules' => 'permit_empty|alpha_space', + 'errors' => [ + 'alpha_space' => 'Old owner name can contain only letters and spaces' + ] + ], + + ]; + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } $data = $this->request->getPost(); - $id = $this->request->getPost('vehicle_primary_key'); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + $id = $sanitized_post_data['vehicle_primary_key'] ?? null; + if ($id) { - $vehicle_update = $this->vehicleModel->where('id', $id)->set($data)->update(); + $vehicle_update = $this->vehicleModel->where('id', $id)->set($sanitized_post_data)->update(); if ($vehicle_update) { return $this->respond(['status' => true, 'message' => 'Vehicle details updated successfully'], 200); @@ -5206,7 +5610,7 @@ class ClientController extends AdminController } } else { - $vehicle_insert = $this->vehicleModel->insert($data); + $vehicle_insert = $this->vehicleModel->insert($sanitized_post_data); if ($vehicle_insert) { @@ -5219,9 +5623,9 @@ class ClientController extends AdminController return $this->respond([ 'status' => true, 'vehicle_id' => $vehicle_insert, - 'owner_id' => $data['owner'], - 'owner_branch_id' => $data['branch_id'] ?? null, - 'owner_type' => $data['Owner_type'], + 'owner_id' => $sanitized_post_data['owner'] ?? null, + 'owner_branch_id' => $sanitized_post_data['branch_id'] ?? null, + 'owner_type' => $sanitized_post_data['Owner_type']?? null, 'vehicles' => $vehicles, 'message' => 'Vehicle created successfully ' @@ -6179,6 +6583,14 @@ class ClientController extends AdminController // $response = $ticketServiceController->getClaimExcelErrorData(["file_id" => 41]); // $response = $ticketServiceController->claimDumpOnBoardProcess(["file_id" => 17]); // $response = $ticketServiceController->extractExcelData("claims_dump_form_client.xlsx"); + // $response = $ticketServiceController->tpaClaimDumpImporter(["file_id" => 52]); //reliance + // $response = $ticketServiceController->tpaClaimDumpImporter(["file_id" => 50]); //fhpl + // $response = $ticketServiceController->tpaClaimDumpImporter(["file_id" => 51]); //abhi + // $response = $ticketServiceController->tpaClaimDumpImporter(["file_id" => 48]); //vidal + // $response = $ticketServiceController->tpaClaimDumpImporter(["file_id" => 53]); //icici + // $response = $ticketServiceController->tpaClaimDumpImporter(["file_id" => 54]); //mediassist + // $response = $ticketServiceController->tpaClaimDumpToTicketMasterImporters(["file_id" => 48]); + // $response = $ticketServiceController->tpaClaimDumpToTicketMasterImporters(["file_id" => 48]); // dd($response); // ---------- TICKET CONTROLLER -------------------------------------------------------------------------------- @@ -6193,7 +6605,8 @@ class ClientController extends AdminController $empServiceController = new EmployeeServiceController(); // $res = $empServiceController->excelFileFormatValidation(['file_id' => '1248']); // $res = $empServiceController->excelFileDataValidation(['file_id' => '1252']); - // $res = $empServiceController->employeesOnboardPreprocess(['file_id' => 1183]); + // $res = $empServiceController->employeesOnboardPreprocess(['file_id' => 1263]); + // $res = $empServiceController->employeesOnboardPreprocess(['file_id' => 1262]); // $res = $empServiceController->employeesOnboardPreprocess(['file_id' => 1169]); // $res = $empServiceController->employeesOnboardProcess(['file_id' => 835]); // $res = $empServiceController->employeesEnrollmentInsert(['file_id' => 836]); @@ -6319,8 +6732,8 @@ class ClientController extends AdminController // $res = $LeadsController->convertQCRJsonToPolicyTerms($jsonArray, $policy_type, $proposel_name, $insurer_name); // $res = $LeadsController->handleMemberDataGPATotalSumInsurerFromExcel(['lead_id' => 169]); // $res = $LeadsController->reorderProposalsByInsurerTotal($jsonArray); - // $res = $LeadsController->calculateMembersDemography(['lead_id' => 326]); - // $res = $LeadsController->generateDemographyDataTable(['lead_id' => 326]); + // $res = $LeadsController->calculateMembersDemography(['lead_id' => 287], "internal"); + // $res = $LeadsController->generateDemographyDataTable(['lead_id' => 287]); // echo $res; // dd($res); diff --git a/app/Controllers/EmployeeController.php b/app/Controllers/EmployeeController.php index 1f996e53..b662d8b1 100755 --- a/app/Controllers/EmployeeController.php +++ b/app/Controllers/EmployeeController.php @@ -1108,7 +1108,39 @@ class EmployeeController extends AdminController try { - $filePath = WRITEPATH . '/uploads/excel/' . $file_name['file_name']; + if (!$file_name) { + return $this->respond([ + 'dataStatus' => false, + 'code' => 200, + 'data' => '
No Data Found
', + 'file_data' => null + ], 200); + } + + $filePath = WRITEPATH . 'uploads/excel/' . $file_name['file_name']; + + // ✅ File not exists on disk + if (!file_exists($filePath)) { + return $this->respond([ + 'dataStatus' => false, + 'code' => 200, + 'data' => '
No Data Found
', + 'file_data' => $file_name + ], 200); + } + + + $excel_data = $empDataServiceController->readExcelFileToArray($filePath); + + // ✅ Excel empty or header only + if (empty($excel_data) || count($excel_data) <= 1) { + return $this->respond([ + 'dataStatus' => false, + 'code' => 200, + 'data' => '
No Data Found
', + 'file_data' => $file_name + ], 200); + } if (file_exists($filePath)) { @@ -1144,8 +1176,7 @@ class EmployeeController extends AdminController $errorMessage = 'Error occurred:' . PHP_EOL . json_encode($errorData, JSON_PRETTY_PRINT); $this->myLogger->logme('error', $errorMessage); - $html = '
No Data Found
'; - return $this->respond(['dataStatus' => false, 'code' => 500, 'data' => $html, 'file_data' => $file_name], 500); + return $this->respond(['dataStatus' => false, 'code' => 500, 'data' => '
Something went wrong
', 'file_data' => $file_name ?? null], 500); } } @@ -2676,12 +2707,73 @@ class EmployeeController extends AdminController //UPDATE EMPLOYEE public function update_emp_data() { - $data = $this->request->getPost(); + + $rules = [ + 'emp_code' => [ + 'rules' => 'required', + 'errors' => [ + 'required' => 'Employee Code is missing' + ] + ], + + 'name' => [ + 'rules' => 'required|min_length[2]|max_length[100]', + 'errors' => [ + 'required' => 'Employee name is required', + 'min_length' => 'Name must be at least 2 characters', + 'max_length' => 'Name cannot exceed 100 characters' + ] + ], + 'gender' => [ + 'rules' => 'permit_empty|in_list[M,F]', + 'errors' => [ + 'in_list' => 'Invalid gender selected' + ] + ], + 'email_corporate' => [ + 'rules' => 'required|valid_email', + 'errors' => [ + 'required' => 'Email is required', + 'valid_email' => 'Enter a valid email address' + ] + ], + + 'mobile' => [ + 'rules' => 'required|numeric|exact_length[10]', + 'errors' => [ + 'required' => 'Mobile number is required', + 'numeric' => 'Mobile number must contain digits only', + 'exact_length' => 'Mobile number must be exactly 10 digits' + ] + ], + ]; + $request_post_data = $this->request->getPost(); + $data = sanitizeInputArrayAdvanced($request_post_data); + if (isset($data['relationship'])) { + $rules['relationship'] = [ + 'rules' => 'required|in_list[Self,Spouse,Child,Father,Mother,Father-in-law,Mother-in-law]', + 'errors' => [ + 'required' => 'Relationship is required', + 'in_list' => 'The selected relationship is invalid.' + ] + ]; + } + + + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } + + + // print_rr($data);die(); // $data['dob'] = date('Y-m-d', strtotime($data['dob'])); - if(isset( $data['dob'])){ - $data['dob'] = change_date_format($data['dob'], null, 'Y-m-d'); - } + $data['dob'] = (!empty($data['dob'])) ? change_date_format($data['dob'], null, 'Y-m-d') : null; // print_rr($data); die; // Fetch current employee data @@ -2971,12 +3063,15 @@ class EmployeeController extends AdminController } public function mapEmployees(){ - $client_id = $this->request->getPost('client_id'); - $branch_id = $this->request->getPost('branch_id'); - $policy_id = $this->request->getPost('client_policy_id'); - $selected_employees = (array)$this->request->getPost('selected'); - $si_amt = $this->request->getPost('si_amt'); - $policy_start_date_unformatted = $this->request->getPost('policy_start_date'); + $request_post_data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($request_post_data); + + $client_id = $sanitized_post_data['client_id'] ?? null; + $branch_id = $sanitized_post_data['branch_id'] ?? null; + $policy_id = $sanitized_post_data['client_policy_id'] ?? null; + $selected_employees = (array)$sanitized_post_data['selected'] ?? []; + $si_amt = $sanitized_post_data['si_amt'] ?? null; + $policy_start_date_unformatted = $sanitized_post_data['policy_start_date'] ?? null; $policy_start_date = change_date_format($policy_start_date_unformatted, 'd/M/Y', 'Y-m-d'); @@ -3013,7 +3108,9 @@ class EmployeeController extends AdminController } public function unmapEmployees($actionType){ - $selected_employees = (array)$this->request->getPost('selected'); + $request_post_data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($request_post_data); + $selected_employees = (array)$sanitized_post_data['selected'] ?? []; if($actionType == 0){ for($i = 0;$iemployeeModel->set(['client_id' => null, 'client_branch_id' => null])->where('id',$selected_employees[$i])->update();log_message('error',$result1); @@ -3273,7 +3370,31 @@ class EmployeeController extends AdminController public function retailendorsementsave() { try { - $data = $this->request->getPost(); + $rules = [ + 'endorsement_no' => [ + 'rules' => 'required', + 'errors' => [ + 'required' => 'Endorsement Number is missing' + ] + ], + 'status' => [ + 'rules' => 'required', + 'errors' => [ + 'required' => 'Status is required', + ] + ] + ]; + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } + $request_post_data = $this->request->getPost(); + $data = sanitizeInputArrayAdvanced($request_post_data); + if (!empty($data['id'])) { $text = "update"; $updateID = $data['id']; diff --git a/app/Controllers/EmployeeRestController.php b/app/Controllers/EmployeeRestController.php index c2f9f397..fa58834a 100755 --- a/app/Controllers/EmployeeRestController.php +++ b/app/Controllers/EmployeeRestController.php @@ -1665,10 +1665,10 @@ class EmployeeRestController extends AdminController { try { - $client = $this->clientModel->where('id', $this->request->getGet('client_id'))->first(); + $client = $this->clientModel->where('md5(id)', $this->request->getGet('client_id'))->first(); if (!empty($client)) { $client['client_logo'] = base_url() . 'public/uploads/logo/' . $client['client_logo']; - $clientPolicy = $this->clientPolicyModel->where('client_id', $this->request->getGet('client_id')) + $clientPolicy = $this->clientPolicyModel->where('md5(client_id)', $this->request->getGet('client_id')) ->where('client_branch_id', $this->request->getGet('client_branch_id'))->findAll(); return $this->respond(['status' => 'success', 'code' => 200, 'data' => ['client' => $client, 'client_policy' => $clientPolicy]], 200); } else { @@ -2307,7 +2307,7 @@ class EmployeeRestController extends AdminController $ClientPolicyData = $this->clientPolicyModel->select('client_policy.id as client_policy_id , client_policy.client_id as client_id, client_policy.policy_type_id as policy_type_id, client_policy.is_addon as is_addon , client_policy.open_for_enrollment as OpenForEnrollment , client_policy.inception_type as inception_type, client_policy.policy_no as policy_no, client_policy.insurer_id as insurer_id, DATE_FORMAT(client_policy.policy_end_date, "%d-%m-%Y") AS policy_expiry_date ') - ->where('client_policy.client_id', $this->request->getGet('client_id')) + ->where('md5(client_policy.client_id)', $this->request->getGet('client_id')) ->where('client_policy.client_branch_id', $this->request->getGet('client_branch_id')) ->where('client_policy.is_active', 1) ->where('client_policy.policy_status', $this->request->getGet('policy_status')) @@ -2329,7 +2329,7 @@ class EmployeeRestController extends AdminController // dd($employeeDetails); $activeCount = 0; $inactiveCount = 0; - if (count($employeeDetails)) { + if (count($employeeDetails)) { foreach ($employeeDetails as $item) { if ($item['emp_status'] === 'active') { $activeCount++; @@ -2555,7 +2555,7 @@ class EmployeeRestController extends AdminController $builder->where('tm.is_active', 1); if ($client_id > 0) { - $builder->where('tm.client_id', $client_id); + $builder->where('md5(tm.client_id)', $client_id); } if (!empty($from_date) && !empty($to_date)) { @@ -3658,7 +3658,7 @@ class EmployeeRestController extends AdminController where emp.id = :employee_id: and emp.is_active = 1 and emp.emp_status = 'active' limit 1 "; - $binds = ['insured_emp_id'=>$insured_emp_id,'client_policy_id'=>(int)$client_policy_id,'$employee_id'=>$employee_id ]; + $binds = ['insured_emp_id'=>$insured_emp_id,'client_policy_id'=>(int)$client_policy_id,'employee_id'=>$employee_id ]; $emp_ticket_data = $this->employeeModel->query($sql,$binds)->getResultArray(); // print_r(db_connect()->getLastQuery()); die; @@ -4468,7 +4468,21 @@ class EmployeeRestController extends AdminController return $this->respondCreated(['status' => false, 'message' => 'Client is required', 'data' => []]); } - $client_data = $this->clientModel->where('id', $post_data['client_id'])->first(); + // Handle raw client_id vs MD5 + if (is_string($post_data['client_id']) && preg_match('/^[a-f0-9]{32}$/i', $post_data['client_id'])) { + $client_data = $this->clientModel->where('MD5(id)', $post_data['client_id'])->first(); + } else { + $client_data = $this->clientModel->where('id', $post_data['client_id'])->first(); + } + + if(empty($client_data)){ + return $this->respondCreated(['status' => false, 'message' => 'Invalid Client Id', 'data' => []]); + } + + $post_data['client_id'] = $client_data['id']; + + + // print_r($client_data); die; if($client_data['hr_file_processed_by'] == 1){ diff --git a/app/Controllers/FhplApiController.php b/app/Controllers/FhplApiController.php index 33037652..9497433c 100644 --- a/app/Controllers/FhplApiController.php +++ b/app/Controllers/FhplApiController.php @@ -27,13 +27,13 @@ class FhplApiController extends BaseController public function generateAuthToken() { - $url = env('FHPL_TOKEN_URL'); // example: https://uat.fhpl.net/token + $url = env('FHPL_TOKEN_URL'); // x-www-form-urlencoded body $postData = http_build_query([ - 'UserName' => 'TestApi@fhpl', - 'Password' => 'Fhpl@12345', - 'grant_type' => 'password', + 'UserName' => env('FHPL_USER_NAME'), + 'Password' => env('FHPL_PASSWORD'), + 'grant_type' => env('FHPL_GRANT_TYPE'), ]); $ch = curl_init(); @@ -65,9 +65,447 @@ class FhplApiController extends BaseController return $this->response->setJSON([ 'status' => $httpCode === 200, 'http_code' => $httpCode, - 'response' => json_decode($response, true), + 'data' => json_decode($response, true), ]); } + public function SubmitClaim($claimId = 515) + { + helper('api'); + + $data = $this->db->table('ticket_master tm') + ->select(' + tm.id, + tm.emp_mobile as mobileNo, + tm.emp_mail as emailId, + tm.doa as admissionDate, + tm.dod as dischargeDate, + tm.hospital_name as hospitalName, + tm.claim_amount as requestedAmount, + tm.tpa_no as dependentUniqueId, + cp.policy_no as policyNo, + e.emp_code as memberId, + tn.note as disease, + cf.url as filePath + ') + ->join('employees e', 'e.id = tm.emp_id', 'left') + ->join('client_policy cp', 'tm.client_policy_id = cp.id', 'left') + ->join('ticket_notes tn', 'tn.ticket_id = tm.id', 'left') + ->join('claim_files cf', "cf.ticket_id = tm.id AND cf.file_type = 2 AND cf.mime_type='application/pdf'", 'left') + ->where('tm.id', $claimId) + ->get() + ->getRowArray(); + + + if (count($data) && $data['filePath'] == null) { + log_message('error', "TPA CLAIM PUSH FAILED FHPL | claimId: '.$claimId.' - Claim or File Missing"); + return $this->response->setJSON(['status' => false,'message' => 'Claim or File Missing', ]); + } + + // Build absolute file path + $filename = basename($data['filePath']); + $pdfPath = WRITEPATH . 'uploads/claim_files/' . $filename; + + if (!file_exists($pdfPath)) { + log_message('error', "TPA CLAIM PUSH FAILED FHPL | claimId: '.$claimId.' - PDF not found on server"); + return $this->response->setJSON(['status' => false,'message' => 'PDF not found on server']); + } + + // Convert PDF to Base64 + $fileContent = base64_encode(file_get_contents($pdfPath)); + + // Generate FHPL Token + $tokenResponse = json_decode($this->generateAuthToken()->getBody(), true); + if (empty($tokenResponse['data']['access_token'])) { + return $this->response->setJSON(['status' => false,'message' => 'FHPL Token generation failed']); + } + $token = $tokenResponse['data']['access_token']; + + // Build FHPL Request + $body = [ + "IssueID" => $data['dependentUniqueId'], // this key added after seeing the error in responce have to click with fhpl team + "Userid" => getenv('FHPL_USER_NAME'), + "PolicyNo" => "111700-TATAMTORS", // $data['policyNo'], + "UhidNo" => "OIC40830846", //$data['dependentUniqueId'], + "ClaimID" => (string) $data['id'], + "DOA" => "2025-10-11",//date('Y-m-d', strtotime($data['admissionDate'])), + "DateofDischarge"=> $data['dischargeDate'] ? date('Y-m-d', strtotime($data['dischargeDate'])) : null, + "ClaimedAmount" => (float) $data['requestedAmount'], + "DocumentType" => 20, // Fresh Claim + "PayeeName" => $data['memberId'], + "HospitalName" => $data['hospitalName'], + "MobileNo" => $data['mobileNo'], + "Documents" => [ + [ + "documentName" => $filename, + "documentCategory" => "IRR", + "filecontent" => $fileContent + ] + ] + ]; + + $url = getenv('FHPL_BASE_URL') . "/api/ClaimSubmission"; + + $headers = [ + "Authorization: Bearer " . $token, + "Content-Type: application/json" + ]; + + log_message('error', 'TPA CLAIM PUSH FHPL | claimId: '.$claimId.' | payload: '.json_encode($body)); + + $response = call_third_party_api($url, 'POST', $headers, $body); + + log_message('error', 'FHPL RESPONSE | ' . json_encode($response)); + + if($response['status'] != true){ + log_message('error', 'TPA CLAIM PUSH FAILED FHPL | claimId: '.$claimId.' | response: '.json_encode($response)); + $this->db->table('ticket_master') + ->where('id',$claimId) + ->update([ 'tpa_push_response' => json_encode($response) ]); + return; + } + + + if ($response['status'] === true && !empty($response['data'][0]['ClaimsInfo'])) + { + $claimsInfo = json_decode($response['data'][0]['ClaimsInfo'], true); + + if (!empty($claimsInfo[0]['ClaimID'])) { + + $fhplClaimNo = $claimsInfo[0]['ClaimID']; + + $this->db->table('ticket_master') + ->where('id', $claimId) + ->update([ + 'claim_number' => $fhplClaimNo, + 'tpa_claim_id' => $fhplClaimNo, + 'tpa_claim_push_reference_no' => $fhplClaimNo, + 'updated_at' => date('Y-m-d H:i:s') + ]); + + log_message('error', 'TPA CLAIM PUSH SUCCESS FHPL | claimId: '.$claimId.' | claimNO: '.$fhplClaimNo); + + } + } + + + return $this->response->setJSON($response); + } + + public function ClaimDetail($claimId = 515) + { + helper('api'); + + $ticket = $this->db->table('ticket_master tm') + ->select("tm.id, tm.tpa_claim_id as claimNo, cp.policy_no , cp.policy_start_date , cp.policy_end_date") + ->join('client_policy cp','tm.client_policy_id=cp.id') + ->where('tm.id',$claimId) + ->get()->getRowArray(); + + + if(!$ticket) return $this->response->setJSON(['status'=>false,'message'=>'Invalid claim']); + + // Generate FHPL Token + $tokenResponse = json_decode($this->generateAuthToken()->getBody(), true); + + if (empty($tokenResponse['data']['access_token'])) { + return $this->response->setJSON(['status' => false,'message' => 'FHPL Token generation failed']); + } + + $token = $tokenResponse['data']['access_token']; + + $url = getenv('FHPL_BASE_URL')."/api/GetTPA_ClaimsDetails"; + + $body = [ + "UserName" => getenv('FHPL_USER_NAME'), + "Password" => getenv('FHPL_PASSWORD'), + "PolicyNumber" => "GHI-81-25-00087313-000",//$ticket['policy_no'], + "Fromdate" => "2025-04-26",//$ticket['claimNo'], + "Todate" => "2025-04-27",//$ticket['claimNo'], + ]; + + $headers = ["Authorization: Bearer ".$token,"Content-Type: application/json"]; + + $response = call_third_party_api($url,'POST',$headers,$body); + + // dd($response); + + if (empty($response['data'][0])) { + log_message('error', 'CLAIM STATUS FAILED | for ticket ID: ' . $claimId.' | response: '.json_encode($response)); + + return $this->response->setJSON([ + 'status' => false, + 'message' => 'API call failed.', + 'data' => $response + ]); + } + + + $status = null; + + // find this claim + foreach($response['data'] as $row){ + if($row['CLAIM_ID']==$ticket['claimNo']){ + $status = $row['CLAIM_STATUS']; + } + } + + $map = [ + "In-Progress" => 5, + "Under Process" => 5, + "Query" => 4, + "Paid" => 11, + "Rejected" => 8, + "Approved" => 8, + "Required Information" => 4, + ]; + + if( $status != null && isset($map[$status])) + { + $this->db->table('ticket_master')->where('id',$claimId)->update(['claim_status_id'=>$map[$status],'tpa_claim_status'=>$status]); + // LOG UPDATE + log_message('error', "CLAIM STATUS SUCCESS | Updated ticket ID $claimId with claim status: $status"); + } + + + + return $this->response->setJSON([ + 'status' => true, + 'message' => 'Claim status updated.', + 'updated_status' => $status, + 'api_response' => $response + ]); + + } + + public function ClaimStatusUpdate() + { + helper('api'); + + $tickets = $this->db->table('ticket_master tm') + ->select("tm.id,tm.tpa_claim_id,cp.policy_no") + ->join('client_policy cp','tm.client_policy_id=cp.id') + ->where('tm.tpa_claim_id IS NOT NULL') + ->get()->getResultArray(); + + $count=0; + + foreach($tickets as $t){ + $this->ClaimDetail($t['id']); + $count++; + } + + return $this->response->setJSON(['status'=>true,'updated'=>$count]); + } + + public function EcardRequest($employeeId,$policyNo,$uhid) + { + helper('api'); + + // Generate FHPL Token + $tokenResponse = json_decode($this->generateAuthToken()->getBody(), true); + + if (empty($tokenResponse['data']['access_token'])) { + return $this->response->setJSON(['status' => false,'message' => 'FHPL Token generation failed']); + } + + // Generate FHPL Token + $tokenResponse = json_decode($this->generateAuthToken()->getBody(), true); + + if (empty($tokenResponse['data']['access_token'])) { + return $this->response->setJSON(['status' => false,'message' => 'FHPL Token generation failed']); + } + + $token = $tokenResponse['data']['access_token']; + + $url = getenv('FHPL_BASE_URL')."/api/GetEcard"; + + $body = [ + "UserName" => getenv('FHPL_USER_NAME'), + "Password" => getenv('FHPL_PASSWORD'), + "PolicyNumber" => $policyNo, + "EmployeeID" => $employeeId + ]; + + $headers = ["Authorization: Bearer ".$token,"Content-Type: application/json"]; + + $response = call_third_party_api($url,'POST',$headers,$body); + + if(($response['data']['STATUS'] ?? '')=='SUCCESS'){ + return $response['data']['E_Card']; + } + + return null; + } + + public function FhplGetBenefDetails($requestData = null) + { + helper('api'); + + $policyNo = $requestData['policy_no'] ?? "10/12/2025/16/17"; + $client_policy_id = $requestData['client_policy_id'] ?? 0; + + // Generate FHPL Token + $tokenResponse = json_decode($this->generateAuthToken()->getBody(), true); + if (empty($tokenResponse['data']['access_token'])) { + return $this->response->setJSON(['status' => false,'message' => 'FHPL Token generation failed']); + } + $token = $tokenResponse['data']['access_token']; + + $url = getenv('FHPL_BASE_URL')."/api/GetEnrollmentDetailsPolicy"; + + $headers = [ + "Authorization: Bearer ".$token, + "Content-Type: application/json" + ]; + + $startIndex = 0; + $range = 100; + $allMembers = []; + + do { + $body = [ + "UserName" => getenv('FHPL_USER_NAME'), + "Password" => getenv('FHPL_PASSWORD'), + "PolicyNumber" => $policyNo, + "StartIndex" => $startIndex, + "Range" => $range + ]; + + $response = call_third_party_api($url,'POST',$headers,$body); + + dd($response); + + if(empty($response['data']['Members'])){ + break; + } + + $allMembers = array_merge($allMembers,$response['data']['Members']); + + $startIndex += $range; + + } while($startIndex < ($response['data']['Total'] ?? 0)); + + + dd($allMembers); + + // Now same matching logic you already have + $employeePolicyModel = new EmployeePolicyModel(); + + $employeePolicyData = $employeePolicyModel + ->join('employees','employees.id=employee_polices.employee_id') + ->where('employee_polices.client_policy_id',$client_policy_id) + ->where('employee_polices.tpa_id IS NULL') + ->findAll(); + + $updated = 0; + + foreach($employeePolicyData as $policy){ + foreach($allMembers as $m){ + + if( + strtolower(trim($policy['name']))==strtolower(trim($m['Name'])) && + $policy['emp_code']==$m['MemberID'] && + strtolower($policy['relationship'])==strtolower($m['Relation']) + ){ + $this->db->table('employee_polices') + ->where('id',$policy['emp_policy_id']) + ->update(['tpa_id'=>$m['UHID']]); + + $updated++; + } + } + } + + return [ + 'status'=>true, + 'total_fetched'=>count($allMembers), + 'updated'=>$updated + ]; + } + + public function syncFhplClaimsToNhance() + { + helper('api'); + + // Generate FHPL Token + $tokenResponse = json_decode($this->generateAuthToken()->getBody(), true); + + if (empty($tokenResponse['data']['access_token'])) { + return $this->response->setJSON(['status' => false,'message' => 'FHPL Token generation failed']); + } + + $token = $tokenResponse['data']['access_token']; + + $url = getenv('FHPL_BASE_URL')."/api/GetTPA_ClaimsDetails"; + + $headers = [ + "Authorization: Bearer ".$token, + "Content-Type: application/json" + ]; + + $policies = $this->db->table('client_policy') + ->where('tpa_id',$this->fhplTpaId) + ->get()->getResultArray(); + + $finalResult=[]; + + foreach($policies as $policy){ + + $body = [ + "UserName" => getenv('FHPL_USER_NAME'), + "Password" => getenv('FHPL_PASSWORD'), + "PolicyNumber" => $policy['policy_no'], + "Fromdate" => $policy['policy_start_date'], + "Todate" => $policy['policy_end_date'] + ]; + + $response = call_third_party_api($url,'POST',$headers,$body); + + if(!empty($response['data'])){ + $finalResult = array_merge($finalResult,$response['data']); + } + } + + // Insert / update ticket_master same way you already do for MediAssist + foreach($finalResult as $row){ + + $status = $row['CLAIM_STATUS']; + + $map = [ + "Under Process"=>5, + "Paid"=>11, + "Rejected"=>8, + "Approved"=>8 + ]; + + $claimStatus = $map[$status] ?? 1; + + $this->db->table('ticket_master')->insert([ + 'policy_no'=>$row['POLICY_NO'], + 'claim_number'=>$row['CLAIM_ID'], + 'tpa_claim_id'=>$row['CLAIM_ID'], + 'emp_code'=>$row['EMPLOYEE_NO'], + 'insured_name'=>$row['PATIENT_NAME'], + 'claim_amount'=>$row['CLAIM_AMOUNT'], + 'hospital_name'=>$row['HOSPITAL_NAME'], + 'doa'=>$row['DATE_OF_ADMISSION'], + 'dod'=>$row['DATE_OF_DISCHARGE'], + 'claim_status_id'=>$claimStatus, + 'tpa_id'=>$this->fhplTpaId + ]); + } + + return ['status'=>true,'total'=>count($finalResult)]; + } + + + + + + + + + } diff --git a/app/Controllers/JobWorker.php b/app/Controllers/JobWorker.php index 9cc001dd..160c6fe9 100755 --- a/app/Controllers/JobWorker.php +++ b/app/Controllers/JobWorker.php @@ -155,6 +155,14 @@ class JobWorker extends AdminController 'type' => 'CC', // Handler Category 'handler' => 'App\Controllers\TicketServiceController', ], + 'tpaClaimDumpImporter' => [ + 'type' => 'CC', // Handler Category + 'handler' => 'App\Controllers\TicketServiceController', + ], + 'tpaClaimDumpToTicketMasterImporters' => [ + 'type' => 'CC', // Handler Category + 'handler' => 'App\Controllers\TicketServiceController', + ], 'excelMultieventFileFormateValidation' => [ 'type' => 'CC', // Handler Category 'handler' => 'App\Controllers\EmployeeMultiEventServiceController', diff --git a/app/Controllers/LeadsController.php b/app/Controllers/LeadsController.php index c9150148..8154fc82 100644 --- a/app/Controllers/LeadsController.php +++ b/app/Controllers/LeadsController.php @@ -378,7 +378,95 @@ class LeadsController extends BaseController private function prepareLeadData() { - $data = $this->request->getPost(); + $rules = [ + 'lead_type' => [ + 'rules' => 'required', + 'errors' => ['required' => 'Lead Type is required'] + ], + 'issuer' => [ + 'rules' => 'required', + 'errors' => ['required' => 'Issuer is required'] + ], + 'entity_type_id' => [ + 'rules' => 'required', + 'errors' => ['required' => 'Entity Type is required'] + ], + 'client_name' => [ + 'rules' => 'required', + 'errors' => ['required' => 'Client Name is required'] + ], + 'client_short_name' => [ + 'rules' => 'required', + 'errors' => ['required' => 'Client Short Name is required'] + ], + 'gst' => [ + 'rules' => 'required', + 'errors' => ['required' => 'GST Number is required'] + ], + 'branch_name' => [ + 'rules' => 'required', + 'errors' => ['required' => 'Branch Name is required'] + ], + 'branch_code' => [ + 'rules' => 'required', + 'errors' => ['required' => 'Branch Code is required'] + ], + 'contact_person_name' => [ + 'rules' => 'required', + 'errors' => ['required' => 'Contact Person Name is required'] + ], + 'contact_person_mobile' => [ + 'rules' => 'required', + 'errors' => ['required' => 'Contact Person Mobile is required'] + ], + 'contact_person_email' => [ + 'rules' => 'required|valid_email', + 'errors' => [ + 'required' => 'Contact Person Email is required', + 'valid_email' => 'Please enter a valid email address' + ] + ], + 'salse_person_id' => [ + 'rules' => 'required', + 'errors' => ['required' => 'Sales Person is required'] + ], + 'status' => [ + 'rules' => 'required', + 'errors' => ['required' => 'Status is required'] + ] + ]; + $request_data = $this->request->getPost(); + $data = sanitizeInputArrayAdvanced($request_data); + if($data['lead_form_type'] == 2){ + $rules['client_type'] = [ + 'rules' => 'required', + 'errors' => ['required' => 'Client Type is required'] + ]; + $rules['policy_type_id'] = [ + 'rules' => 'required', + 'errors' => ['required' => 'Policy Type is required'] + ]; + $rules['policy_start_date'] = [ + 'rules' => 'required', + 'errors' => ['required' => 'Date of Commencement is required'] + ]; + $rules['policy_end_date'] = [ + 'rules' => 'required', + 'errors' => ['required' => 'Date of Expiry is required'] + ]; + } + + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } + + + $data['client_type'] = 1; $data['pan'] = ""; @@ -1136,7 +1224,7 @@ class LeadsController extends BaseController // 12. Conditional rendering based on lead_form_type if ($lead_data['lead_form_type'] == 1) { - $data['demogrphy_html_data'] = $this->generateDemographyDataTable(['lead_id' => $id]); + // $data['demogrphy_html_data'] = $this->generateDemographyDataTable(['lead_id' => $id]); $this->loadLayout('view_rfq.php', $data); } else if ($lead_data['lead_form_type'] == 2) { $data['occupancy'] = $this->occupancyModel->findAll(); @@ -5384,8 +5472,13 @@ class LeadsController extends BaseController return []; } - public function generateDemographyDataTable($param) - { + public function generateDemographyDataTable($param = []) + { + + if ($this->request !== null) { + $param['lead_id'] = $this->request->getGet('lead_id'); + } + $returnData = $this->calculateMembersDemography($param, "internal"); $html = ""; @@ -5431,6 +5524,14 @@ class LeadsController extends BaseController } } + if ($this->request !== null) { + if(!empty($html)){ + return $this->respond(['status' => true, 'data' => $html], 200); + }else{ + return $this->respond(['status' => false, 'data' => $html], 200); + } + } + return $html; } @@ -5726,7 +5827,7 @@ class LeadsController extends BaseController $first_file_name = $isFirstField ? 'Member List' : ''; $member_data_link = $isFirstField ? $sample_dwn_link : ''; $read_only = $isFirstField ? 'readonly' : ''; - $accept = $isFirstField ? '.xls,.xlsx' : ''; + $accept = $isFirstField ? '.xls,.xlsx' : '.xls,.xlsx,.pdf,.jpg,.jpeg,.png'; $displayIndex = $index + 1; $html .= ' diff --git a/app/Controllers/LoginController.php b/app/Controllers/LoginController.php index 779c788b..fb073f21 100755 --- a/app/Controllers/LoginController.php +++ b/app/Controllers/LoginController.php @@ -62,9 +62,7 @@ class LoginController extends BaseController set_session_data($session_data); // Bind session to device - set_session_data(['fingerprint' => hash('sha256', - ($this->request->getUserAgent()->getAgentString() . '|' . ($this->request->getIPAddress() - )))]); + set_session_data(['fingerprint' => generateFingerprint()]); log_message('error', 'Set The UserId : `'. $user->id .'` in Session'); log_message('error', 'User Login Sucessfully'); diff --git a/app/Controllers/MasterController.php b/app/Controllers/MasterController.php index 475c8a97..610d6de2 100755 --- a/app/Controllers/MasterController.php +++ b/app/Controllers/MasterController.php @@ -283,26 +283,54 @@ class MasterController extends AdminController { $this->myLogger->logme('error','Insurer general info function called'); + $rules = [ + 'name' => [ + 'rules' => 'required', + 'errors' => [ + 'required' => 'Name is required' + ] + ], + 'short_name' => [ + 'rules' => 'required|min_length[3]|max_length[8]', + 'errors' => [ + 'required' => 'Short name is required', + 'min_length' => 'Short name must be at least 3 characters', + 'max_length' => 'Short name cannot exceed 8 characters' + ] + ], + 'insurer_logo' => [ + 'rules' => 'if_exist|is_image[insurer_logo]|max_size[insurer_logo,200]|ext_in[insurer_logo,jpg,jpeg,png]', + 'errors' => [ + 'is_image' => 'The uploaded file must be an image', + 'max_size' => 'File size should not exceed 200 KB', + 'ext_in' => 'Allowed file types: jpg, jpeg, png', + ] + ], + ]; + + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } + $uploadFilePath = ROOTPATH . 'public/uploads/logo/'; $file_name = file_Upload($this->request->getFile('insurer_logo'), $uploadFilePath); $data = $this->request->getPost(); + print_r($data);die; + $sanitized_post_data = sanitizeInputArrayAdvanced($data); - if($this->request->getPost('addition_add_day')){ - $data['addition_add_day'] = 1; - } - - if($this->request->getPost('deletion_add_day')){ - $data['deletion_add_day'] = 1; - } - - if($this->request->getPost('is_multi_event')){ - $data['is_multi_event'] = 1; - } - - $data['created_by'] = get_session_userid(); - $data['insurer_logo'] = $file_name; + $sanitized_post_data['addition_add_day'] = (!empty($sanitized_post_data['addition_add_day'])) ? 1 : 0; + $sanitized_post_data['deletion_add_day'] = (!empty($sanitized_post_data['deletion_add_day'])) ? 1 : 0; + $sanitized_post_data['is_multi_event'] = (!empty($sanitized_post_data['is_multi_event'])) ? 1 : 0; + $sanitized_post_data['created_by'] = get_session_userid(); + $sanitized_post_data['insurer_logo'] = $file_name; - $insert = $this->insurerModel->insert($data); + $insert = $this->insurerModel->insert($sanitized_post_data); + if($insert){ $insurer_data = $this->insurerModel->where(['id' => $insert, 'is_active' => 1])->first(); $insurer_templete_count = $this->insurerTemplateModel->where(['insurer_id' => $insert, 'is_active' => 1])->countAllResults(); @@ -316,28 +344,129 @@ class MasterController extends AdminController { $this->myLogger->logme('error','Client branch CREATE function called'); + $rules = [ + + // ====================== + // Branch Details + // ====================== + 'branch_name' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'Branch name is required' + ] + ], + + 'branch_code' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'Branch code is required' + ] + ], + + 'address1' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'Address Line 1 is required' + ] + ], + + 'state' => [ + 'rules' => 'required|is_natural_no_zero', + 'errors' => [ + 'required' => 'State is required' + ] + ], + + 'district' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'District is required' + ] + ], + + 'city' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'City is required' + ] + ], + + 'pincode' => [ + 'rules' => 'required|numeric|exact_length[6]', + 'errors' => [ + 'required' => 'Pincode is required', + 'numeric' => 'Pincode must contain only numbers', + 'exact_length' => 'Pincode must be exactly 6 digits' + ] + ], + + // ====================== + // Contact Details (Array) + // ====================== + 'name.*' => [ + 'rules' => 'required|trim|min_length[2]', + 'errors' => [ + 'required' => 'Contact name is required', + 'min_length' => 'Contact name must be at least 2 characters' + ] + ], + + 'designation.*' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'Designation is required' + ] + ], + + 'email.*' => [ + 'rules' => 'required|valid_email', + 'errors' => [ + 'required' => 'Email is required', + 'valid_email' => 'Invalid email format' + ] + ], + + 'mobile.*' => [ + 'rules' => 'required|numeric|exact_length[10]', + 'errors' => [ + 'required' => 'Mobile number is required', + 'numeric' => 'Mobile must contain only digits', + 'exact_length' => 'Mobile number must be exactly 10 digits' + ] + ], + ]; + + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } $data = $this->request->getPost(); - $data['created_by'] = get_session_userid(); - $insert = $this->insurerBranchModel->insert($data); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + $sanitized_post_data['created_by'] = get_session_userid(); + $insert = $this->insurerBranchModel->insert($sanitized_post_data); if($insert){ - for ($i = 0; $i < count($this->request->getPost('name')); $i++) { + for ($i = 0; $i < count($sanitized_post_data('name')); $i++) { // Prepare data to insert - $data = [ + $sanitized_post_data_for_level = [ 'contact_type' => 'insurer', 'ref_id' => $insert, 'created_by' => get_session_userid(), - 'name' => $this->request->getPost('name')[$i], - 'email' => $this->request->getPost('email')[$i], - 'mobile' => $this->request->getPost('mobile')[$i], - 'designation' => $this->request->getPost('designation')[$i] + 'name' => $sanitized_post_data['name'][$i] ?? null, + 'email' => $sanitized_post_data['email'][$i] ?? null, + 'mobile' => $sanitized_post_data['mobile'][$i] ?? null, + 'designation' => $sanitized_post_data['designation'][$i] ?? null ]; - $contacts = $this->levelContactModel->insert($data); + $contacts = $this->levelContactModel->insert($sanitized_post_data_for_level); } } if($insert){ - $branchData = $this->insurerBranchModel->where('insurer_id', $this->request->getPost('insurer_id'))->findAll(); + $branchData = $this->insurerBranchModel->where('insurer_id', $sanitized_post_data_for_level['insurer_id'])->findAll(); echo json_encode(array("status" => true , 'data' => $branchData)); }else{ echo json_encode(array("status" => false)); @@ -367,40 +496,61 @@ class MasterController extends AdminController public function editInsurerGeneralInfo() { - $this->myLogger->logme('error','edit Insurer general info function called'); + + $this->myLogger->logme('error','Edit Insurer general info function called'); + $rules = [ + 'name' => [ + 'rules' => 'required', + 'errors' => [ + 'required' => 'Name is required' + ] + ], + 'short_name' => [ + 'rules' => 'required|min_length[3]|max_length[8]', + 'errors' => [ + 'required' => 'Short name is required', + 'min_length' => 'Short name must be at least 3 characters', + 'max_length' => 'Short name cannot exceed 8 characters' + ] + ], + 'insurer_logo' => [ + 'rules' => 'if_exist|is_image[insurer_logo]|max_size[insurer_logo,200]|ext_in[insurer_logo,jpg,jpeg,png]', + 'errors' => [ + 'is_image' => 'The uploaded file must be an image', + 'max_size' => 'File size should not exceed 200 KB', + 'ext_in' => 'Allowed file types: jpg, jpeg, png', + ] + ], + ]; + + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } $uploadFilePath = ROOTPATH . 'public/uploads/logo/'; - $file_name = file_Upload($this->request->getFile('insurer_logo'), $uploadFilePath); - - $id = $this->request->getPost('PrimaryKey'); - $data = $this->request->getPost(); - $data['updated_by'] = get_session_userid(); - + $file_name = file_Upload($this->request->getFile('insurer_logo'), $uploadFilePath); + $data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + $id = $sanitized_post_data['PrimaryKey']; + + $sanitized_post_data['addition_add_day'] = (!empty($sanitized_post_data['addition_add_day'])) ? 1 : 0; + $sanitized_post_data['deletion_add_day'] = (!empty($sanitized_post_data['deletion_add_day'])) ? 1 : 0; + $sanitized_post_data['is_multi_event'] = (!empty($sanitized_post_data['is_multi_event'])) ? 1 : 0; + $sanitized_post_data['updated_by'] = get_session_userid(); + if(!empty($file_name)){ - $data['insurer_logo'] = $file_name; + $sanitized_post_data['insurer_logo'] = $file_name; } - if($this->request->getPost('addition_add_day')){ - $data['addition_add_day'] = 1; - }else{ - $data['addition_add_day'] = 0; - } + $update = $this->insurerModel->update($id,$sanitized_post_data); - if($this->request->getPost('deletion_add_day')){ - $data['deletion_add_day'] = 1; - }else{ - $data['deletion_add_day'] = 0; - } - - if($this->request->getPost('is_multi_event')){ - $data['is_multi_event'] = 1; - }else{ - $data['is_multi_event'] = 0; - } - - $update = $this->insurerModel->update($id,$data); if($update){ - echo json_encode(array("status" => true , 'data' => $data)); + echo json_encode(array("status" => true , 'data' => $sanitized_post_data)); }else{ echo json_encode(array("status" => false)); } @@ -422,33 +572,133 @@ class MasterController extends AdminController public function editInsurerBranch() { - $this->myLogger->logme('error','Insurer branch CREATE function called'); - $id = $this->request->getPost('PrimaryKey'); - $data = $this->request->getPost(); - $update = $this->insurerBranchModel->update($id, $data); + $this->myLogger->logme('error','Insurer branch EDIT function called'); + $rules = [ + + // ====================== + // Branch Details + // ====================== + 'branch_name' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'Branch name is required' + ] + ], + + 'branch_code' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'Branch code is required' + ] + ], + + 'address1' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'Address Line 1 is required' + ] + ], + + 'state' => [ + 'rules' => 'required|is_natural_no_zero', + 'errors' => [ + 'required' => 'State is required' + ] + ], + + 'district' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'District is required' + ] + ], + + 'city' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'City is required' + ] + ], + + 'pincode' => [ + 'rules' => 'required|numeric|exact_length[6]', + 'errors' => [ + 'required' => 'Pincode is required', + 'numeric' => 'Pincode must contain only numbers', + 'exact_length' => 'Pincode must be exactly 6 digits' + ] + ], + + // ====================== + // Contact Details (Array) + // ====================== + 'name.*' => [ + 'rules' => 'required|trim|min_length[2]', + 'errors' => [ + 'required' => 'Contact name is required', + 'min_length' => 'Contact name must be at least 2 characters' + ] + ], + + 'designation.*' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'Designation is required' + ] + ], + + 'email.*' => [ + 'rules' => 'required|valid_email', + 'errors' => [ + 'required' => 'Email is required', + 'valid_email' => 'Invalid email format' + ] + ], + + 'mobile.*' => [ + 'rules' => 'required|numeric|exact_length[10]', + 'errors' => [ + 'required' => 'Mobile number is required', + 'numeric' => 'Mobile must contain only digits', + 'exact_length' => 'Mobile number must be exactly 10 digits' + ] + ], + ]; + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } + $data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + $id = $sanitized_post_data['PrimaryKey'] ?? null; + $update = $this->insurerBranchModel->update($id, $sanitized_post_data); if($update){ $contactsToDelete = $this->levelContactModel->where(['ref_id' => $id,'contact_type' => 'insurer', 'is_active' => 1])->get()->getResult(); foreach ($contactsToDelete as $contact) { $this->levelContactModel->delete($contact->id); } - for ($i = 0; $i < count($this->request->getPost('name')); $i++) { + for ($i = 0; $i < count($sanitized_post_data['name']); $i++) { // Prepare data to update - $data = [ + $sanitized_post_data_for_level = [ 'contact_type' => 'insurer', 'ref_id' => $id, 'created_by' => get_session_userid(), - 'name' => $this->request->getPost('name')[$i], - 'email' => $this->request->getPost('email')[$i], - 'mobile' => $this->request->getPost('mobile')[$i], - 'designation' => $this->request->getPost('designation')[$i] - ]; - $contacts = $this->levelContactModel->insert($data); + 'name' => $sanitized_post_data['name'][$i] ?? null, + 'email' => $sanitized_post_data['email'][$i] ?? null, + 'mobile' => $sanitized_post_data['mobile'][$i] ?? null, + 'designation' => $sanitized_post_data['designation'][$i] ?? null + ]; + $contacts = $this->levelContactModel->insert($sanitized_post_data_for_level); } } if($update){ - $branchData = $this->insurerBranchModel->where('insurer_id', $this->request->getPost('insurer_id'))->findAll(); + $branchData = $this->insurerBranchModel->where('insurer_id', $sanitized_post_data['insurer_id'])->findAll(); echo json_encode(array("status" => true , 'data' => $branchData, 'edit')); }else{ echo json_encode(array("status" => false, 'edit')); @@ -594,6 +844,74 @@ class MasterController extends AdminController { $this->myLogger->logme('error','TPA general info function called'); + $rules = [ + + // ====================== + // TPA Basic Details + // ====================== + 'name' => [ + 'rules' => 'required|trim|min_length[2]', + 'errors' => [ + 'required' => 'TPA name is required', + 'min_length' => 'TPA name must be at least 2 characters' + ] + ], + + 'short_name' => [ + 'rules' => 'required|trim|min_length[3]', + 'errors' => [ + 'required' => 'TPA short name is required', + 'min_length' => 'Short name must be at least 3 characters', + ] + ], + + 'network_hospitals' => [ + 'rules' => 'required|valid_url', + 'errors' => [ + 'required' => 'Network hospitals URL is required', + 'valid_url' => 'Please enter a valid URL' + ] + ], + 'tpa_logo' => [ + 'rules' => 'if_exist|is_image[tpa_logo]|max_size[tpa_logo,200]|ext_in[tpa_logo,jpg,jpeg,png]', + 'errors' => [ + 'is_image' => 'TPA logo must be an image', + 'max_size' => 'TPA logo should not exceed 200 KB', + 'ext_in' => 'Allowed logo types: jpg, jpeg, png' + ] + ], + + 'fc' => [ + 'rules' => 'if_exist|is_image[fc]|max_size[fc,500]|ext_in[fc,jpg,jpeg,png]', + 'errors' => [ + 'is_image' => 'Front card must be an image', + 'max_size' => 'Front card image should not exceed 500 KB', + 'ext_in' => 'Allowed types: jpg, jpeg, png' + ] + ], + + 'bc' => [ + 'rules' => 'if_exist|is_image[bc]|max_size[bc,500]|ext_in[bc,jpg,jpeg,png]', + 'errors' => [ + 'is_image' => 'Back card must be an image', + 'max_size' => 'Back card image should not exceed 500 KB', + 'ext_in' => 'Allowed types: jpg, jpeg, png' + ] + ], + ]; + + + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } + $data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + $uploadFilePath = ROOTPATH . 'public/uploads/logo/'; $file_name = file_Upload($this->request->getFile('tpa_logo'), $uploadFilePath); @@ -603,18 +921,18 @@ class MasterController extends AdminController $back_card_file_name = file_Upload($this->request->getFile('bc'), $template_bg_path); - $eCardTemplate = $this->request->getPost('ecard_content'); - $data = $this->request->getPost(); - $data['created_by'] = get_session_userid(); - $data['tpa_logo'] = $file_name; - $data['front_card'] = $front_card_file_name; - $data['back_card'] = $back_card_file_name; - $data['network_hospitals'] = $this->request->getPost('network_hospitals'); + $eCardTemplate = $sanitized_post_data['ecard_content']; - $insert = $this->tpaModel->insert($data); + $sanitized_post_data['created_by'] = get_session_userid(); + $sanitized_post_data['tpa_logo'] = $file_name; + $sanitized_post_data['front_card'] = $front_card_file_name; + $sanitized_post_data['back_card'] = $back_card_file_name; + $sanitized_post_data['network_hospitals'] = $sanitized_post_data['network_hospitals']; + + $insert = $this->tpaModel->insert($sanitized_post_data); - $tpa_name = (string) $this->request->getPost('name'); - $short_name = (string) $this->request->getPost('short_name'); + $tpa_name = ((string) $sanitized_post_data['name']) ?? null; + $short_name = ((string) $sanitized_post_data['short_name']) ?? null; $filename = strtolower(str_replace(' ', '_', $short_name)) . '.html'; $file_directory = WRITEPATH . 'e_card_template/'; @@ -629,10 +947,10 @@ class MasterController extends AdminController header('Content-type:text/html; charset=utf-8'); // Write the HTML content to the file - $data = file_put_contents($file_path, $eCardTemplate); + $html_data = file_put_contents($file_path, $eCardTemplate); - if ($data !== false) { + if ($html_data !== false) { $this->myLogger->logme('error', 'TPA: {tpa}, e-Card HTML template file saved successfully: {data}, filepath is: {path}', ['data' => $filename, 'tpa' => $tpa_name, 'path' => $file_path]); } else { $this->myLogger->logme('error', 'TPA: {tpa}, e-Card HTML template file unable to save: {data}', ['data' => $filename, 'tpa' => $tpa_name]); @@ -651,28 +969,129 @@ class MasterController extends AdminController { $this->myLogger->logme('error','TPA branch CREATE function called'); + $rules = [ + + // ====================== + // Branch Details + // ====================== + 'branch_name' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'Branch name is required' + ] + ], + + 'branch_code' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'Branch code is required' + ] + ], + + 'address1' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'Address Line 1 is required' + ] + ], + + 'state' => [ + 'rules' => 'required|is_natural_no_zero', + 'errors' => [ + 'required' => 'State is required' + ] + ], + + 'district' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'District is required' + ] + ], + + 'city' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'City is required' + ] + ], + + 'pincode' => [ + 'rules' => 'required|numeric|exact_length[6]', + 'errors' => [ + 'required' => 'Pincode is required', + 'numeric' => 'Pincode must contain only numbers', + 'exact_length' => 'Pincode must be exactly 6 digits' + ] + ], + + // ====================== + // Contact Details (Array) + // ====================== + 'name.*' => [ + 'rules' => 'required|trim|min_length[2]', + 'errors' => [ + 'required' => 'Contact name is required', + 'min_length' => 'Contact name must be at least 2 characters' + ] + ], + + 'designation.*' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'Designation is required' + ] + ], + + 'email.*' => [ + 'rules' => 'required|valid_email', + 'errors' => [ + 'required' => 'Email is required', + 'valid_email' => 'Invalid email format' + ] + ], + + 'mobile.*' => [ + 'rules' => 'required|numeric|exact_length[10]', + 'errors' => [ + 'required' => 'Mobile number is required', + 'numeric' => 'Mobile must contain only digits', + 'exact_length' => 'Mobile number must be exactly 10 digits' + ] + ], + ]; + + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } $data = $this->request->getPost(); - $data['created_by'] = get_session_userid(); - $insert = $this->tpaBranchModel->insert($data); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + $sanitized_post_data['created_by'] = get_session_userid(); + $insert = $this->tpaBranchModel->insert($sanitized_post_data); if($insert){ - for ($i = 0; $i < count($this->request->getPost('name')); $i++) { + for ($i = 0; $i < count($sanitized_post_data['name']); $i++) { // Prepare data to insert - $data = [ + $sanitized_post_data_for_level = [ 'contact_type' => 'tpa', 'ref_id' => $insert, 'created_by' => get_session_userid(), - 'name' => $this->request->getPost('name')[$i], - 'email' => $this->request->getPost('email')[$i], - 'mobile' => $this->request->getPost('mobile')[$i], - 'designation' => $this->request->getPost('designation')[$i] + 'name' => $sanitized_post_data['name'][$i] ?? null, + 'email' => $sanitized_post_data['email'][$i] ?? null, + 'mobile' => $sanitized_post_data['mobile'][$i] ?? null, + 'designation' => $sanitized_post_data['designation'][$i] ?? null ]; - $contacts = $this->levelContactModel->insert($data); + $contacts = $this->levelContactModel->insert($sanitized_post_data_for_level); } } if($insert){ - $branchData = $this->tpaBranchModel->where('tpa_id', $this->request->getPost('tpa_id'))->findAll(); + $branchData = $this->tpaBranchModel->where('tpa_id', $sanitized_post_data['tpa_id'])->findAll(); echo json_encode(array("status" => true , 'data' => $branchData)); }else{ echo json_encode(array("status" => false)); @@ -715,6 +1134,74 @@ class MasterController extends AdminController public function editTPAGeneralInfo() { $this->myLogger->logme('error','edit TPA general info function called'); + $rules = [ + + // ====================== + // TPA Basic Details + // ====================== + 'name' => [ + 'rules' => 'required|trim|min_length[2]', + 'errors' => [ + 'required' => 'TPA name is required', + 'min_length' => 'TPA name must be at least 2 characters' + ] + ], + + 'short_name' => [ + 'rules' => 'required|trim|min_length[3]', + 'errors' => [ + 'required' => 'TPA short name is required', + 'min_length' => 'Short name must be at least 3 characters', + ] + ], + + 'network_hospitals' => [ + 'rules' => 'required|valid_url', + 'errors' => [ + 'required' => 'Network hospitals URL is required', + 'valid_url' => 'Please enter a valid URL' + ] + ], + 'tpa_logo' => [ + 'rules' => 'if_exist|is_image[tpa_logo]|max_size[tpa_logo,200]|ext_in[tpa_logo,jpg,jpeg,png]', + 'errors' => [ + 'is_image' => 'TPA logo must be an image', + 'max_size' => 'TPA logo should not exceed 200 KB', + 'ext_in' => 'Allowed logo types: jpg, jpeg, png' + ] + ], + + 'fc' => [ + 'rules' => 'if_exist|is_image[fc]|max_size[fc,500]|ext_in[fc,jpg,jpeg,png]', + 'errors' => [ + 'is_image' => 'Front card must be an image', + 'max_size' => 'Front card image should not exceed 500 KB', + 'ext_in' => 'Allowed types: jpg, jpeg, png' + ] + ], + + 'bc' => [ + 'rules' => 'if_exist|is_image[bc]|max_size[bc,500]|ext_in[bc,jpg,jpeg,png]', + 'errors' => [ + 'is_image' => 'Back card must be an image', + 'max_size' => 'Back card image should not exceed 500 KB', + 'ext_in' => 'Allowed types: jpg, jpeg, png' + ] + ], + ]; + + + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } + $data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + $uploadFilePath = ROOTPATH . 'public/uploads/logo/'; $file_name = file_Upload($this->request->getFile('tpa_logo'), $uploadFilePath); @@ -723,29 +1210,29 @@ class MasterController extends AdminController $front_card_file_name = file_Upload($this->request->getFile('fc'), $template_bg_path); $back_card_file_name = file_Upload($this->request->getFile('bc'), $template_bg_path); - $id = $this->request->getPost('PrimaryKey'); - $data = $this->request->getPost(); - $data['updated_by'] = get_session_userid(); + $id = $sanitized_post_data['PrimaryKey'] ?? null; + + $sanitized_post_data['updated_by'] = get_session_userid(); if(!empty($file_name)){ - $data['tpa_logo'] = $file_name; + $sanitized_post_data['tpa_logo'] = $file_name; } if(!empty($front_card_file_name)){ - $data['front_card'] = $front_card_file_name; + $sanitized_post_data['front_card'] = $front_card_file_name; } if(!empty($back_card_file_name)){ - $data['back_card'] = $back_card_file_name; + $sanitized_post_data['back_card'] = $back_card_file_name; } - $data['network_hospitals'] = $this->request->getPost('network_hospitals'); - $update = $this->tpaModel->update($id,$data); + $sanitized_post_data['network_hospitals'] = $sanitized_post_data['network_hospitals'] ?? null; + $update = $this->tpaModel->update($id,$sanitized_post_data); - $tpa_name = (string) $this->request->getPost('name'); - $short_name = (string) $this->request->getPost('short_name'); - $eCardTemplate = $this->request->getPost('ecard_content'); + $tpa_name = ((string) $sanitized_post_data['name']) ?? null; + $short_name = ((string) $sanitized_post_data['short_name']) ?? null; + $eCardTemplate = $sanitized_post_data['ecard_content'] ?? null; $filename = strtolower(str_replace(' ', '_', $short_name)) . '.html'; $file_directory = WRITEPATH . 'e_card_template/'; @@ -760,10 +1247,10 @@ class MasterController extends AdminController header('Content-type:text/html; charset=utf-8'); // Write the HTML content to the file - $data = file_put_contents($file_path, $eCardTemplate); + $html_data = file_put_contents($file_path, $eCardTemplate); - if ($data !== false) { + if ($html_data !== false) { $this->myLogger->logme('error', 'TPA: {tpa}, e-Card HTML template file saved successfully: {data}, filepath is: {path}', ['data' => $filename, 'tpa' => $tpa_name, 'path' => $file_path]); } else { $this->myLogger->logme('error', 'TPA: {tpa}, e-Card HTML template file unable to save: {data}', ['data' => $filename, 'tpa' => $tpa_name]); @@ -772,7 +1259,7 @@ class MasterController extends AdminController if($update){ - echo json_encode(array("status" => true , 'data' => $data)); + echo json_encode(array("status" => true , 'data' => $sanitized_post_data)); }else{ echo json_encode(array("status" => false)); } @@ -795,9 +1282,110 @@ class MasterController extends AdminController public function editTPABranch() { $this->myLogger->logme('error','TPA branch CREATE function called'); - $id = $this->request->getPost('PrimaryKey'); + $rules = [ + + // ====================== + // Branch Details + // ====================== + 'branch_name' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'Branch name is required' + ] + ], + + 'branch_code' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'Branch code is required' + ] + ], + + 'address1' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'Address Line 1 is required' + ] + ], + + 'state' => [ + 'rules' => 'required|is_natural_no_zero', + 'errors' => [ + 'required' => 'State is required' + ] + ], + + 'district' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'District is required' + ] + ], + + 'city' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'City is required' + ] + ], + + 'pincode' => [ + 'rules' => 'required|numeric|exact_length[6]', + 'errors' => [ + 'required' => 'Pincode is required', + 'numeric' => 'Pincode must contain only numbers', + 'exact_length' => 'Pincode must be exactly 6 digits' + ] + ], + + // ====================== + // Contact Details (Array) + // ====================== + 'name.*' => [ + 'rules' => 'required|trim|min_length[2]', + 'errors' => [ + 'required' => 'Contact name is required', + 'min_length' => 'Contact name must be at least 2 characters' + ] + ], + + 'designation.*' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'Designation is required' + ] + ], + + 'email.*' => [ + 'rules' => 'required|valid_email', + 'errors' => [ + 'required' => 'Email is required', + 'valid_email' => 'Invalid email format' + ] + ], + + 'mobile.*' => [ + 'rules' => 'required|numeric|exact_length[10]', + 'errors' => [ + 'required' => 'Mobile number is required', + 'numeric' => 'Mobile must contain only digits', + 'exact_length' => 'Mobile number must be exactly 10 digits' + ] + ], + ]; + + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } $data = $this->request->getPost(); - $update = $this->tpaBranchModel->update($id, $data); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + $id = $sanitized_post_data['PrimaryKey'] ?? null; + $update = $this->tpaBranchModel->update($id, $sanitized_post_data); // print_r($this->request->getPost('name[]')); // print_r($this->request->getPost('email[]')); @@ -809,18 +1397,18 @@ class MasterController extends AdminController foreach ($contactsToDelete as $contact) { $this->levelContactModel->delete($contact->id); } - for ($i = 0; $i < count($this->request->getPost('name')); $i++) { + for ($i = 0; $i < count($sanitized_post_data['name']); $i++) { // Prepare data to update - $data = [ + $sanitized_post_data_for_level = [ 'contact_type' => 'tpa', 'ref_id' => $id, 'created_by' => get_session_userid(), - 'name' => $this->request->getPost('name')[$i], - 'email' => $this->request->getPost('email')[$i], - 'mobile' => $this->request->getPost('mobile')[$i], - 'designation' => $this->request->getPost('designation')[$i] + 'name' => $sanitized_post_data['name'][$i] ?? null, + 'email' => $sanitized_post_data['email'][$i] ?? null, + 'mobile' => $sanitized_post_data['mobile'][$i] ?? null, + 'designation' => $sanitized_post_data['designation'][$i] ?? null ]; - $contacts = $this->levelContactModel->insert($data); + $contacts = $this->levelContactModel->insert($sanitized_post_data_for_level); } } @@ -926,10 +1514,28 @@ class MasterController extends AdminController { $this->myLogger->logme('error','KYC Entity Type general info function called'); + $rules = [ + 'name' => [ + 'rules' => 'required', + 'errors' => [ + 'required' => 'KYC Entity Type Name is required' + ] + ], + ]; + + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } $data = $this->request->getPost(); - $data['created_by'] = get_session_userid(); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + $sanitized_post_data['created_by'] = get_session_userid(); - $insert = $this->kycEntityTypeModel->insert($data); + $insert = $this->kycEntityTypeModel->insert($sanitized_post_data); if($insert){ $kyc_data = $this->kycEntityTypeModel->where(['id' => $insert, 'is_active' => 1])->first(); echo json_encode(array("status" => true , 'data' => $kyc_data)); @@ -942,20 +1548,40 @@ class MasterController extends AdminController { $this->myLogger->logme('error','Kyc Docs CREATE function called'); + $rules = [ + 'file_name' => [ + 'rules' => 'required', + 'errors' => [ + 'required' => 'KYC Docs File Name is required' + ] + ], + ]; + + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } + $data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + // print_r($data);die; - if($data['kyc_type_id'] == ''){ + if($sanitized_post_data['kyc_type_id'] == ''){ // PrimaryKey - $data['kyc_type_id'] =$data['PrimaryKey']; + $sanitized_post_data['kyc_type_id'] =$data['PrimaryKey']; } // print_r($data);die; - $data['created_by'] = get_session_userid(); - $insert = $this->kycDocsModel->insert($data); + $sanitized_post_data['created_by'] = get_session_userid(); + $insert = $this->kycDocsModel->insert($sanitized_post_data); if($insert){ - $kycDocsData = $this->kycDocsModel->where('kyc_type_id', $data['kyc_type_id'])->where('is_active',1)->findAll(); + $kycDocsData = $this->kycDocsModel->where('kyc_type_id', $sanitized_post_data['kyc_type_id'])->where('is_active',1)->findAll(); echo json_encode(array("status" => true , 'data' => $kycDocsData)); }else{ echo json_encode(array("status" => false)); @@ -999,12 +1625,31 @@ class MasterController extends AdminController public function editKYCInfo() { $this->myLogger->logme('error','edit KYC general info function called'); - $id = $this->request->getPost('PrimaryKey'); - $data = $this->request->getPost(); - $data['updated_by'] = get_session_userid(); - $update = $this->kycEntityTypeModel->update($id,$data); + $rules = [ + 'file_name' => [ + 'rules' => 'required', + 'errors' => [ + 'required' => 'KYC Docs File Name is required' + ] + ], + ]; + + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } + + $data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + $id = $sanitized_post_data['PrimaryKey'] ?? null; + $sanitized_post_data['updated_by'] = get_session_userid(); + $update = $this->kycEntityTypeModel->update($id,$sanitized_post_data); if($update){ - echo json_encode(array("status" => true , 'data' => $data)); + echo json_encode(array("status" => true , 'data' => $sanitized_post_data)); }else{ echo json_encode(array("status" => false)); } @@ -1138,11 +1783,97 @@ class MasterController extends AdminController public function createPolicyType() { $this->myLogger->logme('error','Policy Type CREATE function called'); + $rules = [ + 'policy_type' => [ + 'rules' => 'required|trim|min_length[2]', + 'errors' => [ + 'required' => 'Policy type name is required', + 'min_length' => 'Policy type name must be at least 2 characters' + ] + ], + + 'bap' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'BAP is required' + ] + ], + + 'allocg' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'Category is required' + ] + ], + + 'alloci' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'BAP category is required' + ] + ], + + + 'ebp' => [ + 'rules' => 'permit_empty|numeric|greater_than_equal_to[0]', + 'errors' => [ + 'numeric' => 'Group base premium must be numeric', + 'greater_than_equal_to' => 'Value cannot be negative' + ] + ], + + 'etp' => [ + 'rules' => 'permit_empty|numeric|greater_than_equal_to[0]', + 'errors' => [ + 'numeric' => 'Group third-party premium must be numeric', + 'greater_than_equal_to' => 'Value cannot be negative' + ] + ], + + 'etep' => [ + 'rules' => 'permit_empty|numeric|greater_than_equal_to[0]', + 'errors' => [ + 'numeric' => 'Group terrorism premium must be numeric', + 'greater_than_equal_to' => 'Value cannot be negative' + ] + ], + + 'iep' => [ + 'rules' => 'permit_empty|numeric|greater_than_equal_to[0]', + 'errors' => [ + 'numeric' => 'Individual base premium must be numeric', + 'greater_than_equal_to' => 'Value cannot be negative' + ] + ], + + 'itp' => [ + 'rules' => 'permit_empty|numeric|greater_than_equal_to[0]', + 'errors' => [ + 'numeric' => 'Individual third-party premium must be numeric', + 'greater_than_equal_to' => 'Value cannot be negative' + ] + ], + + 'itep' => [ + 'rules' => 'permit_empty|numeric|greater_than_equal_to[0]', + 'errors' => [ + 'numeric' => 'Individual terrorism premium must be numeric', + 'greater_than_equal_to' => 'Value cannot be negative' + ] + ], + ]; + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } $data = $this->request->getPost(); - - $data['created_by'] = get_session_userid(); - $insert = $this->policyTypeModel->insert($data); - + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + $sanitized_post_data['created_by'] = get_session_userid(); + $insert = $this->policyTypeModel->insert($sanitized_post_data); if($insert){ $policyTypeData = $this->policyTypeModel->where('id', $insert)->first(); echo json_encode(array("status" => true , 'data' => $policyTypeData)); @@ -1175,12 +1906,101 @@ class MasterController extends AdminController public function editPolicyType() { $this->myLogger->logme('error','edit Policy general info function called'); - $id = $this->request->getPost('PrimaryKey'); - $data = $this->request->getPost(); - $data['updated_by'] = get_session_userid(); - $update = $this->policyTypeModel->update($id,$data); + $rules = [ + 'policy_type' => [ + 'rules' => 'required|trim|min_length[2]', + 'errors' => [ + 'required' => 'Policy type name is required', + 'min_length' => 'Policy type name must be at least 2 characters' + ] + ], + + 'bap' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'BAP is required' + ] + ], + + 'allocg' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'Category is required' + ] + ], + + 'alloci' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'BAP category is required' + ] + ], + + + 'ebp' => [ + 'rules' => 'permit_empty|numeric|greater_than_equal_to[0]', + 'errors' => [ + 'numeric' => 'Group base premium must be numeric', + 'greater_than_equal_to' => 'Value cannot be negative' + ] + ], + + 'etp' => [ + 'rules' => 'permit_empty|numeric|greater_than_equal_to[0]', + 'errors' => [ + 'numeric' => 'Group third-party premium must be numeric', + 'greater_than_equal_to' => 'Value cannot be negative' + ] + ], + + 'etep' => [ + 'rules' => 'permit_empty|numeric|greater_than_equal_to[0]', + 'errors' => [ + 'numeric' => 'Group terrorism premium must be numeric', + 'greater_than_equal_to' => 'Value cannot be negative' + ] + ], + + 'iep' => [ + 'rules' => 'permit_empty|numeric|greater_than_equal_to[0]', + 'errors' => [ + 'numeric' => 'Individual base premium must be numeric', + 'greater_than_equal_to' => 'Value cannot be negative' + ] + ], + + 'itp' => [ + 'rules' => 'permit_empty|numeric|greater_than_equal_to[0]', + 'errors' => [ + 'numeric' => 'Individual third-party premium must be numeric', + 'greater_than_equal_to' => 'Value cannot be negative' + ] + ], + + 'itep' => [ + 'rules' => 'permit_empty|numeric|greater_than_equal_to[0]', + 'errors' => [ + 'numeric' => 'Individual terrorism premium must be numeric', + 'greater_than_equal_to' => 'Value cannot be negative' + ] + ], + ]; + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } + $data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + + $id = $sanitized_post_data['PrimaryKey'] ?? null; + $sanitized_post_data['updated_by'] = get_session_userid(); + $update = $this->policyTypeModel->update($id,$sanitized_post_data); if($update){ - echo json_encode(array("status" => true , 'data' => $data)); + echo json_encode(array("status" => true , 'data' => $sanitized_post_data)); }else{ echo json_encode(array("status" => false)); } @@ -1229,8 +2049,10 @@ class MasterController extends AdminController public function editPolicies() { $this->myLogger->logme('error','edit Policy general info function called'); - $id = $this->request->getPost('PrimaryKey'); - $data = $this->request->getPost(); + $request_post_data = $this->request->getPost(); + $data = sanitizeInputArrayAdvanced($request_post_data); + + $id = $data['PrimaryKey'] ?? null; $data['updated_by'] = get_session_userid(); $update = $this->policesModel->update($id,$data); if($update){ @@ -1347,12 +2169,74 @@ class MasterController extends AdminController public function createCDMasterData() { $this->myLogger->logme("error", 'Create CD Master Data API called.'); - $data = $this->request->getPost(); + $rules = [ + + // ====================== + // Client / Insurer Mapping + // ====================== + 'client_id' => [ + 'rules' => 'required|is_natural_no_zero', + 'errors' => [ + 'required' => 'Client is required' + ] + ], + + 'insurer_id' => [ + 'rules' => 'required|is_natural_no_zero', + 'errors' => [ + 'required' => 'Insurer is required' + ] + ], + + 'insurer_branch_id' => [ + 'rules' => 'required|is_natural_no_zero', + 'errors' => [ + 'required' => 'Insurer branch is required' + ] + ], + + // ====================== + // CD Account Details + // ====================== + 'opening_date' => [ + 'rules' => 'required|valid_date[d-m-Y]', + 'errors' => [ + 'required' => 'Opening date is required', + 'valid_date' => 'Opening date must be in DD-MM-YYYY format' + ] + ], + + 'cd_ac_no' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'CD account number is required' + ] + ], + + 'opening_bal' => [ + 'rules' => 'required|numeric|greater_than_equal_to[0]', + 'errors' => [ + 'required' => 'Opening amount is required', + 'numeric' => 'Opening amount must be numeric', + 'greater_than_equal_to' => 'Opening amount cannot be negative' + ] + ], + ]; + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } + $data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); $this->myLogger->logme("error", 'Received POST data: ' . json_encode($data)); - $id = $data['PrimaryKey'] ?? null; - $date = (string) ($data['opening_date'] ?? ''); - $data['opening_date'] = date('Y-m-d', strtotime($date)); + $id = $sanitized_post_data['PrimaryKey'] ?? null; + $date = (string) ($sanitized_post_data['opening_date'] ?? ''); + $sanitized_post_data['opening_date'] = date('Y-m-d', strtotime($date)); $this->myLogger->logme("error", 'Formatted opening_date: ' . $data['opening_date']); $loggedInUserID = get_session_userid(); @@ -1362,9 +2246,9 @@ class MasterController extends AdminController if (empty($id)) { $cd_acc_count = $this->CDMasterModel->where('is_active', 1) - ->where('client_id', $data['client_id']) - ->where('insurer_id', $data['insurer_id']) - ->where('insurer_branch_id', $data['insurer_branch_id']) + ->where('client_id', $sanitized_post_data['client_id']) + ->where('insurer_id', $sanitized_post_data['insurer_id']) + ->where('insurer_branch_id', $sanitized_post_data['insurer_branch_id']) ->countAllResults(); if($cd_acc_count > 0){ @@ -1372,19 +2256,19 @@ class MasterController extends AdminController } $this->myLogger->logme("error", 'Performing INSERT operation.'); - $insert = $this->CDMasterModel->insert($data); + $insert = $this->CDMasterModel->insert($sanitized_post_data); $this->myLogger->logme("error", 'Insert result: ' . json_encode($insert)); if ($insert) { $cd_tranction_data = [ - 'amount' => $data['opening_bal'], + 'amount' => $sanitized_post_data['opening_bal'] ?? null, 'sub_type_id' => 7, - 'client_id' => $data['client_id'], + 'client_id' => $sanitized_post_data['client_id'] ?? null, 'client_policy_id' => null, - 'cd_ac_no' => $data['cd_ac_no'], + 'cd_ac_no' => $sanitized_post_data['cd_ac_no'] ?? null, 'endorsement_no' => null, - 'insurer_id' => $data['insurer_id'], + 'insurer_id' => $sanitized_post_data['insurer_id'] ?? null, 'description' => 'Opening Amount', 'transaction_type' => 'Credit', 'event_name' => null, @@ -1400,9 +2284,9 @@ class MasterController extends AdminController $this->myLogger->logme("error", 'Inserted CD Master data: ' . json_encode($cd_master_data)); $cd_master_full_data = $this->CDMasterModel->where('is_active', 1) - ->where('client_id', $data['client_id']) - ->where('insurer_id', $data['insurer_id']) - ->where('insurer_branch_id', $data['insurer_branch_id']) + ->where('client_id', $sanitized_post_data['client_id']) + ->where('insurer_id', $sanitized_post_data['insurer_id']) + ->where('insurer_branch_id', $sanitized_post_data['insurer_branch_id']) ->findAll(); return $this->respond([ @@ -1427,7 +2311,7 @@ class MasterController extends AdminController // === UPDATE === $this->myLogger->logme("error", 'Performing UPDATE operation for ID: ' . $id); - $updated = $this->CDMasterModel->where('id', $id)->set($data)->update(); + $updated = $this->CDMasterModel->where('id', $id)->set($sanitized_post_data)->update(); $this->myLogger->logme("error", 'Update result: ' . json_encode($updated)); $existingData = $this->CDMasterModel->where('is_active', 1)->where('id', $id)->first(); @@ -1465,27 +2349,89 @@ class MasterController extends AdminController public function editCDMasterData($id = null) { + $this->myLogger->logme("error", 'Edit CD Master Data API called.'); + $rules = [ - $id = $this->request->getPost('PrimaryKey'); - $date = (string) $this->request->getPost('opening_date'); - $data = $this->request->getPost(); - $data['opening_date'] = date('Y-m-d', strtotime($date)); + // ====================== + // Client / Insurer Mapping + // ====================== + 'client_id' => [ + 'rules' => 'required|is_natural_no_zero', + 'errors' => [ + 'required' => 'Client is required' + ] + ], + + 'insurer_id' => [ + 'rules' => 'required|is_natural_no_zero', + 'errors' => [ + 'required' => 'Insurer is required' + ] + ], + + 'insurer_branch_id' => [ + 'rules' => 'required|is_natural_no_zero', + 'errors' => [ + 'required' => 'Insurer branch is required' + ] + ], + + // ====================== + // CD Account Details + // ====================== + 'opening_date' => [ + 'rules' => 'required|valid_date[d-m-Y]', + 'errors' => [ + 'required' => 'Opening date is required', + 'valid_date' => 'Opening date must be in DD-MM-YYYY format' + ] + ], + + 'cd_ac_no' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'CD account number is required' + ] + ], + + 'opening_bal' => [ + 'rules' => 'required|numeric|greater_than_equal_to[0]', + 'errors' => [ + 'required' => 'Opening amount is required', + 'numeric' => 'Opening amount must be numeric', + 'greater_than_equal_to' => 'Opening amount cannot be negative' + ] + ], + ]; + if (!$this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } + $data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + $id = $sanitized_post_data['PrimaryKey'] ?? null; + $date = ((string) $sanitized_post_data['opening_date']) ?? null; + $sanitized_post_data['opening_date'] = date('Y-m-d', strtotime($date)); if ($data) { - $insert = $this->CDMasterModel->where('id', $id)->set($data)->update(); + $insert = $this->CDMasterModel->where('id', $id)->set($sanitized_post_data)->update(); - $data = $this->CDMasterModel->where('id', $id)->first(); + $get_data = $this->CDMasterModel->where('id', $id)->first(); $cd_transaction_updated_data = [ - 'balance' => $data['opening_bal'], - 'amount' => $data['opening_bal'] + 'balance' => $get_data['opening_bal'], + 'amount' => $get_data['opening_bal'] ]; $cd_tranction = $this->clientDepositModel - ->where('client_id', $data['client_id']) - ->where('insurer_id', $data['insurer_id']) - ->where('cd_ac_no', $data['cd_ac_no']) + ->where('client_id', $sanitized_post_data['client_id']) + ->where('insurer_id', $sanitized_post_data['insurer_id']) + ->where('cd_ac_no', $sanitized_post_data['cd_ac_no']) ->where('sub_type', 7) ->set($cd_transaction_updated_data)->update(); @@ -1731,35 +2677,72 @@ class MasterController extends AdminController { // return $this->respond($this->request->getPost()); $template_id = $this->request->getPost('template_id'); + + $rules = [ + 'policy_type' => [ + 'rules' => 'required|is_natural_no_zero', + 'errors' => [ + 'required' => 'Policy type is required' + ] + ], + + 'event' => [ + 'rules' => 'required|trim', + 'errors' => [ + 'required' => 'Event is required' + ] + ], + + + 'json_data' => [ + 'rules' => 'required', + 'errors' => [ + 'required' => 'Template mapping data is required' + ] + ], + ]; + + if (! $this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } + $data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + + - $data = [ - 'insurer_id' => $this->request->getPost('insurer_id'), - 'policy_type_id' => $this->request->getPost('policy_type'), - 'event_name' => $this->request->getPost('event'), + $fetch_data = [ + 'insurer_id' => $sanitized_post_data['insurer_id'] ?? null , + 'policy_type_id' => $sanitized_post_data['policy_type'] ?? null, + 'event_name' => $sanitized_post_data['event'] ?? null, 'type_name' => 'export', - 'jsoncolumns' => $this->request->getPost('json_data'), + 'jsoncolumns' => $sanitized_post_data['json_data'] ?? null, 'is_active' => 1, 'created_by' => get_session_userid(), ]; if($template_id){ - $update = $this->insurerTemplateModel->where('id', $template_id)->set($data)->update(); + $update = $this->insurerTemplateModel->where('id', $template_id)->set($fetch_data)->update(); if($update){ - return $this->respond(['status' => true, 'message' => 'Template updated successfully', $data]); + return $this->respond(['status' => true, 'message' => 'Template updated successfully', $fetch_data]); }else{ - return $this->respond(['status' => true, 'message' => 'Failed to update template', $data]); + return $this->respond(['status' => true, 'message' => 'Failed to update template', $fetch_data]); } }else{ - $insert = $this->insurerTemplateModel->insert($data); + $insert = $this->insurerTemplateModel->insert($fetch_data); if($insert){ - return $this->respond(['status' => true, 'message' => 'Template created successfully', $data]); + return $this->respond(['status' => true, 'message' => 'Template created successfully', $fetch_data]); }else{ - return $this->respond(['status' => true, 'message' => 'Failed to create template', $data]); + return $this->respond(['status' => true, 'message' => 'Failed to create template', $fetch_data]); } } @@ -2161,13 +3144,34 @@ class MasterController extends AdminController if ($method === 'post') { - $id = $this->request->getPost('pk') ?? null; - $data = $this->request->getPost(); + + $rules = [ + 'branch_name' => [ + 'rules' => 'required', + 'errors' => [ + 'required' => 'Branch Name is required' + ] + ] + ]; + if (! $this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } + + $data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + $id = $sanitized_post_data['pk'] ?? null; + unset($sanitized_post_data['pk']); + if (empty($id)) { - $update_status = $nhanceBranchModel->insert($data); + $update_status = $nhanceBranchModel->insert($sanitized_post_data); } else { - $update_status = $nhanceBranchModel->where('id', $id)->set($data)->update(); + $update_status = $nhanceBranchModel->where('id', $id)->set($sanitized_post_data)->update(); } if ($update_status) { @@ -2243,13 +3247,34 @@ class MasterController extends AdminController if ($method === 'post') { - $id = $this->request->getPost('pk') ?? null; - $data = $this->request->getPost(); + + $rules = [ + 'vehicle_type' => [ + 'rules' => 'required', + 'errors' => [ + 'required' => 'Vehicle Type is required' + ] + ] + ]; + + if (! $this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } + + $data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + $id = $sanitized_post_data['pk'] ?? null; + unset($sanitized_post_data['pk']); if (empty($id)) { - $update_status = $vehicleTypeModel->insert($data); + $update_status = $vehicleTypeModel->insert($sanitized_post_data); } else { - $update_status = $vehicleTypeModel->where('id', $id)->set($data)->update(); + $update_status = $vehicleTypeModel->where('id', $id)->set($sanitized_post_data)->update(); } if ($update_status) { @@ -2257,14 +3282,14 @@ class MasterController extends AdminController 'status' => true, 'code' => 200, 'message' => 'Vehicle Type Master updated successfully', - 'data' => $data + 'data' => $sanitized_post_data ], 200); } else { return $this->respond([ 'status' => false, 'code' => 400, 'message' => 'Failed to update', - 'data' => $data + 'data' => $sanitized_post_data ], 200); } @@ -2324,13 +3349,62 @@ class MasterController extends AdminController if ($method === 'post') { - $id = $this->request->getPost('pk') ?? null; - $data = $this->request->getPost(); + $rules = [ + // ====================== + // RTO Office Name + // ====================== + 'rto_name' => [ + 'rules' => 'required|trim|min_length[3]|max_length[100]|alpha_numeric_space', + 'errors' => [ + 'required' => 'RTO Office Name is required', + 'min_length' => 'RTO Office Name must be at least 3 characters' + ] + ], + // ====================== + // RTO Code (2 digits only) + // ====================== + 'rto_code' => [ + 'rules' => 'required|exact_length[2]|numeric', + 'errors' => [ + 'required' => 'RTO Code is required', + 'exact_length' => 'RTO Code must be exactly 2 digits', + 'numeric' => 'RTO Code must contain only numbers' + ] + ], + // ====================== + // RTO State (2 letters only) + // ====================== + 'rto_state' => [ + 'rules' => 'required|exact_length[2]|alpha', + 'errors' => [ + 'required' => 'RTO State is required', + 'exact_length' => 'RTO State must be exactly 2 letters', + 'alpha' => 'RTO State must contain only alphabets' + ] + ], + + ]; + + if (! $this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } + + + $data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + $id = $sanitized_post_data['pk'] ?? null; + unset($sanitized_post_data['pk']); + if (empty($id)) { - $update_status = $rtoModel->insert($data); + $update_status = $rtoModel->insert($sanitized_post_data); } else { - $update_status = $rtoModel->where('id', $id)->set($data)->update(); + $update_status = $rtoModel->where('id', $id)->set($sanitized_post_data)->update(); } if ($update_status) { @@ -2338,14 +3412,14 @@ class MasterController extends AdminController 'status' => true, 'code' => 200, 'message' => 'RTO Master updated successfully', - 'data' => $data + 'data' => $sanitized_post_data ], 200); } else { return $this->respond([ 'status' => false, 'code' => 400, 'message' => 'Failed to update', - 'data' => $data + 'data' => $sanitized_post_data ], 200); } @@ -2405,47 +3479,172 @@ class MasterController extends AdminController if ($this->request->getMethod() === 'post') { - $id = $this->request->getPost('pk'); - $data = $this->request->getPost(); + $rules = [ + 'manager_id' => [ + 'rules' => 'required|integer', + 'errors' => [ + 'required' => 'Manager is required', + 'integer' => 'Invalid Manager selected' + ] + ], + 'name' => [ + 'rules' => 'required|min_length[3]|max_length[100]|alpha_space', + 'errors' => [ + 'required' => 'Name is required', + 'min_length' => 'Name must be at least 3 characters', + 'max_length' => 'Name cannot exceed 100 characters', + 'alpha_space'=> 'Name can contain only letters and spaces' + ] + ], + 'pos_code' => [ + 'rules' => 'required|alpha_numeric|max_length[20]', + 'errors' => [ + 'required' => 'POS Code is required', + 'alpha_numeric' => 'POS Code must be alphanumeric', + 'max_length' => 'POS Code cannot exceed 20 characters' + ] + ], + 'email' => [ + 'rules' => 'required|valid_email', + 'errors' => [ + 'required' => 'Email is required', + 'valid_email' => 'Enter a valid email address' + ] + ], + 'mobile' => [ + 'rules' => 'required|numeric|exact_length[10]', + 'errors' => [ + 'required' => 'Mobile number is required', + 'numeric' => 'Mobile number must contain only digits', + 'exact_length' => 'Mobile number must be exactly 10 digits' + ] + ], + 'address' => [ + 'rules' => 'required|min_length[5]', + 'errors' => [ + 'required' => 'Address is required', + 'min_length' => 'Address must be at least 5 characters' + ] + ], + 'city' => [ + 'rules' => 'required|alpha_space', + 'errors' => [ + 'required' => 'City is required', + 'alpha_space' => 'City must contain only letters and spaces' + ] + ], + 'state' => [ + 'rules' => 'required|alpha_space', + 'errors' => [ + 'required' => 'State is required', + 'alpha_space' => 'State must contain only letters and spaces' + ] + ], + 'pincode' => [ + 'rules' => 'required|numeric|exact_length[6]', + 'errors' => [ + 'required' => 'Pincode is required', + 'numeric' => 'Pincode must contain only digits', + 'exact_length' => 'Pincode must be exactly 6 digits' + ] + ], + 'aadhar' => [ + 'rules' => 'required|numeric|exact_length[12]', + 'errors' => [ + 'required' => 'Aadhaar number is required', + 'numeric' => 'Aadhaar must contain only digits', + 'exact_length' => 'Aadhaar must be exactly 12 digits' + ] + ], + 'pan' => [ + 'rules' => 'required|regex_match[/^[A-Z]{5}[0-9]{4}[A-Z]{1}$/]', + 'errors' => [ + 'required' => 'PAN number is required', + 'regex_match' => 'Enter a valid PAN number (ABCDE1234F)' + ] + ], + 'gst' => [ + 'rules' => 'permit_empty|max_length[15]', + 'errors' => [ + 'max_length' => 'GST number cannot exceed 15 characters' + ] + ], + 'aadhar_file_name' => [ + 'rules' => 'permit_empty|uploaded[aadhar_file_name]|max_size[aadhar_file_name,5120]|ext_in[aadhar_file_name,pdf,jpg,jpeg,png]', + 'errors' => [ + 'uploaded' => 'Invalid Aadhaar file', + 'max_size' => 'Aadhaar file size should not exceed 5MB', + 'ext_in' => 'Aadhaar must be PDF or image (jpg, jpeg, png)' + ] + ], + 'pan_file_name' => [ + 'rules' => 'permit_empty|uploaded[pan_file_name]|max_size[pan_file_name,5120]|ext_in[pan_file_name,pdf,jpg,jpeg,png]', + 'errors' => [ + 'uploaded' => 'Invalid PAN file', + 'max_size' => 'PAN file size should not exceed 5MB', + 'ext_in' => 'PAN must be PDF or image (jpg, jpeg, png)' + ] + ], + 'certificate_file_name' => [ + 'rules' => 'permit_empty|uploaded[certificate_file_name]|max_size[certificate_file_name,5120]|ext_in[certificate_file_name,pdf,jpg,jpeg,png]', + 'errors' => [ + 'uploaded' => 'Invalid Certificate file', + 'max_size' => 'Certificate file size should not exceed 5MB', + 'ext_in' => 'Certificate must be PDF or image (jpg, jpeg, png)' + ] + ], + ]; - unset($data['pk']); + if (! $this->validate($rules)) { + return $this->response->setStatusCode(400)->setJSON([ + 'status' => false, + 'message' => 'Input validation failed', + 'code' => 400, + 'errors' => $this->validator->getErrors() + ]); + } + + $data = $this->request->getPost(); + $sanitized_post_data = sanitizeInputArrayAdvanced($data); + $id = $sanitized_post_data['pk'] ?? null; + unset($sanitized_post_data['pk']); try { // Certificate $certificate = $this->uploadPOSFile('certificate_file_name', 'pos_certificate_files'); - if ($certificate !== null) { $data['certificate_file_name'] = $certificate; } else { unset($data['certificate_file_name']); } + if ($certificate !== null) { $sanitized_post_data['certificate_file_name'] = $certificate; } else { unset($sanitized_post_data['certificate_file_name']); } // PAN file $panFile = $this->uploadPOSFile('pan_file_name', 'pos_certificate_files'); - if ($panFile !== null) { $data['pan_file_name'] = $panFile; } else { unset($data['pan_file_name']);} + if ($panFile !== null) { $sanitized_post_data['pan_file_name'] = $panFile; } else { unset($sanitized_post_data['pan_file_name']);} // Aadhaar file $aadharFile = $this->uploadPOSFile('aadhar_file_name', 'pos_certificate_files'); - if ($aadharFile !== null) { $data['aadhar_file_name'] = $aadharFile; } else { unset($data['aadhar_file_name']);} + if ($aadharFile !== null) { $sanitized_post_data['aadhar_file_name'] = $aadharFile; } else { unset($sanitized_post_data['aadhar_file_name']);} } catch (\RuntimeException $e) { - return $this->respond([ 'status' => false, 'code' => 400, 'message' => $e->getMessage(), 'data' => $data ], 400); + return $this->respond([ 'status' => false, 'code' => 400, 'message' => $e->getMessage(), 'data' => $sanitized_post_data ], 400); } - foreach ($data as $k => $v) { + foreach ($sanitized_post_data as $k => $v) { if ($v === '' || $v === null) { - unset($data[$k]); + unset($sanitized_post_data[$k]); } } // INSERT / UPDATE if (empty($id)) { - $status = $posModel->insert($data); + $status = $posModel->insert($sanitized_post_data); } else { - $status = $posModel->update($id, $data); + $status = $posModel->update($id, $sanitized_post_data); } if ($status) { - return $this->respond([ 'status' => true, 'code' => 200, 'message' => 'POS updated successfully', 'data' => $data ], 200); + return $this->respond([ 'status' => true, 'code' => 200, 'message' => 'POS updated successfully', 'data' => $sanitized_post_data ], 200); } - return $this->respond([ 'status' => false, 'code' => 400, 'message' => 'Failed to update', 'data' => $data ], 400); + return $this->respond([ 'status' => false, 'code' => 400, 'message' => 'Failed to update', 'data' => $sanitized_post_data ], 400); } elseif ($method === 'get') { diff --git a/app/Controllers/PayoutController.php b/app/Controllers/PayoutController.php index bba35e99..bf992d88 100644 --- a/app/Controllers/PayoutController.php +++ b/app/Controllers/PayoutController.php @@ -281,13 +281,17 @@ class PayoutController extends BaseController //... Payout-invoice Mapping - Save/update/soft Delete/Hard Delete Data public function saveInvoice() { - $json = $this->request->getJSON(true); - // print_rr($json);die(); - - if (!$json) { + $raw_json = $this->request->getJSON(true); + + // 1. Check if the JSON was actually valid/parsed before sanitizing + if (is_null($raw_json)) { return $this->response->setJSON(['error' => 'Invalid JSON','message' => 'Invalid JSON received.'])->setStatusCode(400); } + // 2. Sanitize the data + $json = sanitizeInputArrayAdvanced($raw_json); + + // 3. Now you can safely use $json (even if it is an empty array) $id = $json['invoice_id'] ?? null; try { diff --git a/app/Controllers/PolicyTransactionController.php b/app/Controllers/PolicyTransactionController.php index f0d6fc56..723a171e 100644 --- a/app/Controllers/PolicyTransactionController.php +++ b/app/Controllers/PolicyTransactionController.php @@ -917,12 +917,14 @@ // policy Transaction Create function start public function createInceptionPolicy() { - $post_data = $this->request->getPost() ?? []; + $post_data = $this->request->getPost(); + $post_data = $post_data ? sanitizeInputArrayAdvanced($post_data) : []; + $this->myLogger->logme('error', 'Policy Trancaction form data : '. json_encode($post_data)); - $id = $this->request->getPost('id'); + $id = $post_data['id'] ?? null; $data = $this->preparePolicyData(); - $data['cd_ac_pk'] = $this->request->getPost('cd_ac_no'); + $data['cd_ac_pk'] = $post_data['cd_ac_no']; $data['issuer'] = 2; $data['status'] = 'completed'; $this->myLogger->logme('error', 'Policy Trancaction modified form data ( insert data ) : '. json_encode($data)); @@ -937,7 +939,8 @@ private function preparePolicyData() { - $data = $this->request->getPost(); + $request_data = $this->request->getPost(); + $data = sanitizeInputArrayAdvanced($request_data); $file_data = $this->request->getFiles() ?? null; $data['file_data'] = $file_data ?? null; @@ -1094,6 +1097,7 @@ private function updateInceptionPolicy($id, $data) { // print_r($data); die; + $data['updated_by'] = get_session_userid(); $old_pt_data = $this->policyTransactionModel->where('is_active', 1)->where("id", $id)->first(); $old_pt_co_share_data = $this->PTCOShareDetailsModel->where('is_active', 1)->where("id", $id)->first(); if ($this->policyTransactionModel->update($id, $data)) { @@ -2007,6 +2011,7 @@ { if ($id) { $data['is_active'] = 0; + $data['updated_by'] = get_session_userid(); $policy_transaction_data = $this->policyTransactionModel->where('id', $id)->first(); if($policy_transaction_data['policy_type_id'] > 7 && $type == 0){ @@ -2247,9 +2252,10 @@ public function createEndorsementPolicy() { - $id = $this->request->getPost('id'); + // $id = $this->request->getPost('id'); $data = $this->preparePolicyTransactionData(); $data['status'] = 'completed'; + $id = $data['id'] ?? null; // print_r($data); die; if (!$id) { @@ -2261,8 +2267,8 @@ private function preparePolicyTransactionData() { - $data = $this->request->getPost(); - + $request_post_data = $this->request->getPost(); + $data = sanitizeInputArrayAdvanced($request_post_data); // echo '
';
             // print_r($data); 
             // die;
@@ -2418,6 +2424,7 @@
 
         private function updateEndorsementTransaction($id, $data)
         {   
+            $data['updated_by']  = get_session_userid();
             $old_endorse_data =  $this->policyTransactionModel->where('id', $id)->where('is_active', 1)->first();
             $update = $this->policyTransactionModel->where('id', $id)->set($data)->update();
 
@@ -3250,10 +3257,12 @@
             $client_policy_id = (!isset($client_policy_id) || $client_policy_id === '' || $client_policy_id === null) ? 0 : $client_policy_id;
             $user_id = (!isset($user_id) || $user_id === '' || $user_id === null) ? 0 : $user_id;
             if ($this->request->is('post')) {
-                $isFromDashboard = $this->request->getPost("is_dashboard");
+                $request_post_data   = $this->request->getPost();
+                $sanitized_post_data = sanitizeInputArrayAdvanced($request_post_data);
+                $isFromDashboard = $sanitized_post_data["is_dashboard"];
 
                 if (isset($isFromDashboard) && !empty($isFromDashboard) && $isFromDashboard == 1) {
-                    $ids = $this->request->getPost('ids');
+                    $ids = $sanitized_post_data['ids'];
 
                     $ids = array_filter(explode(',', $ids));
 
@@ -4221,10 +4230,12 @@
             // echo 'scbsc';die();
             if ($this->request->is('post')) {
                 // $jsonData = (array)$this->request->getJSON();
-                $customer_id = $this->request->getPost('customer_id');
-                $policy_id = $this->request->getPost('policy_id');
-                $cus_doc_name = $this->request->getPost('cus_doc_name');
-                $policy_doc_name = $this->request->getPost('policy_doc_name');
+                $request_data   = $this->request->getPost();
+                $data = sanitizeInputArrayAdvanced($request_data);
+                $customer_id = $data['customer_id'];
+                $policy_id = $data['policy_id'];
+                $cus_doc_name = $data['cus_doc_name'];
+                $policy_doc_name = $data['policy_doc_name'];
                 $pt_files = [];
                 $kyc_files = [];
                 $batch_files = [];
diff --git a/app/Controllers/RestAuthenticationController.php b/app/Controllers/RestAuthenticationController.php
index 9bfb87f9..b2d54fbb 100755
--- a/app/Controllers/RestAuthenticationController.php
+++ b/app/Controllers/RestAuthenticationController.php
@@ -759,6 +759,8 @@ class RestAuthenticationController extends AdminController
 
                             $decoded = json_decode($HRAccessData['allowed_modules'], true);
                             $getAllhrData[$key]['allowed_modules'] = $decoded;
+                            $HRAccessData['pre_client_id'] = md5($HRAccessData['pre_client_id']);
+                            $HRAccessData['post_client_id'] = md5($HRAccessData['post_client_id']);
 
                             $token = JWTToken::encode($HRAccessData);
                             $getAllhrData[$key]['token'] = $token;
diff --git a/app/Controllers/ThzController.php b/app/Controllers/ThzController.php
index df886d2a..713a8fb7 100644
--- a/app/Controllers/ThzController.php
+++ b/app/Controllers/ThzController.php
@@ -63,7 +63,98 @@ class ThzController extends BaseController
     public function ticketSave()
     {
         try {
-            $data = $this->request->getPost();
+            $rules = [
+                    'client_id' => [
+                        'rules'  => 'permit_empty|integer',
+                        'errors' => [
+                            'integer' => 'Invalid client selected'
+                        ]
+                    ],
+
+                    'mobile' => [
+                        'rules'  => 'required|regex_match[/^[0-9]{10}$/]',
+                        'errors' => [
+                            'required'     => 'Mobile number is required',
+                            'regex_match'  => 'Mobile number must be exactly 10 digits'
+                        ]
+                    ],
+
+                    'name' => [
+                        'rules'  => 'required|min_length[3]|max_length[100]|alpha_space',
+                        'errors' => [
+                            'required'   => 'Name is required',
+                            'min_length' => 'Name must be at least 3 characters',
+                            'alpha_space'=> 'Name can contain only letters and spaces'
+                        ]
+                    ],
+
+                    'email' => [
+                        'rules'  => 'required|valid_email|max_length[150]',
+                        'errors' => [
+                            'required'    => 'Email is required',
+                            'valid_email' => 'Please enter a valid email address'
+                        ]
+                    ],
+
+                    'empcode' => [
+                        'rules'  => 'permit_empty|max_length[50]',
+                        'errors' => [
+                            'max_length' => 'Employee code is too long'
+                        ]
+                    ],
+
+                    'ticket_type' => [
+                        'rules'  => 'required|in_list[Sales,Service]',
+                        'errors' => [
+                            'required' => 'Ticket Type is required',
+                            'in_list'  => 'Invalid Ticket Type selected'
+                        ]
+                    ],
+
+                    'assign_to' => [
+                        'rules'  => 'permit_empty|integer',
+                        'errors' => [
+                            'integer' => 'Invalid assignee selected'
+                        ]
+                    ],
+
+                    'subject' => [
+                        'rules'  => 'required|min_length[5]|max_length[150]',
+                        'errors' => [
+                            'required'   => 'Subject is required',
+                            'min_length' => 'Subject must be at least 5 characters',
+                            'max_length' => 'Subject cannot exceed 150 characters'
+                        ]
+                    ],
+
+                    'message' => [
+                        'rules'  => 'required|min_length[10]|max_length[1500]',
+                        'errors' => [
+                            'required'   => 'Message is required',
+                            'min_length' => 'Message must be at least 10 characters',
+                            'max_length' => 'Message cannot exceed 1500 characters'
+                        ]
+                    ],
+                    'status' => [
+                        'rules'  => 'permit_empty|in_list[Open,In Progress,Resolved,Closed]',
+                        'errors' => [
+                            'in_list' => 'Invalid ticket status'
+                        ]
+                    ],
+            ];
+
+            if (!$this->validate($rules)) {
+                return $this->response->setStatusCode(400)->setJSON([
+                    'status' => false,
+                    'message' => 'Input validation failed',
+                    'code' => 400,
+                    'errors' => $this->validator->getErrors()
+                ]);
+            }
+
+            $request_post_data = $this->request->getPost();
+            $data = sanitizeInputArrayAdvanced($request_post_data);
+                
             $references   = "";
             if (!empty($data['thz_id'])) {
 
@@ -157,7 +248,30 @@ class ThzController extends BaseController
     {
 
         try {
-            $data = $this->request->getPost();
+            
+            $rules = [
+                'notes' => [
+                    'rules'  => 'required|string|min_length[1]|max_length[1500]',
+                    'errors' => [
+                        'required'   => 'Notes is required',
+                        'string'     => 'Notes must be valid text',
+                        'min_length' => 'Notes cannot be empty',
+                        'max_length' => 'Notes cannot exceed 1500 characters'
+                    ]
+                ],
+            ];
+
+            if (!$this->validate($rules)) {
+                return $this->response->setStatusCode(400)->setJSON([
+                    'status' => false,
+                    'message' => 'Input validation failed',
+                    'code' => 400,
+                    'errors' => $this->validator->getErrors()
+                ]);
+            }
+
+            $request_post_data = $this->request->getPost();
+            $data = sanitizeInputArrayAdvanced($request_post_data);
 
             $data['notes_type'] = $data['notes_type'] ?? 'External';
 
diff --git a/app/Controllers/TicketController.php b/app/Controllers/TicketController.php
index 09021a99..59307eac 100644
--- a/app/Controllers/TicketController.php
+++ b/app/Controllers/TicketController.php
@@ -1122,8 +1122,130 @@ class TicketController extends BaseController
 
     public function createTicket()
     {
-        $ticket_data = $this->request->getPost();
-        $ticket_data = $this->formatDateForClaim($ticket_data);
+        $rules = [
+            'emp_code' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Employee Code is required']
+            ],
+
+            'emp_name' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Employee Name is required']
+            ],
+
+            'insured_name' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Insured Name is required']
+            ],
+
+            'relationship' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Relationship is required']
+            ],
+
+            'emp_mobile' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Employee Mobile is required']
+            ],
+
+            'emp_mail' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Employee Email is required']
+            ],
+
+            'client_name' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Client Name is required']
+            ],
+
+            'insurer_id' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Insurer is required']
+            ],
+
+            'client_policy_id' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Policy is required']
+            ],
+
+            'claim_status_id' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Claim Status is required']
+            ],
+
+            'priority' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Priority is required']
+            ],
+
+            'mode_of_intimation' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Mode of Intimation is required']
+            ],
+
+            'claim_type' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Claim Type is required']
+            ],
+
+            'hospital_name' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Hospital Name is required']
+            ],
+
+            'hospital_address' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Hospital Address is required']
+            ],
+
+            'hospital_city' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Hospital City is required']
+            ],
+
+            'hospital_state' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Hospital State is required']
+            ],
+
+            'hospital_pin_code' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Hospital Pincode is required']
+            ],
+
+            'hospital_phone_no' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Hospital Phone Number is required']
+            ],
+
+            'doa' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Date of Admission is required']
+            ],
+
+            'dod' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Date of Discharge is required']
+            ],
+
+            'claim_amount' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Claim Amount is required']
+            ],
+        ];
+
+        if (!$this->validate($rules)) {
+            return $this->response->setStatusCode(400)->setJSON([
+                'status' => false,
+                'message' => 'Input validation failed',
+                'code' => 400,
+                'errors' => $this->validator->getErrors()
+            ]);
+        }
+
+        $request_data = $this->request->getPost();
+        $sanitized_data = sanitizeInputArrayAdvanced($request_data);
+        $ticket_data = $this->formatDateForClaim($sanitized_data);
         // $ticket_data = $this->getLastMatchedStatus($ticket_data, );
         // print_rr($ticket_data); die;
 
@@ -1183,9 +1305,132 @@ class TicketController extends BaseController
 
     public function updateTicket()
     {
+
+        $rules = [
+            'emp_code' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Employee Code is required']
+            ],
+
+            'emp_name' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Employee Name is required']
+            ],
+
+            'insured_name' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Insured Name is required']
+            ],
+
+            'relationship' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Relationship is required']
+            ],
+
+            'emp_mobile' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Employee Mobile is required']
+            ],
+
+            'emp_mail' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Employee Email is required']
+            ],
+
+            'client_name' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Client Name is required']
+            ],
+
+            'insurer_id' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Insurer is required']
+            ],
+
+            'client_policy_id' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Policy is required']
+            ],
+
+            'claim_status_id' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Claim Status is required']
+            ],
+
+            'priority' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Priority is required']
+            ],
+
+            'mode_of_intimation' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Mode of Intimation is required']
+            ],
+
+            'claim_type' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Claim Type is required']
+            ],
+
+            'hospital_name' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Hospital Name is required']
+            ],
+
+            'hospital_address' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Hospital Address is required']
+            ],
+
+            'hospital_city' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Hospital City is required']
+            ],
+
+            'hospital_state' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Hospital State is required']
+            ],
+
+            'hospital_pin_code' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Hospital Pincode is required']
+            ],
+
+            'hospital_phone_no' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Hospital Phone Number is required']
+            ],
+
+            'doa' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Date of Admission is required']
+            ],
+
+            'dod' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Date of Discharge is required']
+            ],
+
+            'claim_amount' => [
+                'rules'  => 'required',
+                'errors' => ['required' => 'Claim Amount is required']
+            ],
+        ];
+
+        if (!$this->validate($rules)) {
+            return $this->response->setStatusCode(400)->setJSON([
+                'status' => false,
+                'message' => 'Input validation failed',
+                'code' => 400,
+                'errors' => $this->validator->getErrors()
+            ]);
+        }
+        
+        $request_data = $this->request->getPost();
+        $sanitized_data = sanitizeInputArrayAdvanced($request_data);
+        $ticket_data = $this->formatDateForClaim($sanitized_data);
         $ticket_id = $this->request->getPost('ticket_master_id');
-        $ticket_data = $this->request->getPost();
-        $ticket_data = $this->formatDateForClaim($ticket_data);
         $old_ticket_data = $this->ticketMasterModel->where('id', $ticket_id)->where('is_active', 1)->first();
         $ticket_data['claim_status_id'] = $this->getLastMatchedStatus($ticket_data, $old_ticket_data);
         // print_rr($ticket_data); die;
@@ -1250,7 +1495,49 @@ class TicketController extends BaseController
     {
         //action 1 is create. action 2 is edit and action 3 is delete
         if ($action == 1) {
-            $received_data = $this->request->getPost();
+                $rules = [
+                    'template_name' => [
+                        'rules'  => 'required',
+                        'errors' => [
+                            'required' => 'Template Name is required'
+                        ]
+                    ],
+                    'ticket_type' => [
+                        'rules'  => 'required',
+                        'errors' => [
+                            'required' => 'Policy Type is required'
+                        ]
+                    ],
+                    'trigger_type' => [
+                        'rules'  => 'required',
+                        'errors' => [
+                            'required' => 'Trigger Type is required'
+                        ]
+                    ],
+                    'subject' => [
+                        'rules'  => 'required',
+                        'errors' => [
+                            'required' => 'Subject is required'
+                        ]
+                    ],
+                    'mail_content' => [
+                        'rules'  => 'required',
+                        'errors' => [
+                            'required' => 'Mail Content is required'
+                        ]
+                    ]
+                ];
+                 if (!$this->validate($rules)) {
+                    return $this->response->setStatusCode(400)->setJSON([
+                        'status' => false,
+                        'message' => 'Input validation failed',
+                        'code' => 400,
+                        'errors' => $this->validator->getErrors()
+                    ]);
+                }
+                $data   = $this->request->getPost();
+                $received_data = sanitizeInputArrayAdvanced($data);
+
             if (isset($received_data['id']) && $received_data['id'] != '') {
                 $status = $this->ticketMailTemplateModel->save($received_data);
                 if ($status) {
@@ -2502,7 +2789,7 @@ class TicketController extends BaseController
 
                     $insertData = [
                         'doc_name' => $data['docs_name'][$key] ?? '',
-                        'url'      => $data['url'][$key] ?? '',
+                        'url'      => convertGoogleDriveToDownloadLink($data['url'][$key] ?? ''),
                         'ticket_id' => $data['ticket_id_url'] ?? '',
                         'created_by' => get_session_userid(),
                         'is_active'  => 1,
@@ -2813,6 +3100,8 @@ class TicketController extends BaseController
     {   
         $data['tab_name'] = "Claim Dupm Upload";
         $data['page_name'] = "Claims";
+        $data['tpa_list'] = $this->TPAModel->where('is_active', 1)->findAll();
+
 
         if($this->request->is('get')){
 
@@ -2877,17 +3166,25 @@ class TicketController extends BaseController
             $status = 'inprogress';
             $insert_data = [
                 'file_name' => $filename, 
-                'status' => $status
+                'status' => $status,
+                'client_id' => !empty($this->request->getPost('client_id')) ? $this->request->getPost('client_id') : null,
+                'client_policy_id' => !empty($this->request->getPost('client_policy_id')) ? $this->request->getPost('client_policy_id') : null,
+                'tpa_id' => !empty($this->request->getPost('tpa_id')) ? $this->request->getPost('tpa_id') : null,
             ];
             
             $file_id = $this->claimDumpFileModel->insert($insert_data); 
             $this->myLogger->logme("error", 'claim_dumb_file_id : {file_id}, uploaded success', ['file_id' => $file_id]);
 
             //after file upload success than call the file formate validation in service controller
-            $ticketServiceController = new TicketServiceController();
-            // $response = $ticketServiceController->claimDumpExcelFileFormatValidation(["file_id" => $file_id]);
-            $r = Jobs::addJob(['job_name' => 'claimDumpExcelFileFormatValidation', 'payload' => ['file_id' => $file_id]]);
 
+            // $ticketServiceController = new TicketServiceController();
+            if(!empty($insert_data['tpa_id'])){
+                $r = Jobs::addJob(['job_name' => 'tpaClaimDumpImporter', 'payload' => ['file_id' => $file_id]]);
+                // $response = $ticketServiceController->claimDumpExcelFileFormatValidation(["file_id" => $file_id]);
+            }else{
+                $r = Jobs::addJob(['job_name' => 'claimDumpExcelFileFormatValidation', 'payload' => ['file_id' => $file_id]]);
+                // $response = $ticketServiceController->claimDumpExcelFileFormatValidation(["file_id" => $file_id]);
+            }
             return $this->respond(['status' => true, 'code' => 200, 'message' => 'File uploaded successfully. File being validated'], 200);
 
         }
@@ -2986,8 +3283,12 @@ class TicketController extends BaseController
 
     }
 
+
+    // -------- CLAIM MIS UPLOAD ----------------------------------------------------------------------------------------------
+
     public function claimMisFileList()
-    {
+    {   
+        $data['tab_name'] = "Claim MIS Upload";
         $data['page_name'] = "Cliam MIS Files";
         $data['claim_mis_file_list'] = $this->claimmisFileModel
                                 ->select('claims_mis_files.*, user_profiles.first_name as user_name')
@@ -3002,6 +3303,71 @@ class TicketController extends BaseController
 
     public function uploadClaimMisFile()
     {
+
+        $filename = '';
+        $fileSize = '';
+
+            //validate uploaded file
+            $validated = $this->validate([
+                'file' => [
+                    'uploaded[file]',
+                    'mime_in[file,application/vnd.ms-excel,application/vnd.openxmlformats-officedocument.spreadsheetml.sheet,application/vnd.oasis.opendocument.spreadsheet]',
+                    'max_size[file,16384]',
+                ],
+            ]);
+            
+            if ($validated) 
+            {
+                    
+                    $file = $this->request->getFile('file');
+                    if (!$file) {
+                        $this->myLogger->logme("error", 'File not found');
+                        return $this->respond(['status' => false, 'code' => 400, 'message' => 'File not found'], 400);
+                    }
+
+                    $is_moved = $file->move(WRITEPATH . 'uploads/claims_mis/');
+                
+                    if ($is_moved) {
+                        $file_path = WRITEPATH.'uploads/claims_mis';
+                        $filename = file_Upload_for_lead($file, $file_path);
+                        $fileSize = $file->getSize(); // File size in bytes
+                        $fileSize = $fileSize / (1024 * 1024); // Convert to MB
+
+                        $this->myLogger->logme("error", 'File move successful');
+                        
+                            $request_data   = $this->request->getPost();
+                            $data = sanitizeInputArrayAdvanced($request_data);
+
+                            if(isset($data['from_date']) && !empty($data['from_date'])){
+                                $data['from_date'] = change_date_format($data['from_date'], 'd/m/Y', 'Y-m-d');
+                            }
+
+                            if(isset($data['to_date']) && !empty($data['to_date'])){
+                                $data['to_date'] = change_date_format($data['to_date'], 'd/m/Y', 'Y-m-d');
+                            }
+                            if(!empty($file_name)){
+                                $data['file_name'] = $file;
+                            }
+
+                            $response = $this->claimmisFileModel->insert($data);
+                        
+                            if($response){
+                                return $this->respond(['status'=>true, 'code'=>200, 'message'=>'MIS file uploaded successfully'], 200);
+                            }else{
+                                return $this->respond(['status'=>true, 'code'=>500, 'message'=>'Failed to upload'], 200);
+                            }
+                        
+                    } else {
+                        $this->myLogger->logme("error", 'File move failed');
+                        return $this->respond(['status' => false, 'code' => 500, 'message' => 'File move failed'], 500);
+                    }
+
+            } else {
+                $this->myLogger->logme("error", 'Upload failed Invalid file');
+                return $this->respond(['status' => false, 'code' => 404, 'message' => 'Invalid file'], 404);
+            }
+
+        /*** OLD CODE KEEP it Safe 
         $file = $this->request->getFile('file');
         $data = $this->request->getPost();
 
@@ -3027,6 +3393,7 @@ class TicketController extends BaseController
         }else{
             return $this->respond(['status'=>true, 'code'=>500, 'message'=>'Failed to upload'], 200);
         }
+        ****/
     }
 
     public function downloadClaimMisFile()
diff --git a/app/Controllers/TicketServiceController.php b/app/Controllers/TicketServiceController.php
index 5cfa99f4..14c1b19a 100644
--- a/app/Controllers/TicketServiceController.php
+++ b/app/Controllers/TicketServiceController.php
@@ -7,6 +7,9 @@ use CodeIgniter\HTTP\ResponseInterface;
 use CodeIgniter\API\ResponseTrait;
 use PhpOffice\PhpSpreadsheet\Cell\Coordinate;
 use Kint\Kint;
+use App\Libraries\TpaClaimsImportFactory;
+use App\Libraries\TPAClaimsImportServices\FhplClaimImportService;
+use App\Libraries\TPAClaimsImportServices\BaseTpaClaimImportService;
 
 use App\Models\ClaimDumpFileModel;
 use App\Models\EmployeeModel;
@@ -15,10 +18,14 @@ use App\Models\TPAModel;
 use App\Models\ClientModel;
 use App\Models\TicketClaimStatusModel;
 use App\Models\ClientPolicyModel;
+use App\Models\ClaimsDumpFhplModel;
 
 use App\Helpers\ExcelSanitizeHelper;
 use App\Models\TicketMasterModel;
 
+use PhpOffice\PhpSpreadsheet\IOFactory;
+use PhpOffice\PhpSpreadsheet\Spreadsheet;
+
 class TicketServiceController extends BaseController
 {
     use ResponseTrait;
@@ -35,6 +42,10 @@ class TicketServiceController extends BaseController
     protected $ticketClaimStatusModel;
     protected $clientPolicyModel;
 
+    protected $medi_assist_primary_key;
+    protected $vidal_primary_key;
+    protected $icici_primary_key;
+
 
     public function __construct()
     {   
@@ -50,6 +61,11 @@ class TicketServiceController extends BaseController
         $this->ticketClaimStatusModel = new TicketClaimStatusModel();
         $this->clientPolicyModel = new ClientPolicyModel();
 
+        $this->medi_assist_primary_key = getenv('MEDI_ASSIST_PRIMARY_KEY_CONSTANT');
+        $this->vidal_primary_key = getenv('VIDAL_PRIMARY_KEY_CONSTANT');
+        $this->icici_primary_key = getenv('ICICI_PRIMARY_KEY_CONSTANT');
+
+
         $this->claim_dump_excel_columns = [
 
             // Mandatory Fields
@@ -1819,5 +1835,243 @@ class TicketServiceController extends BaseController
     {
 
     }
+
+
+    // --------------------------------------------------------------------------------------------------------------------------------
+
+
+    public function tpaClaimImporter($params)
+    {
+        $file_id = $params['file_id'];
+        $tpa_claims_files_data = $this->claimDumpFileModel->where('id', $file_id)->first();
+
+
+        if($this->vidal_primary_key == $tpa_claims_files_data['tpa_id']){
+
+        }else if($this->icici_primary_key == $tpa_claims_files_data['tpa_id']){
+
+        }else{
+            $this->myLogger->logme('error', 'No TPA found to import');
+            return ['status' => false, 'message' => 'No TPA found to import'];
+        }
+    }
+
+    public function tpaClaimDumpImporter($params)
+    {
+        try {
+
+            $file_id   = $params['file_id'] ?? null;
+            $file_path = WRITEPATH . 'uploads/claim_dump_excel/';
+
+            if (!$file_id) {
+                return ['status' => false, 'message' => 'File ID is missing'];
+            }
+
+            $fileData = $this->claimDumpFileModel->where('id', $file_id)->first();
+
+            if (!$fileData) {
+                return ['status' => false, 'message' => 'Invalid file ID. No file data found'];
+            }
+
+            $file_full_path = $file_path . $fileData['file_name'];
+
+            if (!is_file($file_full_path)) {
+                return ['status' => false, 'message' => 'Claim dump file not found'];
+            }
+
+            $handler = TpaClaimsImportFactory::make($fileData['tpa_id'] ?? 0);
+            $result  = $handler->runTpaClaimDumpInsert($file_full_path, $file_id);
+
+            // ---------- Prepare update data ----------
+            $data = [];
+
+            if (!empty($result['status']) && $result['status'] === true) {
+                $data['status'] = 'success';
+                $data['reason'] = null;
+            } else {
+                $data['status'] = 'failed';
+
+                $errorMessage = $result['message'] ?? 'Unknown import error';
+
+                $reason = [
+                    'error_summary' => array_count_values([5]),
+                    'error_data'    => $errorMessage
+                ];
+
+                $data['reason'] = json_encode($reason, JSON_UNESCAPED_UNICODE);
+            }
+
+            // dd($data); 
+            // ---------- Update DB ----------
+            $sql = "UPDATE claim_dump_files  SET status = ?, reason = ? WHERE id = ?";
+
+            $updated = db_connect()->query(
+                $sql,
+                [
+                    $data['status'] ?? null,
+                    $data['reason'] ?? null,
+                    $file_id
+                ]
+            );
+
+            if (!$updated) {
+                $this->myLogger->logme('error', 'Claim dump file update failed for file_id: ' . $file_id);
+            }
+
+            dd(db_connect()->getLastQuery()->getQuery());
+
+            if(!empty($result['status']) && $result['status'] === true){
+                $r = Jobs::addJob(['job_name' => 'tpaClaimDumpToTicketMasterImporters', 'payload' => ['file_id' => $file_id]]);
+            }
+
+            return $result;
+
+        } catch (\Throwable $th) {
+
+            $this->myLogger->logme(
+                "error",
+                'TPA_CLAIM_IMPORTER_JOB : ' .
+                $th->getMessage() . ' | Line: ' . $th->getLine()
+            );
+
+            return [
+                'status' => false,
+                'message' => 'TPA Claim dump import failed',
+                'error_data' => [
+                    'message' => $th->getMessage(),
+                    'file'    => $th->getFile(),
+                    'line'    => $th->getLine(),
+                    'trace'   => $th->getTraceAsString()
+                ]
+            ];
+        }
+    }
+
+    public function tpaClaimDumpToTicketMasterImporters($params)
+    {
+        try {
+
+            $file_id = $params['file_id'] ?? null;
+            $fileData = $this->claimDumpFileModel->where('id', $file_id)->first();
+
+            if (!$fileData) {
+                return ['status' => false, 'message' => 'Invalid file ID No file data found to import'];
+            }
+
+            $handler = TpaClaimsImportFactory::make($fileData['tpa_id'] ?? 0);
+            $result = $handler->runTicketMasterInsert($params);
+
+            return $result;
+
+        } catch (\Throwable $th) {
+
+            $this->myLogger->logme("error", 'TICKET_MASTER_CLAIM_IMPORTER_JOB :' .($th->getMessage() . ' --- ' . $th->getLine() . '----' . $th->getTraceAsString()));
+            
+            $errorData = [
+                'message' => $th->getMessage(),
+                'file'    => $th->getFile(),
+                'line'    => $th->getLine(),
+                'code'    => $th->getCode(),
+                'trace'   => $th->getTraceAsString(),
+                'trace_array' => $th->getTrace(), // full array version (optional)
+                'function' => $th->getTrace()[0]['function'] ?? null,
+                'class' => $th->getTrace()[0]['class'] ?? null,
+            ];
+
+            return [
+                'status'  => false,
+                'message' => $th->getMessage(),
+                'error_data' => json_encode($errorData, JSON_PRETTY_PRINT)
+            ];
+        }
+    }
+
+    public function tpaClaimDumpToTicketMasterImportBatchSeperater($params)
+    {
+        try {
+
+            $file_id = $params['file_id'] ?? null;
+            $fileData = $this->claimDumpFileModel->where('id', $file_id)->first();
+
+            if (!$fileData) {
+                return ['status' => false, 'message' => 'Invalid file ID No file data found to import'];
+            }
+
+            $handler = TpaClaimsImportFactory::make($fileData['tpa_id'] ?? 0);
+            $result = $handler->runTicketMasterInsert($params);
+
+            return $result;
+
+        } catch (\Throwable $th) {
+
+            $this->myLogger->logme("error", 'TICKET_MASTER_CLAIM_IMPORTER_JOB :' .($th->getMessage() . ' --- ' . $th->getLine() . '----' . $th->getTraceAsString()));
+            
+            $errorData = [
+                'message' => $th->getMessage(),
+                'file'    => $th->getFile(),
+                'line'    => $th->getLine(),
+                'code'    => $th->getCode(),
+                'trace'   => $th->getTraceAsString(),
+                'trace_array' => $th->getTrace(), // full array version (optional)
+                'function' => $th->getTrace()[0]['function'] ?? null,
+                'class' => $th->getTrace()[0]['class'] ?? null,
+            ];
+
+            return [
+                'status'  => false,
+                'message' => $th->getMessage(),
+                'error_data' => json_encode($errorData, JSON_PRETTY_PRINT)
+            ];
+        }
+    }
+
+    public function readExcelBySheetName(string $filePath, string $sheetName): array
+    {
+        if (!file_exists($filePath)) {
+           return [];
+        }
+
+        $spreadsheet = IOFactory::load($filePath);
+
+        // Get sheet by name
+        $sheet = $spreadsheet->getSheetByName($sheetName);
+
+        if ($sheet === null) {
+            return [];
+        }
+
+        $rows = $sheet->toArray(null, true, true, true);
+
+        // Need at least header + one row
+        if (count($rows) < 2) {
+            return [];
+        }
+
+        // First row = headers
+        $headers = array_shift($rows);
+        $headers = array_map('trim', $headers);
+
+        $data = [];
+
+        foreach ($rows as $row) {
+            // Skip completely empty rows
+            if (!array_filter($row)) {
+                continue;
+            }
+
+            $item = [];
+
+            foreach ($headers as $key => $headerName) {
+                if ($headerName !== '') {
+                    $item[$headerName] = $row[$key] ?? null;
+                }
+            }
+
+            $data[] = $item;
+        }
+
+        return $data;
+    }
+
    
 }
diff --git a/app/Controllers/UserController.php b/app/Controllers/UserController.php
index 668144a6..daaadb9f 100755
--- a/app/Controllers/UserController.php
+++ b/app/Controllers/UserController.php
@@ -83,7 +83,114 @@ class UserController extends AdminController
             return redirect()->to(base_url('/user/list'));
         } else {
 
-            $userData = $this->request->getPost();
+            // $userData = $this->request->getPost();
+            $data      = $this->request->getPost();
+            $userData  = sanitizeInputArrayAdvanced($data);
+            $rules = [
+
+                // ======================
+                // Nhance Branch
+                // ======================
+                'nhance_branch_id' => [
+                    'rules'  => 'required|integer',
+                    'errors' => [
+                        'required' => 'Nhance Branch is required',
+                        'integer'  => 'Invalid Nhance Branch selected'
+                    ]
+                ],
+
+                // ======================
+                // Reporting Manager
+                // ======================
+                'rm_id' => [
+                    'rules'  => 'required|integer',
+                    'errors' => [
+                        'required' => 'Reporting Manager is required',
+                        'integer'  => 'Invalid Reporting Manager selected'
+                    ]
+                ],
+
+                // ======================
+                // Employee Code
+                // ======================
+                'emp_code' => [
+                    'rules'  => 'required|alpha_numeric|min_length[3]|max_length[20]|is_unique[user_profiles.emp_code,id,{PrimaryKey}]',
+                    'errors' => [
+                        'required'      => 'Employee Code is required',
+                        'alpha_numeric' => 'Employee Code must be alphanumeric',
+                        'min_length'    => 'Employee Code must be at least 3 characters',
+                        'max_length'    => 'Employee Code cannot exceed 20 characters',
+                        'is_unique'     => 'Employee Code already exists'
+                    ]
+                ],
+
+                // ======================
+                // First Name
+                // ======================
+                'first_name' => [
+                    'rules'  => 'required|alpha_space|min_length[2]|max_length[100]',
+                    'errors' => [
+                        'required'    => 'Name is required',
+                        'alpha_space' => 'Name can contain only letters and spaces',
+                        'min_length'  => 'Name must be at least 2 characters',
+                        'max_length'  => 'Name cannot exceed 100 characters'
+                    ]
+                ],
+
+                // ======================
+                // Email
+                // ======================
+                'email' => [
+                    'rules'  => 'required|valid_email|is_unique[user_profiles.email,id,{PrimaryKey}]',
+                    'errors' => [
+                        'required'    => 'Email is required',
+                        'valid_email' => 'Please enter a valid email address',
+                        'is_unique'   => 'Email already exists'
+                    ]
+                ],
+
+                // ======================
+                // Mobile
+                // ======================
+                'mobile' => [
+                    'rules'  => 'required|regex_match[/^[6-9][0-9]{9}$/]|is_unique[user_profiles.mobile,id,{PrimaryKey}]',
+                    'errors' => [
+                        'required'     => 'Mobile number is required',
+                        'regex_match'  => 'Enter a valid 10-digit mobile number starting with 6, 7, 8, or 9',
+                        'is_unique'    => 'Mobile number already exists'
+                    ]
+                ],
+
+                // ======================
+                // Role
+                // ======================
+                'role' => [
+                    'rules'  => 'required|integer',
+                    'errors' => [
+                        'required' => 'User Role is required',
+                        'integer'  => 'Invalid User Role selected'
+                    ]
+                ],
+
+                // ======================
+                // Team (Multiple select)
+                // ======================
+                'team' => [
+                    'rules'  => 'required',
+                    'errors' => [
+                        'required' => 'At least one User Team must be selected'
+                    ]
+                ],
+            ];
+            if (!$this->validate($rules)) {
+                return $this->response->setStatusCode(400)->setJSON([
+                    'status' => false,
+                    'message' => 'Input validation failed',
+                    'code' => 400,
+                    'errors' => $this->validator->getErrors()
+                ]);
+            }
+
             $userData['created_by'] =  get_session_userid();
             $temp_team = $userData['team'];
             unset($userData['team']);
@@ -167,9 +274,116 @@ class UserController extends AdminController
             return redirect()->to(base_url('/user/list'));
         } else {
             // echo ":/ in 163";
-            $id = $this->request->getPost('PrimaryKey');
-            $teams = $this->request->getPost('team');
-            $userData = $this->request->getPost();
+            $rules = [
+
+                // ======================
+                // Nhance Branch
+                // ======================
+                'nhance_branch_id' => [
+                    'rules'  => 'required|integer',
+                    'errors' => [
+                        'required' => 'Nhance Branch is required',
+                        'integer'  => 'Invalid Nhance Branch selected'
+                    ]
+                ],
+
+                // ======================
+                // Reporting Manager
+                // ======================
+                'rm_id' => [
+                    'rules'  => 'required|integer',
+                    'errors' => [
+                        'required' => 'Reporting Manager is required',
+                        'integer'  => 'Invalid Reporting Manager selected'
+                    ]
+                ],
+
+                // ======================
+                // Employee Code
+                // ======================
+                'emp_code' => [
+                    'rules'  => 'required|alpha_numeric|min_length[3]|max_length[20]|is_unique[user_profiles.emp_code,id,{PrimaryKey}]',
+                    'errors' => [
+                        'required'      => 'Employee Code is required',
+                        'alpha_numeric' => 'Employee Code must be alphanumeric',
+                        'min_length'    => 'Employee Code must be at least 3 characters',
+                        'max_length'    => 'Employee Code cannot exceed 20 characters',
+                        'is_unique'     => 'Employee Code already exists'
+                    ]
+                ],
+
+                // ======================
+                // First Name
+                // ======================
+                'first_name' => [
+                    'rules'  => 'required|alpha_space|min_length[2]|max_length[100]',
+                    'errors' => [
+                        'required'    => 'Name is required',
+                        'alpha_space' => 'Name can contain only letters and spaces',
+                        'min_length'  => 'Name must be at least 2 characters',
+                        'max_length'  => 'Name cannot exceed 100 characters'
+                    ]
+                ],
+
+                // ======================
+                // Email
+                // ======================
+                'email' => [
+                    'rules'  => 'required|valid_email|is_unique[user_profiles.email,id,{PrimaryKey}]',
+                    'errors' => [
+                        'required'    => 'Email is required',
+                        'valid_email' => 'Please enter a valid email address',
+                        'is_unique'   => 'Email already exists'
+                    ]
+                ],
+
+                // ======================
+                // Mobile
+                // ======================
+                'mobile' => [
+                    'rules'  => 'required|regex_match[/^[6-9][0-9]{9}$/]|is_unique[user_profiles.mobile,id,{PrimaryKey}]',
+                    'errors' => [
+                        'required'     => 'Mobile number is required',
+                        'regex_match'  => 'Enter a valid 10-digit mobile number starting with 6, 7, 8, or 9',
+                        'is_unique'    => 'Mobile number already exists'
+                    ]
+                ],
+
+                // ======================
+                // Role
+                // ======================
+                'role' => [
+                    'rules'  => 'required|integer',
+                    'errors' => [
+                        'required' => 'User Role is required',
+                        'integer'  => 'Invalid User Role selected'
+                    ]
+                ],
+
+                // ======================
+                // Team (Multiple select)
+                // ======================
+                'team' => [
+                    'rules'  => 'required',
+                    'errors' => [
+                        'required' => 'At least one User Team must be selected'
+                    ]
+                ],
+            ];
+            if (!$this->validate($rules)) {
+                return $this->response->setStatusCode(400)->setJSON([
+                    'status' => false,
+                    'message' => 'Input validation failed',
+                    'code' => 400,
+                    'errors' => $this->validator->getErrors()
+                ]);
+            }
+            
+            $data      = $this->request->getPost();
+            $userData  = sanitizeInputArrayAdvanced($data);
+            $id = $userData['PrimaryKey'];
+            $teams = $userData['team'];
+            
             unset($userData['csrf_test_name']);
             unset($userData['PrimaryKey']);
 
@@ -594,29 +808,100 @@ class UserController extends AdminController
             
             // add/update
             if ($method === 'post') {
-                $data = $this->request->getPost();
-                $id = !empty($data['PrimaryKey']) ? $data['PrimaryKey'] : null;
+
+                $rules = [
+                    // ======================
+                    // Partner Name
+                    // ======================
+                    'name' => [
+                        'rules'  => 'required|alpha_space|min_length[2]|max_length[100]',
+                        'errors' => [
+                            'required'    => 'Partner name is required',
+                            'alpha_space' => 'Partner name can contain only letters and spaces',
+                            'min_length'  => 'Partner name must be at least 2 characters',
+                            'max_length'  => 'Partner name cannot exceed 100 characters'
+                        ]
+                    ],
+                    // ======================
+                    // Mobile Number
+                    // ======================
+                    'mobile' => [
+                        'rules'  => 'required|regex_match[/^[6-9][0-9]{9}$/]',
+                        'errors' => [
+                            'required'    => 'Mobile number is required',
+                            'regex_match' => 'Enter a valid 10-digit mobile number starting with 6, 7, 8, or 9',
+                        ]
+                    ],
+
+                    // ======================
+                    // Email
+                    // ======================
+                    'email' => [
+                        'rules'  => 'required|valid_email',
+                        'errors' => [
+                            'required'    => 'Email is required',
+                            'valid_email' => 'Please enter a valid email address',
+                        ]
+                    ],
+                    // ======================
+                    // Retention Rate
+                    // ======================
+                     'retention_rate' => [
+        'rules'  => [
+            'required',
+            'regex_match[/^(100(\.0{1,2})?|([0-9]{1,2})(\.[0-9]{1,2})?)$/]'
+        ],
+        'errors' => [
+            'required'    => 'Retention Rate is required',
+            'regex_match' => 'Retention Rate must be between 0 and 100 with up to 2 decimal places'
+        ]
+        ],
+                    // ======================
+                    // Nhance Branch
+                    // ======================
+                    'nhance_branch_id' => [
+                        'rules'  => 'required|integer',
+                        'errors' => [
+                            'required' => 'Nhance Branch is required',
+                            'integer'  => 'Invalid Nhance Branch selected'
+                        ]
+                    ],
+                ];
+                if (! $this->validate($rules)) {
+                return $this->response->setStatusCode(400)->setJSON([
+                    'status'  => false,
+                    'message' => 'Input validation failed',
+                    'code'    => 400,
+                    'errors'  => $this->validator->getErrors()
+                ]);
+            }
+
+
+                $data           = $this->request->getPost();
+                $sanitized_post_data = sanitizeInputArrayAdvanced($data);
+                $id = !empty($sanitized_post_data['PrimaryKey']) ? $sanitized_post_data['PrimaryKey'] : null;
+                unset($sanitized_post_data['pk']); 
                 
                 // don't forgot same means just unset the key because partner_staff some UNIQUE KEY sets in table thats why
                 if ($id) {
                     $existing = $this->partnerStaffModel->find((int)$id);
                     if ($existing) {
-                        if ($data['email'] === $existing['email']) { unset($data['email']); }
-                        if ($data['mobile'] === $existing['mobile']) { unset($data['mobile']); }
+                        if ($sanitized_post_data['email'] === $existing['email']) { unset($sanitized_post_data['email']); }
+                        if ($sanitized_post_data['mobile'] === $existing['mobile']) { unset($sanitized_post_data['mobile']); }
                     }
                 }
 
                 $errors = [];
 
                 // Check Email Duplicate (if it wasn't unset)
-                if (isset($data['email'])) {
-                    $count = $this->partnerStaffModel->where('email', $data['email'])->countAllResults();
+                if (isset($sanitized_post_data['email'])) {
+                    $count = $this->partnerStaffModel->where('email', $sanitized_post_data['email'])->countAllResults();
                     if ($count > 0) $errors['email'] = "This email is already taken by another user.";
                 }
 
                 // Check Mobile Duplicate (if it wasn't unset)
-                if (isset($data['mobile'])) {
-                    $count = $this->partnerStaffModel->where('mobile', $data['mobile'])->countAllResults();
+                if (isset($sanitized_post_data['mobile'])) {
+                    $count = $this->partnerStaffModel->where('mobile', $sanitized_post_data['mobile'])->countAllResults();
                     if ($count > 0) $errors['mobile'] = "This mobile is already taken by another user.";
                 }
 
@@ -632,14 +917,14 @@ class UserController extends AdminController
                 // --- Save/Update ---
                 if ($id) {
                     $text   = "update";            
-                    $data['updated_by'] =  get_session_userid();
+                    $sanitized_post_data['updated_by'] =  get_session_userid();
                     
-                    $result = $this->partnerStaffModel->update($id, $data);
+                    $result = $this->partnerStaffModel->update($id, $sanitized_post_data);
                 } else {
                     $text = "create";
-                    $data['role_id'] = 1;
-                    $data['created_by'] = get_session_userid();
-                    $id = $this->partnerStaffModel->insert($data);
+                    $sanitized_post_data['role_id'] = 1;
+                    $sanitized_post_data['created_by'] = get_session_userid();
+                    $id = $this->partnerStaffModel->insert($sanitized_post_data);
                     if($id){
                         $details['manager_id'] = $id;
                         $details['updated_by'] =  get_session_userid();
diff --git a/app/Controllers/VidalApiController.php b/app/Controllers/VidalApiController.php
index a6c45242..0c0bc293 100644
--- a/app/Controllers/VidalApiController.php
+++ b/app/Controllers/VidalApiController.php
@@ -112,7 +112,7 @@ class VidalApiController extends BaseController
         ];
     }
 
-    public function  SubmitClaim ($claimId = 515)
+    public function  SubmitClaim ($claimId = null) //515
     {
         helper('api');
 
diff --git a/app/Filters/AuthMVC.php b/app/Filters/AuthMVC.php
index efda2976..298a72b9 100755
--- a/app/Filters/AuthMVC.php
+++ b/app/Filters/AuthMVC.php
@@ -23,13 +23,11 @@ class AuthMVC implements FilterInterface
         // }
 
         // Fingerprint validation
-        $fp = hash('sha256', 
-            $request->getUserAgent()->getAgentString() . '|' . $request->getIPAddress()
-        );
-
-        if (session()->get('fingerprint') !== $fp) {
-            return AuthLogout::logout();
-        }
+        // $fp = generateFingerprint();
+        // // log_message('error',$fp);
+        // if (session()->get('fingerprint') !== $fp) {
+        //     return AuthLogout::logout();
+        // }
 
     }
 
diff --git a/app/Helpers/JWTToken.php b/app/Helpers/JWTToken.php
index 73978ddb..311182d4 100755
--- a/app/Helpers/JWTToken.php
+++ b/app/Helpers/JWTToken.php
@@ -38,6 +38,7 @@ class JWTToken
            
             }else{
                 $models = new LevelContactModel();
+                $id = $request_data['post_hr_id'];
                 $models->update($id, $data);
 
             }
diff --git a/app/Helpers/excel_util_helper.php b/app/Helpers/excel_util_helper.php
index ef882326..a4f773cd 100755
--- a/app/Helpers/excel_util_helper.php
+++ b/app/Helpers/excel_util_helper.php
@@ -1884,7 +1884,7 @@ if (!function_exists('premium_calculation_manager')) {
 
         }
         // if the family floater case first self add first the process completed, after spouse or any dependent add the rata premium not added this change will handle this
-        if (strtolower($emp_data['relationship']) != 'self' && $temp_slab_rates[0]['premium_type'] == 1 && $emp_data['temp']['action'] == 'DA') {
+        if (strtolower($emp_data['relationship']) != 'self' && empty($emp_data['temp']['acting_self']) && $temp_slab_rates[0]['premium_type'] == 1 && $emp_data['temp']['action'] == 'DA') {
             //set dependent si to 0
             $emp_data['policy_details']['basic_cover_si'] = 0;
             $emp_data['policy_details']['premium'] = 0;
@@ -1897,7 +1897,7 @@ if (!function_exists('premium_calculation_manager')) {
                 $emp_data['policy_details']['gst'] = (float) number_format(($emp_data['policy_details']['rata_premimum'] * ($gst / 100)), 2, '.', '');
             }
 
-        }else if(strtolower($emp_data['relationship']) != 'self' && $temp_slab_rates[0]['premium_type'] == 1 && ($emp_data['temp']['action'] == 'I' || $emp_data['temp']['action'] == 'A' || $emp_data['temp']['action'] == 'MI')){
+        }else if(strtolower($emp_data['relationship']) != 'self' && empty($emp_data['temp']['acting_self']) && $temp_slab_rates[0]['premium_type'] == 1 && ($emp_data['temp']['action'] == 'I' || $emp_data['temp']['action'] == 'A' || $emp_data['temp']['action'] == 'MI')){
 
             $emp_data['policy_details']['basic_cover_si'] = 0;
             $emp_data['policy_details']['premium'] = 0;
diff --git a/app/Helpers/utility_helper.php b/app/Helpers/utility_helper.php
index 15d873eb..79e4ddf9 100755
--- a/app/Helpers/utility_helper.php
+++ b/app/Helpers/utility_helper.php
@@ -640,6 +640,8 @@ if (!function_exists('change_date_format')) {
 
             'd/m/Y',     // 01/01/2025
             'd-m-Y',     // 01-01-2025
+            'm/d/Y h:i:s A',     // 01-01-2025
+            'm/d/Y',     // 25-05-2025
 
         ];
 
@@ -649,7 +651,7 @@ if (!function_exists('change_date_format')) {
                 $date = DateTime::createFromFormat($source_format, $date_str);
                 if (!$date) {
                     // throw new Exception("Invalid date string for source format: $source_format");
-                    log_message('error', "❌ Date format error : Invalid date string | Params => date_str: {$date_str}, source_format: {$source_format}, output_format: {$output_format}");
+                    // log_message('error', "❌ Date format error : Invalid date string | Params => date_str: {$date_str}, source_format: {$source_format}, output_format: {$output_format}");
                     return null;
                 }
                 return $date->format($output_format);
@@ -660,7 +662,7 @@ if (!function_exists('change_date_format')) {
                 $date = DateTime::createFromFormat($source_format, $date_str);
                 if (!$date) {
                     // throw new Exception("Invalid date string for source format: $source_format");
-                    log_message('error', "❌ Date format error : Invalid date string | Params => date_str: {$date_str}, source_format: {$source_format}, output_format: {$output_format}");
+                    // log_message('error', "❌ Date format error : Invalid date string | Params => date_str: {$date_str}, source_format: {$source_format}, output_format: {$output_format}");
                     return null;
                 }
                 return $date->format('Y-m-d'); // MySQL default format
@@ -677,15 +679,15 @@ if (!function_exists('change_date_format')) {
                 // If no format matches, throw an exception
                 $allowed_placeholders = implode(', ', $allowed_formats);
                 // throw new Exception("Invalid date string format. Allowed formats: $allowed_placeholders");
-                log_message(
-                    'error',
-                    "❌ Date format error: Invalid date string. Allowed formats: {$allowed_placeholders} | Params => date_str: {$date_str}, source_format: {$source_format}, output_format: {$output_format}"
-                );
+                // log_message(
+                //     'error',
+                //     "❌ Date format error: Invalid date string. Allowed formats: {$allowed_placeholders} | Params => date_str: {$date_str}, source_format: {$source_format}, output_format: {$output_format}"
+                // );
                 return null;
             }
         } catch (Exception $e) {
             // return "Error: " . $e->getMessage();
-            log_message('error', "❌ Date format error: {$e->getMessage()} | Params => date_str: {$date_str}, source_format: {$source_format}, output_format: {$output_format}");
+            // log_message('error', "❌ Date format error: {$e->getMessage()} | Params => date_str: {$date_str}, source_format: {$source_format}, output_format: {$output_format}");
             return null;
         }
 
@@ -1036,3 +1038,66 @@ if (!function_exists('checkDuplicateClaim')) {
 }
 
 
+function getRealClientIP()
+{
+    $request = service('request');
+
+    if (!empty($_SERVER['HTTP_CF_CONNECTING_IP'])) {
+        return $_SERVER['HTTP_CF_CONNECTING_IP'];
+    }
+
+    if (!empty($_SERVER['HTTP_X_FORWARDED_FOR'])) {
+        return explode(',', $_SERVER['HTTP_X_FORWARDED_FOR'])[0];
+    }
+
+    return $request->getIPAddress();
+}
+
+function generateFingerprint()
+{
+    $request = service('request');
+
+    $ua = $request->getUserAgent()->getAgentString();
+    $ip = getRealClientIP();
+
+    // Use only subnet (first 3 blocks) to tolerate IP change
+    $ipParts = explode('.', $ip);
+    $ipSubnet = $ipParts[0] . '.' . $ipParts[1] . '.' . $ipParts[2];
+
+    // $secret = env('app.sessionFingerprintSalt');
+
+    // return hash('sha256', $ua . '|' . $ipSubnet . '|' . $secret);
+    return hash('sha256', $ua . '|' . $ipSubnet );
+}
+
+if (!function_exists('convertGoogleDriveToDownloadLink')) {
+    function convertGoogleDriveToDownloadLink(?string $url): ?string
+    {
+        if (empty($url)) {
+            return null;
+        }
+
+        // Trim spaces
+        $url = trim($url);
+
+        // Pattern to extract Google Drive file ID
+        $patterns = [
+            '#https?://drive\.google\.com/file/d/([^/]+)/?#',
+            '#https?://drive\.google\.com/open\?id=([^&]+)#',
+            '#https?://drive\.google\.com/uc\?id=([^&]+)#'
+        ];
+
+        foreach ($patterns as $pattern) {
+            if (preg_match($pattern, $url, $matches)) {
+                $fileId = $matches[1];
+
+                // Return direct download link
+                return 'https://drive.google.com/uc?export=download&id=' . $fileId;
+            }
+        }
+
+        // Not a Google Drive link → return original
+        return $url;
+    }
+}
+
diff --git a/app/Libraries/TPAClaimsImportServices/AbhiClaimImportService.php b/app/Libraries/TPAClaimsImportServices/AbhiClaimImportService.php
new file mode 100644
index 00000000..21818613
--- /dev/null
+++ b/app/Libraries/TPAClaimsImportServices/AbhiClaimImportService.php
@@ -0,0 +1,480 @@
+ ["col_name" => "ABHI Claim No", "col_index" => 0], "db_column" => "abhi_claim_no"],
+        ["excel_column" => ["col_name" => "New ABHI Claim No With Extension", "col_index" => 1], "db_column" => "new_abhi_claim_no_with_extension"],
+        ["excel_column" => ["col_name" => "Unique Count", "col_index" => 2], "db_column" => "unique_count"],
+        ["excel_column" => ["col_name" => "Proposer Name", "col_index" => 3], "db_column" => "proposer_name"],
+        ["excel_column" => ["col_name" => "Patient Name", "col_index" => 4], "db_column" => "patient_name"],
+        ["excel_column" => ["col_name" => "Family ID", "col_index" => 5], "db_column" => "family_id"],
+        ["excel_column" => ["col_name" => "Member Code", "col_index" => 6], "db_column" => "member_code"],
+        ["excel_column" => ["col_name" => "Patient Age", "col_index" => 7], "db_column" => "patient_age"],
+        ["excel_column" => ["col_name" => "Relation", "col_index" => 8], "db_column" => "relation"],
+        ["excel_column" => ["col_name" => "Gender", "col_index" => 9], "db_column" => "gender"],
+        ["excel_column" => ["col_name" => "Certificate No", "col_index" => 10], "db_column" => "certificate_no"],
+        ["excel_column" => ["col_name" => "Master Policy No", "col_index" => 11], "db_column" => "master_policy_no"],
+        ["excel_column" => ["col_name" => "Policy Number", "col_index" => 12], "db_column" => "policy_number"],
+        ["excel_column" => ["col_name" => "Policy From", "col_index" => 13], "db_column" => "policy_from"],
+        ["excel_column" => ["col_name" => "Policy Upto", "col_index" => 14], "db_column" => "policy_upto"],
+        ["excel_column" => ["col_name" => "Product Name", "col_index" => 15], "db_column" => "product_name"],
+        ["excel_column" => ["col_name" => "Product Name 1", "col_index" => 16], "db_column" => "product_name_1"],
+        ["excel_column" => ["col_name" => "Sub - Product", "col_index" => 17], "db_column" => "sub_product"],
+        ["excel_column" => ["col_name" => "Policy Category", "col_index" => 18], "db_column" => "policy_category"],
+        ["excel_column" => ["col_name" => "Policy Category (Carry Forward till Q3 18-19)+(New Q4 18-19 Onward)", "col_index" => 19], "db_column" => "policy_category_cf_q3_q4"],
+        ["excel_column" => ["col_name" => "Sum Insured", "col_index" => 20], "db_column" => "sum_insured"],
+        ["excel_column" => ["col_name" => "Bonus", "col_index" => 21], "db_column" => "bonus"],
+        ["excel_column" => ["col_name" => "Intimation Date", "col_index" => 22], "db_column" => "intimation_date"],
+        ["excel_column" => ["col_name" => "Date Of Doc Rec", "col_index" => 23], "db_column" => "date_of_doc_rec"],
+        ["excel_column" => ["col_name" => "Intimation Final Month", "col_index" => 24], "db_column" => "intimation_final_month"],
+        ["excel_column" => ["col_name" => "Reported Year", "col_index" => 25], "db_column" => "reported_year"],
+        ["excel_column" => ["col_name" => "Reported Qurter", "col_index" => 26], "db_column" => "reported_quarter"],
+        ["excel_column" => ["col_name" => "Hospital Name", "col_index" => 27], "db_column" => "hospital_name"],
+        ["excel_column" => ["col_name" => "Hospital City", "col_index" => 28], "db_column" => "hospital_city"],
+        ["excel_column" => ["col_name" => "Hospital State", "col_index" => 29], "db_column" => "hospital_state"],
+        ["excel_column" => ["col_name" => "Diagnosis", "col_index" => 30], "db_column" => "diagnosis"],
+        ["excel_column" => ["col_name" => "ICD Chapter", "col_index" => 31], "db_column" => "icd_chapter"],
+        ["excel_column" => ["col_name" => "ICD Block", "col_index" => 32], "db_column" => "icd_block"],
+        ["excel_column" => ["col_name" => "ICD Level1", "col_index" => 33], "db_column" => "icd_level1"],
+        ["excel_column" => ["col_name" => "ICD Level2", "col_index" => 34], "db_column" => "icd_level2"],
+        ["excel_column" => ["col_name" => "Procedure Description", "col_index" => 35], "db_column" => "procedure_description"],
+        ["excel_column" => ["col_name" => "PCS Description", "col_index" => 36], "db_column" => "pcs_description"],
+        ["excel_column" => ["col_name" => "DOA", "col_index" => 37], "db_column" => "doa"],
+        ["excel_column" => ["col_name" => "DOD", "col_index" => 38], "db_column" => "dod"],
+        ["excel_column" => ["col_name" => "Claim Type", "col_index" => 39], "db_column" => "claim_type"],
+        ["excel_column" => ["col_name" => "Claim Category", "col_index" => 40], "db_column" => "claim_category"],
+        ["excel_column" => ["col_name" => "Disc Datails", "col_index" => 41], "db_column" => "disc_details"],
+        ["excel_column" => ["col_name" => "Disc Date", "col_index" => 42], "db_column" => "disc_date"],
+        ["excel_column" => ["col_name" => "Hospital Code", "col_index" => 43], "db_column" => "hospital_code"],
+        ["excel_column" => ["col_name" => "Claim Status", "col_index" => 44], "db_column" => "claim_status"],
+        ["excel_column" => ["col_name" => "Final ABHI Status-Current Month", "col_index" => 45], "db_column" => "final_abhi_status_current_month"],
+        ["excel_column" => ["col_name" => "Claimed Amount", "col_index" => 46], "db_column" => "claimed_amount"],
+        ["excel_column" => ["col_name" => "ABHI Amount Less Coins - Current Month", "col_index" => 47], "db_column" => "abhi_amount_less_coins_current_month"],
+        ["excel_column" => ["col_name" => "Repudiation Date", "col_index" => 48], "db_column" => "repudiation_date"],
+        ["excel_column" => ["col_name" => "Settled Date", "col_index" => 49], "db_column" => "settled_date"],
+        ["excel_column" => ["col_name" => "Settled Month", "col_index" => 50], "db_column" => "settled_month"],
+        ["excel_column" => ["col_name" => "Settled Year", "col_index" => 51], "db_column" => "settled_year"],
+        ["excel_column" => ["col_name" => "Settled Quarter", "col_index" => 52], "db_column" => "settled_quarter"],
+        ["excel_column" => ["col_name" => "Rejection Category", "col_index" => 53], "db_column" => "rejection_category"],
+        ["excel_column" => ["col_name" => "Rejection Category - Level 1", "col_index" => 54], "db_column" => "rejection_category_level_1"],
+        ["excel_column" => ["col_name" => "Rejection Category - Level 2", "col_index" => 55], "db_column" => "rejection_category_level_2"],
+        ["excel_column" => ["col_name" => "COVID tagging - Current Month", "col_index" => 56], "db_column" => "covid_tagging_current_month"],
+        ["excel_column" => ["col_name" => "EXPECTED DOA", "col_index" => 57], "db_column" => "expected_doa"],
+        ["excel_column" => ["col_name" => "EXPECTED DOD", "col_index" => 58], "db_column" => "expected_dod"],
+        ["excel_column" => ["col_name" => "AGENT/BROKER CODE", "col_index" => 59], "db_column" => "agent_broker_code"],
+        ["excel_column" => ["col_name" => "AGENT/BROKER NAME", "col_index" => 60], "db_column" => "agent_broker_name"],
+        ["excel_column" => ["col_name" => "HEALTHCARD_ID", "col_index" => 61], "db_column" => "healthcard_id"],
+        ["excel_column" => ["col_name" => "ABHI_NETWORK_NON_NETWORK", "col_index" => 62], "db_column" => "abhi_network_non_network"],
+        ["excel_column" => ["col_name" => "CORPORATE_EMPLOYEE_CODE", "col_index" => 63], "db_column" => "corporate_employee_code"],
+    ];
+
+    protected $ticketMasterMapping = [
+
+        // Employee / Member details
+        'member_code'        => 'emp_code',
+        'relation'           => 'relationship',
+
+        // Policy / Claim identifiers
+        'policy_number'      => 'policy_no',
+        'abhi_claim_no'     => 'claim_number',
+
+        // Dates
+        'doa'                => 'doa',
+        'dod'                => 'dod',
+        'intimation_date'    => 'date_of_intimat',
+
+        // Claim info
+        'claim_status'       => 'tpa_claim_status',
+        'claimed_amount'     => 'claim_amount',
+
+        // Hospital details
+        'hospital_name'      => 'hospital_name',
+        'hospital_city'      => 'hospital_city',
+        'hospital_state'     => 'hospital_state',
+
+        // Settlement / decision
+        'repudiation_date'   => 'denial_date',
+        'settled_date'       => 'settled_date',
+        'rejection_category' => 'denial_reason',
+
+        // Misc
+        'diagnosis'          => 'claim_description',
+        'healthcard_id'      => 'tpa_no',
+    ];
+
+    protected $statusMapping = [
+        'Settled' => 11,
+        'Rejected' => 8,
+        'Cancelled' => 13,
+    ];
+
+    protected $dateColumns = [
+        'policy_from',
+        'policy_upto',
+
+        'intimation_date',
+        'date_of_doc_rec',
+
+        'doa',
+        'dod',
+
+        'repudiation_date',
+        'settled_date',
+
+        'expected_doa',
+        'expected_dod',
+    ];
+
+
+    /**
+     * ABSTRACT FUNCTIONs 
+     */
+    public function bulkInsertTPATable(array $data): bool
+    {
+        if (empty($data)) {
+            return false;
+        }
+
+        $builder = $this->db->table('claims_dump_abhi');
+
+        foreach ($data as $value) {
+
+            if (!$builder->insert($value)) {
+
+                // 🔍 Debug purpose
+                log_message('error', print_r($this->db->error(), true));
+                log_message('error', $this->db->getLastQuery());
+
+                return false;
+            }
+        }
+
+        return true;
+    }
+
+
+    public function importClaimMaster(array $data): bool
+    {
+        if (empty($data)) {
+            return false;
+        }
+
+        $ticketMasterModel = new TicketMasterModel();
+        $ticketMasterModel->insertBatch($data);
+
+        return true;
+    }
+
+
+    public function updateTicketIdInTPATable(): bool
+    {
+        if (empty($data)) {
+            return false;
+        }
+
+        $builder = $this->db->table('claims_dump_abhi');
+        $builder->insertBatch($data);
+
+        return true;
+    }
+
+
+    public function updateTicketMasterRejectedReasonInTPATable($data): bool
+    {
+        if (empty($data)) {
+            return false;
+        }
+
+        $builder = $this->db->table('claims_dump_abhi');
+        $builder->insertBatch($data);
+
+        return true;
+    }
+
+
+    /**
+     * MAPPING FUNCTIONs 
+     */
+
+    public function mapTPAData(array $rows, $file_id): array
+    {
+        $ClientPolicyModel = new ClaimDumpFileModel();
+        $file_data = $ClientPolicyModel->where('id', $file_id)->first();
+
+        $mapped = [];
+
+        foreach ($rows as $row) {
+
+            $item = [];
+
+            foreach ($this->mapping as $map) {
+                $excelColumn = $map['excel_column']['col_name'];
+                $dbColumn    = $map['db_column'];
+
+                $value = $row[$excelColumn] ?? null;
+                $item[$dbColumn] = trim($value);
+            }
+
+            foreach ($this->dateColumns as $key => $value) {
+                $item[$value] = change_date_format($item[$value] ?? null, 'm/d/Y h:i:s A', 'Y-m-d');
+            }
+
+            $params = [
+                'doa' => $item['doa'] ?? null,
+                'member_code' => $item['member_code'] ?? null,
+                'claimed_amount' => $item['claimed_amount'] ?? null,
+                'healthcard_id' => $item['healthcard_id'] ?? null
+            ];
+
+            $is_duplicate = $this->checkDuplicateTpaClaim('claims_dump_abhi', $params);
+
+            if ($is_duplicate) {
+                $item = [];
+                continue;
+            }
+
+            $item['file_id'] = $file_id ?? null;
+            $item['client_id'] = $file_data['client_id'] ?? null;
+            $item['client_policy_id'] = $file_data['client_policy_id'] ?? null;
+            $item['created_by'] = $file_data['created_by'] ?? null;
+
+            $mapped[] = $item;
+        }
+
+        return $mapped;
+    }
+
+    public function mapClaimMasterData($file_id): array
+    {
+
+        $ClientPolicyModel = new ClaimDumpFileModel();
+        $file_data = $ClientPolicyModel->where('id', $file_id)->first();
+
+        $tpaClaimDumpData = $this->getTpaClaimDumpData('claims_dump_abhi', ['file_id' => $file_id]);
+
+        if (empty($tpaClaimDumpData)) {
+            return ['status' => false, 'message' => "No data to insert in TICKET MASTER"];
+        }
+
+
+        $ClientPolicyModel = new ClientPolicyModel();
+        $client_policy_data = $ClientPolicyModel
+            ->select("
+                client_policy.*,
+                (
+                    SELECT id
+                    FROM client_rm
+                    WHERE is_active = 1
+                    AND level = 3
+                    AND client_id = client_policy.client_id
+                    ORDER BY id ASC
+                    LIMIT 1
+                ) AS acm_id
+            ")
+            ->where('client_policy.id', $file_data['client_policy_id'])
+            ->where('client_policy.is_active', 1)
+            ->first();
+
+        try {
+
+            $mapped = [];
+            $rejecetd_reason = [];
+
+            foreach ($tpaClaimDumpData as $row) {
+
+                $params = [
+                    'doa' => change_date_format($row['doa'] ?? '') ?? null,
+                    'emp_code' => $row['member_code'] ?? null,
+                    'claim_amount' => $row['claimed_amount'] ?? null,
+                    'tpa_no' => $row['healthcard_id'] ?? null
+                ];
+
+                $isduplicate = $this->checkDublicateTicketMasterClaim($params);
+
+                if ($isduplicate) {
+                    $reason = "This claim already exists in our system.";
+                    $rejecetd_reason[$row['id']] = ["ticket_master_insert_reject_reason" => $reason];
+                    continue;
+                }
+
+                $item = [];
+
+                $item['client_id']    = $client_policy_data['client_id'] ?? null;
+                $item['client_policy_id'] = $client_policy_data['id'] ?? null;
+                $item['insurer_id']  = $client_policy_data['insurer_id'] ?? null;
+                $item['tpa_id']  = $client_policy_data['tpa_id'] ?? null;
+                $item['acm_id']  = $client_policy_data['acm_id'] ?? null;
+                $item['policy_no']  = $client_policy_data['policy_no'] ?? null;
+                $item['relationship']  = $this->convertRelation($row['relation'] ?? null);
+
+                $employee_data = $this->getEmployeeDetails($file_data['client_id'], $file_data['client_policy_id'], $row['member_code'], $item['relationship']);
+
+                if (!empty($employee_data)) {
+                    $item['emp_id']    = $employee_data['id'] ?? null;
+                    $item['emp_name'] = $employee_data['name'] ?? null;
+                    $item['emp_mail']  = $employee_data['email_corporate'] ?? null;
+                    $item['emp_mobile']  = $employee_data['mobile'] ?? null;
+                    $item['insured_emp_id']  = $employee_data['insured_emp_id'] ?? null;
+                    $item['insured_name']  = $employee_data['insured_name'] ?? null;
+                } else {
+
+                    $reason = sprintf(
+                        'The policy number "%s" does not exist in our system. ' .
+                            'Details - Client ID: %s, Client Policy ID: %s, Employee Number: %s, Relationship: %s',
+                        $row['insurer_policy_number'],
+                        $file_data['client_id'],
+                        $file_data['client_policy_id'],
+                        $row['employee_number'],
+                        $item['relationship']
+                    );
+
+                    $rejecetd_reason[$row['id']] = ["ticket_master_insert_reject_reason" => $reason];
+                    continue;
+                }
+
+                foreach ($this->ticketMasterMapping as $tpaKey => $ticketMasterKey) {
+                    $item[$ticketMasterKey] = array_key_exists($tpaKey, $row) ? $row[$tpaKey] : null;
+                }
+
+                // Meta fields
+                $item['claim_status_id'] = $statusMapping[$row['claim_status']] ?? 61;
+                $item['file_id']    = $file_id;
+                $item['claim_dump_ref_id']    = $row['id'];
+                $item['created_by'] = $file_data['created_by'] ?? null;
+                $item['claim_type'] = isset($row['mainclaim_prepost_type']) && !empty($row['mainclaim_prepost_type']) && strtolower($row['mainclaim_prepost_type']) == 'normal' ? 1 : 3;
+                $item['priority']           = 1;
+                $item['mode_of_intimation'] = 5;
+                $item['ticket_type_id']     = 1;
+
+
+                $mapped[] = $item;
+            }
+
+            return ['status' => true, 'mapped_array' => $mapped, 'rejected_reason_array' => $rejecetd_reason];
+        } catch (\Throwable $th) {
+
+            $errorData = [
+                'message' => $th->getMessage(),
+                'file'    => $th->getFile(),
+                'line'    => $th->getLine(),
+                'code'    => $th->getCode(),
+                'trace'   => $th->getTraceAsString(),
+                'trace_array' => $th->getTrace(), // full array version (optional)
+                'function' => $th->getTrace()[0]['function'] ?? null,
+                'class' => $th->getTrace()[0]['class'] ?? null,
+            ];
+
+            return ['status' => false, "message" => $errorData['message'], 'error_data' => $errorData];
+        }
+    }
+
+
+    /**
+     * HELPER FUNCTIONs 
+     */
+
+    public function isDateValue($value): bool
+    {
+        if (empty($value)) {
+            return false;
+        }
+
+        // Excel numeric date
+        if (is_numeric($value) && $value > 30000) {
+            return true;
+        }
+
+        return strtotime(str_replace('/', '-', $value)) !== false;
+    }
+
+    public function normalizeDate($value): ?string
+    {
+        try {
+            if (empty($value)) {
+                return null;
+            }
+
+            // Excel numeric date
+            if (is_numeric($value)) {
+                return date(
+                    'Y-m-d',
+                    \PhpOffice\PhpSpreadsheet\Shared\Date::excelToTimestamp($value)
+                );
+            }
+
+            $value = trim((string) $value);
+
+            // Replace / with - for strtotime compatibility
+            $value = str_replace('/', '-', $value);
+
+            $timestamp = strtotime($value);
+
+            if ($timestamp === false) {
+                return null;
+            }
+
+            return date('Y-m-d', $timestamp);
+
+        } catch (\Throwable $e) {
+            return null;
+        }
+    }
+
+    public function convertRelation(?string $relation): ?string
+    {
+        if (empty($relation)) {
+            return null;
+        }
+
+        $relation = strtolower($relation);
+
+        if (str_contains($relation, 'self')) {
+            return 'self';
+        }
+
+        if (str_contains($relation, 'spouse') || str_contains($relation, 'wife') || str_contains($relation, 'husband')) {
+            return 'spouse';
+        }
+
+        if (str_contains($relation, 'daughter')) {
+            return 'daughter';
+        }
+
+        if (str_contains($relation, 'son')) {
+            return 'son';
+        }
+
+        if (str_contains($relation, 'father in law') || str_contains($relation, 'father-in-law')) {
+            return 'father-in-law';
+        }
+
+        if (str_contains($relation, 'mother in law') || str_contains($relation, 'mother-in-law')) {
+            return 'mother-in-law';
+        }
+
+        if (str_contains($relation, 'father')) {
+            return 'father';
+        }
+
+        if (str_contains($relation, 'mother')) {
+            return 'mother';
+        }
+
+        return null; // unmatched case
+    }
+
+}
diff --git a/app/Libraries/TPAClaimsImportServices/BaseTpaClaimImportService.php b/app/Libraries/TPAClaimsImportServices/BaseTpaClaimImportService.php
new file mode 100644
index 00000000..1485dee2
--- /dev/null
+++ b/app/Libraries/TPAClaimsImportServices/BaseTpaClaimImportService.php
@@ -0,0 +1,368 @@
+db = db_connect();
+        $this->claimDumpFileModel = new ClaimDumpFileModel();
+    }
+
+    /**
+     * First JOB for insert TPA wise Bulk Upload
+     */
+    public function runTpaClaimDumpInsert(string $filePath, int $fileId): array
+    {
+        $this->db->transStart();
+
+        $fileData = $this->claimDumpFileModel->where('id', $fileId)->first();
+
+        if (env('FHPL_PRIMARY_KEY_CONSTANT') == $fileData['tpa_id']) {
+            $rows = $this->readExcelBySheetName($filePath, 'Claims&Preauth');
+        } else if (env('R_CARE_PRIMARY_KEY_CONSTANT') == $fileData['tpa_id']) {
+            $rows = $this->readExcelBySheetName($filePath, 'CL');
+            // $AL = $this->readExcelBySheetName($filePath, 'AL');
+            // $rows = array_merge($CL, $AL);
+        } else {
+            $rows = $this->readExcel($filePath);
+        }
+        // dd($rows);
+
+        if (empty($rows)) {
+            return ['status' => false, 'message' => 'Excel file contains no data or wrong file upload'];
+        }
+
+        $tpaInsertData = $this->mapTPAData($rows, $fileId);
+        // dd($tpaInsertData);
+
+        if (empty($tpaInsertData)) {
+            return ['status' => false, 'message' => 'These records already exist in the system.'];
+        }
+
+        if (env('FHPL_PRIMARY_KEY_CONSTANT') == $fileData['tpa_id']) {
+            $ClaimsDumpFhplModel = $this->db->table('claims_dump_fhpl');
+            $return_res = $ClaimsDumpFhplModel->insertBatch($tpaInsertData);
+        } else if (env('R_CARE_PRIMARY_KEY_CONSTANT') == $fileData['tpa_id']) {
+            $ClaimsDumpIciciModel = $this->db->table('claims_dump_reliance');
+            $return_res = $ClaimsDumpIciciModel->insertBatch($tpaInsertData);
+        } else if (env('ICICI_PRIMARY_KEY_CONSTANT') == $fileData['tpa_id']) {
+            $ClaimsDumpIciciModel = $this->db->table('claims_dump_icici');
+            $return_res = $ClaimsDumpIciciModel->insertBatch($tpaInsertData);
+        } else if (env('ABHI_PRIMARY_KEY_CONSTANT') == $fileData['tpa_id']) {
+            // $ClaimsDumpAbhiModel = $this->db->table('claims_dump_abhi');
+            // $return_res = $ClaimsDumpAbhiModel->insertBatch($tpaInsertData);
+            $return_res = $this->bulkInsertTPATable($tpaInsertData);
+        } else if (env('VIDAL_PRIMARY_KEY_CONSTANT') == $fileData['tpa_id']) {
+            $ClaimsDumpVidalModel = $this->db->table('claims_dump_vidal');
+            $return_res = $ClaimsDumpVidalModel->insertBatch($tpaInsertData);
+        }  else if (env('MEDI_ASSIST_PRIMARY_KEY_CONSTANT') == $fileData['tpa_id']) {
+            $ClaimsDumpMediAssistModel = $this->db->table('claims_dump_medi_assist');
+            $return_res = $ClaimsDumpMediAssistModel->insertBatch($tpaInsertData);
+        } else{
+
+        }
+
+        // $return_res = $this->bulkInsertTPATable($tpaInsertData);
+
+        if (!$return_res) {
+            return ['status' => false, 'message' => 'TPA Import bulk insert failed'];
+        }
+
+        $this->db->transComplete();
+
+        if ($this->db->transStatus() === false) {
+
+            $error = $this->db->error();
+
+            $error_data = [
+                'message'    => $error['message'] ?: 'Unknown DB error',
+                'code'       => $error['code'] ?? null,
+                'last_query' => (string) $this->db->getLastQuery()
+            ];
+
+            // dd($error_data);
+            // unset($error_data['last_query']);
+            return ['status' => false, 'message' => 'TPA Import transaction failed', 'error_data' => $error_data];
+        }
+
+        return ['status' => true, 'message' => 'File uploaded successfully', 'record_count' => count($tpaInsertData ?? [])];
+    }
+
+    /**
+     * Second JOB for insert Ticket Master table after insert the TPA bulk upload success
+     */
+    public function runTicketMasterInsert(array $params): array
+    {
+        $this->db->transStart();
+
+        $file_id = $params['file_id']; 
+
+        $ticketMasterData = $this->mapClaimMasterData($file_id);
+
+        if (!$ticketMasterData['status']) {
+            return $ticketMasterData;
+        }
+
+        $return_res = $this->importClaimMaster($ticketMasterData['mapped_array']);
+
+        if(!$return_res){
+            return ['status' => false, 'message' => 'Ticket Master Claim bulk insert failed'];
+        }
+
+        $this->updateTicketMasterRejectedReasonInTPATable($ticketMasterData['rejected_reason_array']);
+
+        $this->db->transComplete();
+
+        if ($this->db->transStatus() === false) {
+            return ['status' => false, 'message' => 'Ticket Master Claim bulk insert failed'];
+        }
+
+
+
+        return ['status' => true, 'message' => 'Ticket Master Claim inserted successfully'];
+
+    }
+
+    /**
+     * Read Excel and return associative rows (header based)
+     */
+    protected function readExcel(string $filePath): array
+    {   
+        helper('excel_util_helper');
+
+        if (!file_exists($filePath)) {
+            throw new RuntimeException("File not found: {$filePath}");
+        }
+
+        $spreadsheet = IOFactory::load($filePath);
+        $sheet = $spreadsheet->getActiveSheet();
+
+        $rows = $sheet->toArray(null, true, true, true);
+
+        // dd($rows);
+
+        if (count($rows) < 2) {
+            return [];
+        }
+
+        // First row is header
+        $headers = array_shift($rows);
+        $headers = array_map('trim', $headers);
+
+        $data = [];
+
+        foreach ($rows as $row) {
+
+            if(check_row_is_empty_or_null($row)){
+                break;
+            }
+
+            $item = [];
+            foreach ($headers as $key => $headerName) {
+                if ($headerName !== '') {
+                    $item[$headerName] = $row[$key] ?? null;
+                }
+            }
+            $data[] = $item;
+        }
+
+        return $data;
+    }
+
+    /**
+     * Read Excel By Sheet name and return associative rows (header based)
+     */
+
+    protected function readExcelBySheetName(string $filePath, string $sheetName): array
+    {
+        if (!file_exists($filePath)) {
+            throw new RuntimeException("File not found: {$filePath}");
+        }
+
+        $spreadsheet = IOFactory::load($filePath);
+
+        // Get sheet by name
+        $sheet = $spreadsheet->getSheetByName($sheetName);
+
+        if ($sheet === null) {
+            throw new RuntimeException("Sheet '{$sheetName}' not found in Excel file");
+        }
+
+        $rows = $sheet->toArray(null, true, true, true);
+
+        // Need at least header + one row
+        if (count($rows) < 2) {
+            return [];
+        }
+
+        // First row = headers
+        $headers = array_shift($rows);
+        $headers = array_map('trim', $headers);
+
+        $data = [];
+
+        foreach ($rows as $row) {
+            // Skip completely empty rows
+            if (!array_filter($row)) {
+                continue;
+            }
+
+            $item = [];
+
+            foreach ($headers as $key => $headerName) {
+                if ($headerName !== '') {
+                    $item[$headerName] = $row[$key] ?? null;
+                }
+            }
+
+            $data[] = $item;
+        }
+
+        return $data;
+    }
+
+
+    /**
+     * Dublicate check in the ticket_master table records
+     */
+    protected function checkDublicateTicketMasterClaim(array $param): bool
+    {   
+        $ticketMaster = new TicketMasterModel();
+        $ticket_master_data = $ticketMaster
+                ->where('doa', $param['doa'])
+                ->where('tpa_no', $param['tpa_no'])
+                ->where('claim_amount', $param['claim_amount'])
+                ->where('emp_code', $param['emp_code'])
+                ->where('is_active', 1)
+                ->findAll();
+
+        if(count($ticket_master_data) > 0){
+            return true;
+        }
+
+        return false;
+    }
+
+    /**
+     * Dublicate check in the TPA specific table records
+     */
+    protected function checkDuplicateTpaClaim(string $table, array $params): bool
+    {   
+        return $this->db->table($table)
+            ->where($params)
+            ->where('is_active', 1)
+            ->countAllResults() > 0;
+    }
+
+    /**
+     * Dublicate check in the TPA specific table records
+     */
+    protected function getTpaClaimDumpData(string $table, array $params): array
+    {   
+        $tpaClaimDumpDataCount = $this->db
+            ->table($table)
+            ->where('is_active', 1)
+            ->where('file_id', $params['file_id'])
+            ->where('ticket_id IS NULL')
+            ->countAllResults();
+
+        $batch_size  = 100;
+        $total_batch = (int) ceil($tpaClaimDumpDataCount / $batch_size);
+        $batch_no    = isset($params['batch_no']) ? (int) $params['batch_no'] : null;
+        $last_emp_id = (int) ($params['last_emp_id'] ?? 0);
+
+
+        return $this->db
+            ->table($table)
+            ->where('is_active', 1)
+            ->where('file_id', $params['file_id'])
+            ->where('ticket_id IS NULL')
+            ->get()
+            ->getResultArray();
+
+    }
+
+    /**
+     * Dublicate check in the TPA specific table records
+     */
+    public function getEmployeeDetails(int $client_id, int $client_policy_id, string $emp_code, string $relation): array
+    {
+        $EmployeeModel = new EmployeeModel();
+        $employeeData = $EmployeeModel
+            ->select([
+                'employees.id AS emp_id',
+                'employees.email_corporate AS emp_mail',
+                'employees.mobile AS emp_mobile',
+                'employees.name AS emp_name',
+
+                // insured employee
+                'insured.id AS insured_emp_id',
+                'insured.name AS insured_name'
+            ])
+            ->join(
+                'employee_polices',
+                'employees.id = employee_polices.employee_id'
+            )
+            ->join(
+                'employees AS insured',
+                "insured.emp_code = employees.emp_code
+                AND insured.client_id = employees.client_id
+                AND LOWER(insured.relationship) = " . $EmployeeModel->db->escape(strtolower($relation)),
+                'left'
+            )
+            ->where('employees.is_active', 1)
+            ->where('employee_polices.is_active', 1)
+            ->where('employee_polices.client_policy_id', $client_policy_id)
+            ->where('employees.client_id', $client_id)
+            ->where('employees.emp_code', $emp_code)
+            ->where('LOWER(employees.relationship)', 'self')
+            ->first();
+
+
+        return $employeeData ?? [];
+    }
+
+    /**
+     * Map Excel rows to TPA table structure
+     */
+    abstract protected function mapTPAData(array $rows, $fileId): array;
+
+    /**
+     * Map DB rows to Ticket Master table structure
+     */
+    abstract protected function mapClaimMasterData($fileId): array;
+
+    /**
+     * Insert into TPA-specific table (bulk)
+     */
+    abstract protected function bulkInsertTPATable(array $data): bool;
+
+    /**
+     * Insert into Ticket-Master-specific table (bulk)
+     */
+    abstract protected function importClaimMaster(array $data): bool;
+
+    /**
+     * Update TPA table with ticket_master primary key
+     */
+    abstract protected function updateTicketIdInTPATable(): bool;
+
+    /**
+     * Update TPA table with ticket_master insert rejected reason
+     */
+    abstract protected function updateTicketMasterRejectedReasonInTPATable(array $data): bool;
+}
diff --git a/app/Libraries/TPAClaimsImportServices/FhplClaimImportService.php b/app/Libraries/TPAClaimsImportServices/FhplClaimImportService.php
new file mode 100644
index 00000000..72614418
--- /dev/null
+++ b/app/Libraries/TPAClaimsImportServices/FhplClaimImportService.php
@@ -0,0 +1,500 @@
+["col_name"=>"Requesttype","col_index"=>0],"db_column"=>"request_type"],
+        ["excel_column"=>["col_name"=>"Intimation ID","col_index"=>1],"db_column"=>"intimation_id"],
+        ["excel_column"=>["col_name"=>"Intimation Date","col_index"=>2],"db_column"=>"intimation_date"],
+        ["excel_column"=>["col_name"=>"claimid","col_index"=>3],"db_column"=>"claim_id"],
+        ["excel_column"=>["col_name"=>"slno","col_index"=>4],"db_column"=>"sl_no"],
+        ["excel_column"=>["col_name"=>"UHIDNO","col_index"=>5],"db_column"=>"uhid_no"],
+        ["excel_column"=>["col_name"=>"Membername","col_index"=>6],"db_column"=>"member_name"],
+        ["excel_column"=>["col_name"=>"Main Memuhidno","col_index"=>7],"db_column"=>"main_member_uhid_no"],
+        ["excel_column"=>["col_name"=>"Main Memname","col_index"=>8],"db_column"=>"main_member_name"],
+        ["excel_column"=>["col_name"=>"Gender","col_index"=>9],"db_column"=>"gender"],
+        ["excel_column"=>["col_name"=>"DOB","col_index"=>10],"db_column"=>"dob"],
+        ["excel_column"=>["col_name"=>"Yrs","col_index"=>11],"db_column"=>"years"],
+        ["excel_column"=>["col_name"=>"relationship","col_index"=>12],"db_column"=>"relationship"],
+        ["excel_column"=>["col_name"=>"employeeid","col_index"=>13],"db_column"=>"employee_id"],
+        ["excel_column"=>["col_name"=>"Mobile","col_index"=>14],"db_column"=>"mobile"],
+        ["excel_column"=>["col_name"=>"Email","col_index"=>15],"db_column"=>"email"],
+        ["excel_column"=>["col_name"=>"Policy No","col_index"=>16],"db_column"=>"policy_no"],
+        ["excel_column"=>["col_name"=>"Policy Start Date","col_index"=>17],"db_column"=>"policy_start_date"],
+        ["excel_column"=>["col_name"=>"Policy Commencing Date","col_index"=>18],"db_column"=>"policy_commencing_date"],
+        ["excel_column"=>["col_name"=>"Policy Expiry Date","col_index"=>19],"db_column"=>"policy_expiry_date"],
+        ["excel_column"=>["col_name"=>"Organisationname","col_index"=>20],"db_column"=>"organisation_name"],
+        ["excel_column"=>["col_name"=>"Claimreceiveddate","col_index"=>21],"db_column"=>"claim_received_date"],
+        ["excel_column"=>["col_name"=>"Admdate","col_index"=>22],"db_column"=>"admission_date"],
+        ["excel_column"=>["col_name"=>"Dis Date","col_index"=>23],"db_column"=>"discharge_date"],
+        ["excel_column"=>["col_name"=>"Diagnosis","col_index"=>24],"db_column"=>"diagnosis"],
+        ["excel_column"=>["col_name"=>"Service Type","col_index"=>25],"db_column"=>"service_type"],
+        ["excel_column"=>["col_name"=>"Service Sub Type","col_index"=>26],"db_column"=>"service_sub_type"],
+        ["excel_column"=>["col_name"=>"icdcode First Level","col_index"=>27],"db_column"=>"icd_code_first_level"],
+        ["excel_column"=>["col_name"=>"icdcode Second Level","col_index"=>28],"db_column"=>"icd_code_second_level"],
+        ["excel_column"=>["col_name"=>"icdcode Third Level","col_index"=>29],"db_column"=>"icd_code_third_level"],
+        ["excel_column"=>["col_name"=>"Claim Type","col_index"=>30],"db_column"=>"claim_type"],
+        ["excel_column"=>["col_name"=>"Providername","col_index"=>31],"db_column"=>"provider_name"],
+        ["excel_column"=>["col_name"=>"provideraddress","col_index"=>32],"db_column"=>"provider_address"],
+        ["excel_column"=>["col_name"=>"providerplace","col_index"=>33],"db_column"=>"provider_place"],
+        ["excel_column"=>["col_name"=>"providerstate","col_index"=>34],"db_column"=>"provider_state"],
+        ["excel_column"=>["col_name"=>"Provider Pincode","col_index"=>35],"db_column"=>"provider_pincode"],
+        ["excel_column"=>["col_name"=>"PROVIDERTYPE","col_index"=>36],"db_column"=>"provider_type"],
+        ["excel_column"=>["col_name"=>"Provider Identification","col_index"=>37],"db_column"=>"provider_identification"],
+        ["excel_column"=>["col_name"=>"coverageamount","col_index"=>38],"db_column"=>"coverage_amount"],
+        ["excel_column"=>["col_name"=>"claimamount","col_index"=>39],"db_column"=>"claim_amount"],
+        ["excel_column"=>["col_name"=>"billedamount","col_index"=>40],"db_column"=>"billed_amount"],
+        ["excel_column"=>["col_name"=>"Disallowed Amount","col_index"=>41],"db_column"=>"disallowed_amount"],
+        ["excel_column"=>["col_name"=>"Dis Allowence Reason1","col_index"=>42],"db_column"=>"dis_allowance_reason_1"],
+        ["excel_column"=>["col_name"=>"Dis Allowence Reason2","col_index"=>43],"db_column"=>"dis_allowance_reason_2"],
+        ["excel_column"=>["col_name"=>"settledamt","col_index"=>44],"db_column"=>"settled_amount"],
+        ["excel_column"=>["col_name"=>"Incurred Amount","col_index"=>45],"db_column"=>"incurred_amount"],
+        ["excel_column"=>["col_name"=>"Discountamount","col_index"=>46],"db_column"=>"discount_amount"],
+        ["excel_column"=>["col_name"=>"TDSAmount","col_index"=>47],"db_column"=>"tds_amount"],
+        ["excel_column"=>["col_name"=>"Net Amount Paid","col_index"=>48],"db_column"=>"net_amount_paid"],
+        ["excel_column"=>["col_name"=>"Co Payment","col_index"=>49],"db_column"=>"co_payment"],
+        ["excel_column"=>["col_name"=>"Current Claim Status","col_index"=>50],"db_column"=>"current_claim_status"],
+        ["excel_column"=>["col_name"=>"Balance Suminsured","col_index"=>51],"db_column"=>"balance_sum_insured"],
+        ["excel_column"=>["col_name"=>"Chequeno","col_index"=>52],"db_column"=>"cheque_no"],
+        ["excel_column"=>["col_name"=>"chequedate","col_index"=>53],"db_column"=>"cheque_date"],
+        ["excel_column"=>["col_name"=>"Claim Passed Date","col_index"=>54],"db_column"=>"claim_passed_date"],
+        ["excel_column"=>["col_name"=>"Settled Date","col_index"=>55],"db_column"=>"settled_date"],
+        ["excel_column"=>["col_name"=>"Pending Remarks","col_index"=>56],"db_column"=>"pending_remarks"],
+        ["excel_column"=>["col_name"=>"Ir Investigation","col_index"=>57],"db_column"=>"ir_investigation"],
+        ["excel_column"=>["col_name"=>"Date of IR","col_index"=>58],"db_column"=>"ir_date"],
+        ["excel_column"=>["col_name"=>"Date of IRretrieval Date","col_index"=>59],"db_column"=>"ir_retrieval_date"],
+        ["excel_column"=>["col_name"=>"first Reminder","col_index"=>60],"db_column"=>"first_reminder"],
+        ["excel_column"=>["col_name"=>"Second Reminder","col_index"=>61],"db_column"=>"second_reminder"],
+        ["excel_column"=>["col_name"=>"Rejection Remarks","col_index"=>62],"db_column"=>"rejection_remarks"],
+        ["excel_column"=>["col_name"=>"Payee name","col_index"=>63],"db_column"=>"payee_name"],
+        ["excel_column"=>["col_name"=>"Treatment Type","col_index"=>64],"db_column"=>"treatment_type"],
+        ["excel_column"=>["col_name"=>"roomdays","col_index"=>65],"db_column"=>"room_days"],
+        ["excel_column"=>["col_name"=>"icudays","col_index"=>66],"db_column"=>"icu_days"],
+        ["excel_column"=>["col_name"=>"totalstay","col_index"=>67],"db_column"=>"total_stay"],
+        ["excel_column"=>["col_name"=>"Room Rent Claimed","col_index"=>68],"db_column"=>"room_rent_claimed"],
+        ["excel_column"=>["col_name"=>"ICU Claimed","col_index"=>69],"db_column"=>"icu_claimed"],
+        ["excel_column"=>["col_name"=>"ICU Related","col_index"=>70],"db_column"=>"icu_related"],
+        ["excel_column"=>["col_name"=>"Nursing Claimed","col_index"=>71],"db_column"=>"nursing_claimed"],
+        ["excel_column"=>["col_name"=>"Nursing Charges","col_index"=>72],"db_column"=>"nursing_charges"],
+        ["excel_column"=>["col_name"=>"Room Rent Related","col_index"=>73],"db_column"=>"room_rent_related"],
+        ["excel_column"=>["col_name"=>"Professional Charges","col_index"=>74],"db_column"=>"professional_charges"],
+        ["excel_column"=>["col_name"=>"Drugs Medication Consumables Investigationsetc","col_index"=>75],"db_column"=>"drugs_medication_consumables"],
+        ["excel_column"=>["col_name"=>"Investigations Procedures IP","col_index"=>76],"db_column"=>"investigations_procedures_ip"],
+        ["excel_column"=>["col_name"=>"Domicillary Hospitalization","col_index"=>77],"db_column"=>"domicillary_hospitalization"],
+        ["excel_column"=>["col_name"=>"Maternity","col_index"=>78],"db_column"=>"maternity"],
+        ["excel_column"=>["col_name"=>"Day Care","col_index"=>79],"db_column"=>"day_care"],
+        ["excel_column"=>["col_name"=>"Operation Theatre","col_index"=>80],"db_column"=>"operation_theatre"],
+        ["excel_column"=>["col_name"=>"Organ Donar","col_index"=>81],"db_column"=>"organ_donor"],
+        ["excel_column"=>["col_name"=>"Ancilliary Services","col_index"=>82],"db_column"=>"ancillary_services"],
+        ["excel_column"=>["col_name"=>"Dental","col_index"=>83],"db_column"=>"dental"],
+        ["excel_column"=>["col_name"=>"Out Patient Coverage","col_index"=>84],"db_column"=>"out_patient_coverage"],
+        ["excel_column"=>["col_name"=>"Personal Accident","col_index"=>85],"db_column"=>"personal_accident"],
+        ["excel_column"=>["col_name"=>"Critical Illness","col_index"=>86],"db_column"=>"critical_illness"],
+        ["excel_column"=>["col_name"=>"Health Check Up","col_index"=>87],"db_column"=>"health_check_up"],
+        ["excel_column"=>["col_name"=>"Spectacles Contact Lenses Hearing Aid","col_index"=>88],"db_column"=>"spectacles_contact_lenses_hearing_aid"],
+        ["excel_column"=>["col_name"=>"Notes","col_index"=>89],"db_column"=>"notes"],
+        ["excel_column"=>["col_name"=>"Buffer Amount","col_index"=>90],"db_column"=>"buffer_amount"],
+        ["excel_column"=>["col_name"=>"tertiaryamount","col_index"=>91],"db_column"=>"tertiary_amount"],
+        ["excel_column"=>["col_name"=>"insurancename","col_index"=>92],"db_column"=>"insurance_name"],
+        ["excel_column"=>["col_name"=>"Roname","col_index"=>93],"db_column"=>"ro_name"],
+        ["excel_column"=>["col_name"=>"Class Of Accommodation","col_index"=>94],"db_column"=>"class_of_accommodation"],
+        ["excel_column"=>["col_name"=>"claimcreateddatetime","col_index"=>95],"db_column"=>"claim_created_datetime"],
+        ["excel_column"=>["col_name"=>"Insurer Claim ID","col_index"=>96],"db_column"=>"insurer_claim_id"],
+        ["excel_column"=>["col_name"=>"Gipsa","col_index"=>97],"db_column"=>"gipsa"],
+        ["excel_column"=>["col_name"=>"Date Of Joining","col_index"=>98],"db_column"=>"date_of_joining"],
+        ["excel_column"=>["col_name"=>"GIPSAHospital","col_index"=>99],"db_column"=>"gipsa_hospital"],
+        ["excel_column"=>["col_name"=>"Package","col_index"=>100],"db_column"=>"package"],
+        ["excel_column"=>["col_name"=>"Is NIDB","col_index"=>101],"db_column"=>"is_nidb"],
+        ["excel_column"=>["col_name"=>"NIDB Removed Date","col_index"=>102],"db_column"=>"nidb_removed_date"],
+        ["excel_column"=>["col_name"=>"Investigationdate","col_index"=>103],"db_column"=>"investigation_date"],
+        ["excel_column"=>["col_name"=>"Investigation Retrieval Date","col_index"=>104],"db_column"=>"investigation_retrieval_date"],
+        ["excel_column"=>["col_name"=>"Reopeneddate","col_index"=>105],"db_column"=>"reopened_date"],
+        ["excel_column"=>["col_name"=>"Referto Insurer Date","col_index"=>106],"db_column"=>"refer_to_insurer_date"],
+        ["excel_column"=>["col_name"=>"Receiveddatefrom Insurer","col_index"=>107],"db_column"=>"received_date_from_insurer"],
+        ["excel_column"=>["col_name"=>"Rejection Category","col_index"=>108],"db_column"=>"rejection_category"],
+        ["excel_column"=>["col_name"=>"Referto Insurer Reasons","col_index"=>109],"db_column"=>"refer_to_insurer_reasons"],
+        ["excel_column"=>["col_name"=>"Is VIP","col_index"=>110],"db_column"=>"is_vip"],
+        ["excel_column"=>["col_name"=>"Main Claim Status","col_index"=>111],"db_column"=>"main_claim_status"],
+        ["excel_column"=>["col_name"=>"Main Claimtype","col_index"=>112],"db_column"=>"main_claim_type"],
+        ["excel_column"=>["col_name"=>"icd Third Level Code","col_index"=>113],"db_column"=>"icd_third_level_code"],
+        ["excel_column"=>["col_name"=>"Benefit Plan Name","col_index"=>114],"db_column"=>"benefit_plan_name"],
+        ["excel_column"=>["col_name"=>"zone","col_index"=>115],"db_column"=>"zone"],
+        ["excel_column"=>["col_name"=>"Grade","col_index"=>116],"db_column"=>"grade"],
+        ["excel_column"=>["col_name"=>"Last Modified Date","col_index"=>117],"db_column"=>"last_modified_date"],
+        ["excel_column"=>["col_name"=>"Temp MOU","col_index"=>118],"db_column"=>"temp_mou"],
+    ];
+
+    protected $ticketMasterMapping = [
+
+        // Claim / Reference
+        'claim_id'                => 'claim_number',
+
+        // Policy
+        'policy_no'               => 'policy_no',
+
+        // Employee / Member
+        'employee_id'             => 'emp_code',
+        'relationship'            => 'relationship',
+
+        // Claim Dates
+        'admission_date'          => 'doa',
+        'discharge_date'          => 'dod',
+        'claim_received_date'     => 'date_of_intimat',
+        'claim_passed_date'       => 'approved_date',
+        'settled_date'            => 'settled_date',
+
+        'current_claim_status'    => 'tpa_claim_status',
+
+        // Amounts
+        'claim_amount'            => 'claim_amount',
+        'settled_amount'          => 'settled_amount',
+        'disallowed_amount'       => 'denial_reason',
+        'coverage_amount'         => 'si_amt',
+
+        // Hospital
+        'provider_name'           => 'hospital_name',
+        'provider_address'        => 'hospital_address',
+        'provider_state'          => 'hospital_state',
+        'provider_place'          => 'hospital_city',
+        'provider_pincode'        => 'hospital_pin_code',
+
+        // Remarks / Description
+        'diagnosis'               => 'claim_description',
+        'rejection_remarks'       => 'return_remark',
+
+        // Payment
+        'cheque_no'               => 'utr_details',
+        'uhid_no'                 => 'tpa_no',
+
+        'priority'                 => 1,
+        'mode_of_intimation'       => 5,
+        'ticket_type_id'           => 1,
+    ];
+
+    protected $statusMapping = [
+        'Settled' => 11,
+        'Rejected' => 8,
+    ];
+
+    protected $dateColumns = [
+        'intimation_date',
+        'policy_start_date',
+        'policy_commencing_date',
+        'policy_expiry_date',
+        'claim_received_date',
+        'admission_date',
+        'discharge_date',
+        'cheque_date',
+        'claim_passed_date',
+        'settled_date',
+        'ir_date',
+        'ir_retrieval_date',
+        'first_reminder',
+        'second_reminder',
+        'date_of_joining',
+        'nidb_removed_date',
+        'investigation_date',
+        'investigation_retrieval_date',
+        'reopened_date',
+        'refer_to_insurer_date',
+        'received_date_from_insurer',
+        'claim_created_datetime',
+        'last_modified_date'
+    ];
+
+
+    /**
+     * ABSTRACT FUNCTIONs 
+     */
+    public function bulkInsertTPATable(array $data): bool
+    {
+        if (empty($data)) {
+            return false;
+        }
+
+        $ClaimsDumpFhplModel = new ClaimsDumpFhplModel();
+        $result = $ClaimsDumpFhplModel->insertBatch($data);
+
+        return true;
+
+    }
+
+
+    public function importClaimMaster(array $data): bool
+    {
+        if (empty($data)) {
+            return false;
+        }
+        
+        $ticketMasterModel = new TicketMasterModel();
+        $ticketMasterModel->insertBatch($data);
+
+        return true;
+    }
+
+
+    public function updateTicketIdInTPATable(): bool
+    {
+        if (empty($data)) {
+            return false;
+        }
+        
+        $builder = $this->db->table('claims_dump_fhpl');
+        $builder->insertBatch($data);
+
+        return true;
+    }
+
+
+    public function updateTicketMasterRejectedReasonInTPATable($data): bool
+    {   
+        if (empty($data)) {
+            return false;
+        }
+        
+        $builder = $this->db->table('claims_dump_fhpl');
+        $builder->insertBatch($data);
+
+        return true;
+    }
+
+
+    /**
+     * MAPPING FUNCTIONs 
+     */
+
+    public function mapTPAData(array $rows, $file_id): array
+    {   
+        $ClientPolicyModel = new ClaimDumpFileModel();
+        $file_data = $ClientPolicyModel->where('id', $file_id)->first();
+
+        $mapped = [];
+
+        foreach ($rows as $row) {
+
+            $item = [];
+
+            foreach ($this->mapping as $map) {
+                $excelColumn = $map['excel_column']['col_name'];
+                $dbColumn    = $map['db_column'];
+
+                $value = $row[$excelColumn] ?? null;
+                $item[$dbColumn] = trim($value);
+            }
+
+            foreach ($this->dateColumns as $key => $value) {
+                $item[$value] = change_date_format($item[$value] ?? null, 'd-M-y', 'Y-m-d');
+            }
+
+            $params = [
+                'admission_date' => $item['admission_date'] ?? null,
+                'employee_id' => $item['employee_id'] ?? null,
+                'claim_amount' => $item['claim_amount'] ?? null,
+                'uhid_no' => $item['uhid_no'] ?? null
+            ];
+
+            $is_duplicate = $this->checkDuplicateTpaClaim('claims_dump_fhpl', $params);
+
+            if ($is_duplicate) {
+                $item = [];
+                continue;
+            }
+
+            $item['file_id'] = $file_id ?? null;
+            $item['client_id'] = $file_data['client_id'] ?? null;
+            $item['client_policy_id'] = $file_data['client_policy_id'] ?? null;
+            $item['created_by'] = $file_data['created_by'] ?? null;
+
+            $mapped[] = $item;
+        }
+
+        return $mapped;
+    }
+
+    public function mapClaimMasterData($file_id): array
+    {
+
+        $ClientPolicyModel = new ClaimDumpFileModel();
+        $file_data = $ClientPolicyModel->where('id', $file_id)->first();
+
+        $tpaClaimDumpData = $this->getTpaClaimDumpData('claims_dump_fhpl', ['file_id' => $file_id]);
+
+        if (empty($tpaClaimDumpData)) {
+            return ['status' => false, 'message' => "No data to insert in TICKET MASTER"];
+        }
+
+
+        $ClientPolicyModel = new ClientPolicyModel();
+        $client_policy_data = $ClientPolicyModel
+            ->select("
+                client_policy.*,
+                (
+                    SELECT id
+                    FROM client_rm
+                    WHERE is_active = 1
+                    AND level = 3
+                    AND client_id = client_policy.client_id
+                    ORDER BY id ASC
+                    LIMIT 1
+                ) AS acm_id
+            ")
+            ->where('client_policy.id', $file_data['client_policy_id'])
+            ->where('client_policy.is_active', 1)
+            ->first();
+
+        try {
+
+            $mapped = [];
+            $rejecetd_reason = [];
+
+            foreach ($tpaClaimDumpData as $row) {
+
+                $params = [
+                    'doa' => change_date_format($row['admission_date'] ?? '') ?? null,
+                    'emp_code' => $row['employee_id'] ?? null,
+                    'claim_amount' => $row['claim_amount'] ?? null,
+                    'tpa_no' => $row['uhid_no'] ?? null
+                ];
+
+                $isduplicate = $this->checkDublicateTicketMasterClaim($params);
+
+                if ($isduplicate) {
+                    $reason = "This claim already exists in our system.";
+                    $rejecetd_reason[$row['id']] = ["ticket_master_insert_reject_reason" => $reason];
+                    continue;
+                }
+
+                $item = [];
+
+                $item['client_id']    = $client_policy_data['client_id'] ?? null;
+                $item['client_policy_id'] = $client_policy_data['id'] ?? null;
+                $item['insurer_id']  = $client_policy_data['insurer_id'] ?? null;
+                $item['tpa_id']  = $client_policy_data['tpa_id'] ?? null;
+                $item['acm_id']  = $client_policy_data['acm_id'] ?? null;
+                $item['policy_no']  = $client_policy_data['policy_no'] ?? null;
+                $item['relationship']  = $this->convertRelation($row['relationship'] ?? null);
+
+                $employee_data = $this->getEmployeeDetails($file_data['client_id'], $file_data['client_policy_id'], $row['employee_id'], $item['relationship']);
+
+                if (!empty($employee_data)) {
+                    $item['emp_id']    = $employee_data['id'] ?? null;
+                    $item['emp_name'] = $employee_data['name'] ?? null;
+                    $item['emp_mail']  = $employee_data['email_corporate'] ?? null;
+                    $item['emp_mobile']  = $employee_data['mobile'] ?? null;
+                    $item['insured_emp_id']  = $employee_data['insured_emp_id'] ?? null;
+                    $item['insured_name']  = $employee_data['insured_name'] ?? null;
+                } else {
+
+                    $reason = sprintf(
+                        'The policy number "%s" does not exist in our system. ' .
+                            'Details - Client ID: %s, Client Policy ID: %s, Employee Number: %s, Relationship: %s',
+                        $row['insurer_policy_number'],
+                        $file_data['client_id'],
+                        $file_data['client_policy_id'],
+                        $row['employee_number'],
+                        $item['relationship']
+                    );
+
+                    $rejecetd_reason[$row['id']] = ["ticket_master_insert_reject_reason" => $reason];
+                    continue;
+                }
+
+                foreach ($this->ticketMasterMapping as $tpaKey => $ticketMasterKey) {
+                    $item[$ticketMasterKey] = array_key_exists($tpaKey, $row) ? $row[$tpaKey] : null;
+                }
+
+                // Meta fields
+                $item['claim_status_id'] = $statusMapping[$row['current_claim_status']] ?? 61;
+                $item['file_id']    = $file_id;
+                $item['claim_dump_ref_id']    = $row['id'];
+                $item['created_by'] = $file_data['created_by'] ?? null;
+                $item['claim_type'] = 1;
+                $item['priority']           = 1;
+                $item['mode_of_intimation'] = 5;
+                $item['ticket_type_id']     = 1;
+
+                $mapped[] = $item;
+            }
+
+            return ['status' => true, 'mapped_array' => $mapped, 'rejected_reason_array' => $rejecetd_reason];
+            
+        } catch (\Throwable $th) {
+
+            $errorData = [
+                'message' => $th->getMessage(),
+                'file'    => $th->getFile(),
+                'line'    => $th->getLine(),
+                'code'    => $th->getCode(),
+                'trace'   => $th->getTraceAsString(),
+                'trace_array' => $th->getTrace(), // full array version (optional)
+                'function' => $th->getTrace()[0]['function'] ?? null,
+                'class' => $th->getTrace()[0]['class'] ?? null,
+            ];
+
+            return ['status' => false, "message" => $errorData['message'], 'error_data' => $errorData];
+        }
+    }
+
+
+    /**
+     * HELPER FUNCTIONs 
+     */
+
+    public function convertRelation(?string $relation): ?string
+    {
+        if (empty($relation)) {
+            return null;
+        }
+
+        $relation = strtolower($relation);
+
+        if (str_contains($relation, 'self')) {
+            return 'self';
+        }
+
+        if (str_contains($relation, 'spouse') || str_contains($relation, 'wife') || str_contains($relation, 'husband')) {
+            return 'spouse';
+        }
+
+        if (str_contains($relation, 'daughter')) {
+            return 'daughter';
+        }
+
+        if (str_contains($relation, 'son')) {
+            return 'son';
+        }
+
+        if (str_contains($relation, 'father in law') || str_contains($relation, 'father-in-law')) {
+            return 'father-in-law';
+        }
+
+        if (str_contains($relation, 'mother in law') || str_contains($relation, 'mother-in-law')) {
+            return 'mother-in-law';
+        }
+
+        if (str_contains($relation, 'father')) {
+            return 'father';
+        }
+
+        if (str_contains($relation, 'mother')) {
+            return 'mother';
+        }
+
+        return null; // unmatched case
+    }
+
+
+
+}
diff --git a/app/Libraries/TPAClaimsImportServices/IciciClaimImportService.php b/app/Libraries/TPAClaimsImportServices/IciciClaimImportService.php
new file mode 100644
index 00000000..b89221ae
--- /dev/null
+++ b/app/Libraries/TPAClaimsImportServices/IciciClaimImportService.php
@@ -0,0 +1,430 @@
+ ["col_name" => "POLICY_NAME", "col_index" => 0], "db_column" => "policy_name"],
+        ["excel_column" => ["col_name" => "POLICY_NO", "col_index" => 1], "db_column" => "policy_no"],
+        ["excel_column" => ["col_name" => "UHID", "col_index" => 2], "db_column" => "uhid"],
+        ["excel_column" => ["col_name" => "INSURED_NAME", "col_index" => 3], "db_column" => "insured_name"],
+        ["excel_column" => ["col_name" => "MAIN_MEMBER_NAME", "col_index" => 4], "db_column" => "main_member_name"],
+        ["excel_column" => ["col_name" => "EMPLOYEE_MEMBER_ID", "col_index" => 5], "db_column" => "employee_member_id"],
+        ["excel_column" => ["col_name" => "GRADE", "col_index" => 6], "db_column" => "grade"],
+        ["excel_column" => ["col_name" => "RELATION", "col_index" => 7], "db_column" => "relation"],
+        ["excel_column" => ["col_name" => "AGE", "col_index" => 8], "db_column" => "age"],
+        ["excel_column" => ["col_name" => "GENDER", "col_index" => 9], "db_column" => "gender"],
+        ["excel_column" => ["col_name" => "DIAGNOSIS", "col_index" => 10], "db_column" => "diagnosis"],
+        ["excel_column" => ["col_name" => "CLAIMED_AMOUNT", "col_index" => 11], "db_column" => "claimed_amount"],
+        ["excel_column" => ["col_name" => "NET_SANCT_AMT", "col_index" => 12], "db_column" => "net_sanct_amt"],
+        ["excel_column" => ["col_name" => "COPAYMENT_AMT", "col_index" => 13], "db_column" => "copayment_amt"],
+        ["excel_column" => ["col_name" => "DISALLOWED_AMOUNT", "col_index" => 14], "db_column" => "disallowed_amount"],
+        ["excel_column" => ["col_name" => "REASON_FOR_DISALLOWANCE", "col_index" => 15], "db_column" => "reason_for_disallowance"],
+        ["excel_column" => ["col_name" => "PAYMENT_AMOUNT", "col_index" => 16], "db_column" => "payment_amount"],
+        ["excel_column" => ["col_name" => "SUM_INSURED", "col_index" => 17], "db_column" => "sum_insured"],
+        ["excel_column" => ["col_name" => "BAL_SUM_INSURED", "col_index" => 18], "db_column" => "bal_sum_insured"],
+        ["excel_column" => ["col_name" => "TYPE_OF_CLAIM", "col_index" => 19], "db_column" => "type_of_claim"],
+        ["excel_column" => ["col_name" => "Claim_r_Os_Amt", "col_index" => 20], "db_column" => "claim_r_os_amt"],
+        ["excel_column" => ["col_name" => "Updated_status", "col_index" => 21], "db_column" => "updated_status"],
+        ["excel_column" => ["col_name" => "Disease_Category", "col_index" => 22], "db_column" => "disease_category"],
+        ["excel_column" => ["col_name" => "POLICY_START_DATE", "col_index" => 23], "db_column" => "policy_start_date"],
+        ["excel_column" => ["col_name" => "POLICY_END_DATE", "col_index" => 24], "db_column" => "policy_end_date"],
+        ["excel_column" => ["col_name" => "CLAIM_NUMBER", "col_index" => 25], "db_column" => "claim_number"],
+        ["excel_column" => ["col_name" => "AL_NO", "col_index" => 26], "db_column" => "al_no"],
+        ["excel_column" => ["col_name" => "HOSPITAL_CODE", "col_index" => 27], "db_column" => "hospital_code"],
+        ["excel_column" => ["col_name" => "HOSPITAL_ID", "col_index" => 28], "db_column" => "hospital_id"],
+        ["excel_column" => ["col_name" => "HOSPITAL_NAME", "col_index" => 29], "db_column" => "hospital_name"],
+        ["excel_column" => ["col_name" => "TREATMENT_TAKEN", "col_index" => 30], "db_column" => "treatment_taken"],
+        ["excel_column" => ["col_name" => "CF_Utilised_Amounnt", "col_index" => 31], "db_column" => "cf_utilised_amount"],
+        ["excel_column" => ["col_name" => "DT_OF_DEFICIENCIES_SENT", "col_index" => 32], "db_column" => "dt_of_deficiencies_sent"],
+        ["excel_column" => ["col_name" => "DT_OF_DEFICIENCIES_RECIEVED", "col_index" => 33], "db_column" => "dt_of_deficiencies_received"],
+        ["excel_column" => ["col_name" => "PAYMENT_DATE", "col_index" => 34], "db_column" => "payment_date"],
+        ["excel_column" => ["col_name" => "PAYEE_NAME", "col_index" => 35], "db_column" => "payee_name"],
+        ["excel_column" => ["col_name" => "PAYMENT_MODE", "col_index" => 36], "db_column" => "payment_mode"],
+        ["excel_column" => ["col_name" => "CHEQUE_NUMBER", "col_index" => 37], "db_column" => "cheque_number"],
+        ["excel_column" => ["col_name" => "DOA", "col_index" => 38], "db_column" => "doa"],
+        ["excel_column" => ["col_name" => "DOD", "col_index" => 39], "db_column" => "dod"],
+        ["excel_column" => ["col_name" => "HOSPITAL_CITY", "col_index" => 40], "db_column" => "hospital_city"],
+        ["excel_column" => ["col_name" => "HOSPITAL_STATE", "col_index" => 41], "db_column" => "hospital_state"],
+        ["excel_column" => ["col_name" => "REJECTED_QUERY_REASON", "col_index" => 42], "db_column" => "rejected_query_reason"],
+        ["excel_column" => ["col_name" => "REJECTED_QUERY_DESC", "col_index" => 43], "db_column" => "rejected_query_desc"],
+        ["excel_column" => ["col_name" => "REJECTED_QUERY_CLOSED_DATE", "col_index" => 44], "db_column" => "rejected_query_closed_date"],
+        ["excel_column" => ["col_name" => "REJREOPEN_CLOSURE_DATE", "col_index" => 45], "db_column" => "rejreopen_closure_date"],
+        ["excel_column" => ["col_name" => "CLAIM_CLASSIFICATION", "col_index" => 46], "db_column" => "claim_classification"],
+        ["excel_column" => ["col_name" => "TAGGED_INWARD_NO", "col_index" => 47], "db_column" => "tagged_inward_no"],
+        ["excel_column" => ["col_name" => "INWARD_DATE", "col_index" => 48], "db_column" => "inward_date"],
+        ["excel_column" => ["col_name" => "ICD_ID_L3", "col_index" => 49], "db_column" => "icd_id_l3"],
+        ["excel_column" => ["col_name" => "Incidence_Count", "col_index" => 50], "db_column" => "incidence_count"],
+        ["excel_column" => ["col_name" => "FLEXI_OPTION", "col_index" => 51], "db_column" => "flexi_option"],
+        ["excel_column" => ["col_name" => "Base_TopUp_Option", "col_index" => 52], "db_column" => "base_topup_option"],
+        ["excel_column" => ["col_name" => "POLICY_GROUP_NAME", "col_index" => 53], "db_column" => "policy_group_name"],
+        ["excel_column" => ["col_name" => "Relation_Group", "col_index" => 54], "db_column" => "relation_group"],
+        ["excel_column" => ["col_name" => "Age_Band", "col_index" => 55], "db_column" => "age_band"],
+        ["excel_column" => ["col_name" => "Work_Location", "col_index" => 56], "db_column" => "work_location"],
+        ["excel_column" => ["col_name" => "ILTC_TAG", "col_index" => 57], "db_column" => "iltc_tag"],
+    ];
+
+    protected $ticketMasterMapping = [
+
+        // Employee / Member
+        'employee_member_id' => 'emp_code',
+        'relation_group'     => 'relationship',
+
+        // Claim
+        'claim_number'      => 'claim_number',
+        'claimed_amount'    => 'claim_amount',
+        'claim_status'      => 'tpa_claim_status',
+
+        // Dates
+        'doa'  => 'doa',
+        'dod'  => 'dod',
+        'payment_date'       => 'settled_date',
+
+        // Hospital
+        'hospital_name'      => 'hospital_name',
+        'hospital_city'      => 'hospital_city',
+        'hospital_state'     => 'hospital_state',
+
+        'cheque_number'      => 'utr_details',
+        'uhid'               => 'tpa_no',
+        'rejected_query_desc'  => 'claim_description',
+    ];
+
+    protected $statusMapping = [
+        'PAID' => 11,
+        'REJECTED' => 8,
+    ];
+
+    protected $dateColumns = [
+        'policy_start_date',
+        'policy_end_date',
+
+        'dt_of_deficiencies_sent',
+        'dt_of_deficiencies_received',
+
+        'payment_date',
+
+        'doa',
+        'dod',
+
+        'rejected_query_closed_date',
+        'rejreopen_closure_date',
+    ];
+
+
+
+    /**
+     * ABSTRACT FUNCTIONs 
+     */
+    public function bulkInsertTPATable(array $data): bool
+    {
+        if (empty($data)) {
+            return false;
+        }
+
+        try {
+
+
+            $ClaimsDumpFhplModel = new ClaimsDumpFhplModel();
+            $result = $ClaimsDumpFhplModel->insertBatch($data);
+
+            return true;
+
+        } catch (\Throwable $th) {
+
+            $errorData = [
+                'message' => $th->getMessage(),
+                'file'    => $th->getFile(),
+                'line'    => $th->getLine(),
+                'code'    => $th->getCode(),
+                'trace'   => $th->getTraceAsString(),
+                'trace_array' => $th->getTrace(), // full array version (optional)
+                'function' => $th->getTrace()[0]['function'] ?? null,
+                'class' => $th->getTrace()[0]['class'] ?? null,
+            ];
+            return false;
+        }
+
+    }
+
+
+    public function importClaimMaster(array $data): bool
+    {
+        if (empty($data)) {
+            return false;
+        }
+        
+        $ticketMasterModel = new TicketMasterModel();
+        $ticketMasterModel->insertBatch($data);
+
+        return true;
+    }
+
+
+    public function updateTicketIdInTPATable(): bool
+    {
+        if (empty($data)) {
+            return false;
+        }
+        
+        $builder = $this->db->table('claims_dump_icici');
+        $builder->insertBatch($data);
+
+        return true;
+    }
+
+
+    public function updateTicketMasterRejectedReasonInTPATable($data): bool
+    {   
+        if (empty($data)) {
+            return false;
+        }
+        
+        $builder = $this->db->table('claims_dump_icici');
+        $builder->insertBatch($data);
+
+        return true;
+    }
+
+
+    /**
+     * MAPPING FUNCTIONs 
+     */
+
+    public function mapTPAData(array $rows, $file_id): array
+    {   
+        $ClientPolicyModel = new ClaimDumpFileModel();
+        $file_data = $ClientPolicyModel->where('id', $file_id)->first();
+
+        $mapped = [];
+
+        foreach ($rows as $row) {
+
+            $item = [];
+
+            foreach ($this->mapping as $map) {
+                $excelColumn = $map['excel_column']['col_name'];
+                $dbColumn    = $map['db_column'];
+
+                $value = $row[$excelColumn] ?? null;
+                $item[$dbColumn] = $value;
+            }
+
+            foreach ($this->dateColumns as $key => $value) {
+                $item[$value] = change_date_format($item[$value] ?? null);
+            }
+
+            $params = [
+                'doa' => change_date_format($item['doa'] ?? '') ?? null,
+                'employee_member_id' => $item['employee_member_id'] ?? null,
+                'claimed_amount' => $item['claimed_amount'] ?? null,
+                'uhid' => $item['uhid'] ?? null
+            ];
+
+            $is_duplicate = $this->checkDuplicateTpaClaim('claims_dump_icici', $params);
+
+            if ($is_duplicate) {
+                $item = [];
+                continue;
+            }
+
+            $item['file_id'] = $file_id ?? null;
+            $item['client_id'] = $file_data['client_id'] ?? null;
+            $item['client_policy_id'] = $file_data['client_policy_id'] ?? null;
+            $item['created_by'] = $file_data['created_by'] ?? null;
+
+            $mapped[] = $item;
+        }
+
+        return $mapped;
+    }
+
+    public function mapClaimMasterData($file_id): array
+    {
+
+        $ClientPolicyModel = new ClaimDumpFileModel();
+        $file_data = $ClientPolicyModel->where('id', $file_id)->first();
+
+        $tpaClaimDumpData = $this->getTpaClaimDumpData('claims_dump_icici', ['file_id' => $file_id]);
+
+        if (empty($tpaClaimDumpData)) {
+            return ['status' => false, 'message' => "No data to insert in TICKET MASTER"];
+        }
+
+
+        $ClientPolicyModel = new ClientPolicyModel();
+        $client_policy_data = $ClientPolicyModel
+            ->select("
+                client_policy.*,
+                (
+                    SELECT id
+                    FROM client_rm
+                    WHERE is_active = 1
+                    AND level = 3
+                    AND client_id = client_policy.client_id
+                    ORDER BY id ASC
+                    LIMIT 1
+                ) AS acm_id
+            ")
+            ->where('client_policy.id', $file_data['client_policy_id'])
+            ->where('client_policy.is_active', 1)
+            ->first();
+
+        try {
+
+            $mapped = [];
+            $rejecetd_reason = [];
+
+            foreach ($tpaClaimDumpData as $row) {
+
+                $params = [
+                    'doa' => change_date_format($row['doa'] ?? '') ?? null,
+                    'emp_code' => $row['employee_member_id'] ?? null,
+                    'claim_amount' => $row['claim_amount'] ?? null,
+                    'tpa_no' => $row['uhid'] ?? null
+                ];
+
+                $isduplicate = $this->checkDublicateTicketMasterClaim($params);
+
+                if ($isduplicate) {
+                    $reason = "This claim already exists in our system.";
+                    $rejecetd_reason[$row['id']] = ["ticket_master_insert_reject_reason" => $reason];
+                    continue;
+                }
+
+                $item = [];
+
+                $item['client_id']    = $client_policy_data['client_id'] ?? null;
+                $item['client_policy_id'] = $client_policy_data['id'] ?? null;
+                $item['insurer_id']  = $client_policy_data['insurer_id'] ?? null;
+                $item['tpa_id']  = $client_policy_data['tpa_id'] ?? null;
+                $item['acm_id']  = $client_policy_data['acm_id'] ?? null;
+                $item['policy_no']  = $client_policy_data['policy_no'] ?? null;
+                $item['relationship']  = $this->convertRelation($row['relation_group'] ?? '');
+
+                $employee_data = $this->getEmployeeDetails($file_data['client_id'], $file_data['client_policy_id'], $row['employee_member_id'], $item['relationship']);
+
+                if (!empty($employee_data)) {
+                    $item['emp_id']    = $employee_data['id'] ?? null;
+                    $item['emp_name'] = $employee_data['name'] ?? null;
+                    $item['emp_mail']  = $employee_data['email_corporate'] ?? null;
+                    $item['emp_mobile']  = $employee_data['mobile'] ?? null;
+                    $item['insured_emp_id']  = $employee_data['insured_emp_id'] ?? null;
+                    $item['insured_name']  = $employee_data['insured_name'] ?? null;
+                } else {
+
+                    $reason = sprintf(
+                        'The policy number "%s" does not exist in our system. ' .
+                            'Details - Client ID: %s, Client Policy ID: %s, Employee Number: %s, Relationship: %s',
+                        $row['insurer_policy_number'],
+                        $file_data['client_id'],
+                        $file_data['client_policy_id'],
+                        $row['employee_number'],
+                        $item['relationship']
+                    );
+
+                    $rejecetd_reason[$row['id']] = ["ticket_master_insert_reject_reason" => $reason];
+                    continue;
+                }
+
+                foreach ($this->ticketMasterMapping as $tpaKey => $ticketMasterKey) {
+                    $item[$ticketMasterKey] = array_key_exists($tpaKey, $row) ? $row[$tpaKey] : null;
+                }
+
+                // Meta fields
+                $item['claim_status_id'] = $statusMapping[$row['updated_status']] ?? 61;
+                $item['claim_dump_ref_id']    = $row['id'];
+                $item['file_id']    = $file_id;
+                $item['created_by'] = $file_data['created_by'] ?? null;
+                $item['claim_type'] = 1;
+                $item['priority']           = 1;
+                $item['mode_of_intimation'] = 5;
+                $item['ticket_type_id']     = 1;
+
+                $mapped[] = $item;
+            }
+
+            return ['status' => true, 'mapped_array' => $mapped, 'rejected_reason_array' => $rejecetd_reason];
+            
+        } catch (\Throwable $th) {
+
+            $errorData = [
+                'message' => $th->getMessage(),
+                'file'    => $th->getFile(),
+                'line'    => $th->getLine(),
+                'code'    => $th->getCode(),
+                'trace'   => $th->getTraceAsString(),
+                'trace_array' => $th->getTrace(), // full array version (optional)
+                'function' => $th->getTrace()[0]['function'] ?? null,
+                'class' => $th->getTrace()[0]['class'] ?? null,
+            ];
+
+            return ['status' => false, "message" => $errorData['message'], 'error_data' => $errorData];
+        }
+    }
+
+
+    /**
+     * HELPER FUNCTIONs 
+     */
+
+
+    public function convertRelation(?string $relation): ?string
+    {
+        if (empty($relation)) {
+            return null;
+        }
+
+        $relation = strtolower($relation);
+
+        if (str_contains($relation, 'self')) {
+            return 'self';
+        }
+
+        if (str_contains($relation, 'spouse') || str_contains($relation, 'wife') || str_contains($relation, 'husband')) {
+            return 'spouse';
+        }
+
+        if (str_contains($relation, 'daughter')) {
+            return 'daughter';
+        }
+
+        if (str_contains($relation, 'son')) {
+            return 'son';
+        }
+
+        if (str_contains($relation, 'father in law') || str_contains($relation, 'father-in-law')) {
+            return 'father-in-law';
+        }
+
+        if (str_contains($relation, 'mother in law') || str_contains($relation, 'mother-in-law')) {
+            return 'mother-in-law';
+        }
+
+        if (str_contains($relation, 'father')) {
+            return 'father';
+        }
+
+        if (str_contains($relation, 'mother')) {
+            return 'mother';
+        }
+
+        return null; // unmatched case
+    }
+
+
+
+}
diff --git a/app/Libraries/TPAClaimsImportServices/MediAssistClaimImportService.php b/app/Libraries/TPAClaimsImportServices/MediAssistClaimImportService.php
new file mode 100644
index 00000000..7326567d
--- /dev/null
+++ b/app/Libraries/TPAClaimsImportServices/MediAssistClaimImportService.php
@@ -0,0 +1,446 @@
+ ["col_name" => "insurance_company", "col_index" => 0], "db_column" => "insurance_company"],
+        ["excel_column" => ["col_name" => "insurer_region_name", "col_index" => 1], "db_column" => "insurer_region_name"],
+        ["excel_column" => ["col_name" => "insurer_ro_code", "col_index" => 2], "db_column" => "insurer_ro_code"],
+        ["excel_column" => ["col_name" => "insurer_do_code", "col_index" => 3], "db_column" => "insurer_do_code"],
+        ["excel_column" => ["col_name" => "insurer_bo_code", "col_index" => 4], "db_column" => "insurer_bo_code"],
+        ["excel_column" => ["col_name" => "event_id", "col_index" => 5], "db_column" => "event_id"],
+        ["excel_column" => ["col_name" => "claim_id", "col_index" => 6], "db_column" => "claim_id"],
+        ["excel_column" => ["col_name" => "insurer_claim_ref_no", "col_index" => 7], "db_column" => "insurer_claim_ref_no"],
+        ["excel_column" => ["col_name" => "claim_pre_auths", "col_index" => 8], "db_column" => "claim_pre_auths"],
+        ["excel_column" => ["col_name" => "ma_policy_id", "col_index" => 9], "db_column" => "ma_policy_id"],
+        ["excel_column" => ["col_name" => "policy_no", "col_index" => 10], "db_column" => "policy_no"],
+        ["excel_column" => ["col_name" => "policy_holder_name", "col_index" => 11], "db_column" => "policy_holder_name"],
+        ["excel_column" => ["col_name" => "policy_type", "col_index" => 12], "db_column" => "policy_type"],
+        ["excel_column" => ["col_name" => "policy_subtype_desc", "col_index" => 13], "db_column" => "policy_subtype_desc"],
+        ["excel_column" => ["col_name" => "policy_start_date", "col_index" => 14], "db_column" => "policy_start_date"],
+        ["excel_column" => ["col_name" => "policy_end_date", "col_index" => 15], "db_column" => "policy_end_date"],
+        ["excel_column" => ["col_name" => "devlopment_officer", "col_index" => 16], "db_column" => "devlopment_officer"],
+        ["excel_column" => ["col_name" => "agent", "col_index" => 17], "db_column" => "agent"],
+        ["excel_column" => ["col_name" => "broker", "col_index" => 18], "db_column" => "broker"],
+        ["excel_column" => ["col_name" => "pribenef_employee_code", "col_index" => 19], "db_column" => "pribenef_employee_code"],
+        ["excel_column" => ["col_name" => "pribenef_name", "col_index" => 20], "db_column" => "pribenef_name"],
+        ["excel_column" => ["col_name" => "pribenef_floater_sum", "col_index" => 21], "db_column" => "pribenef_floater_sum"],
+        ["excel_column" => ["col_name" => "benef_maid", "col_index" => 22], "db_column" => "benef_maid"],
+        ["excel_column" => ["col_name" => "benef_insurer_id", "col_index" => 23], "db_column" => "benef_insurer_id"],
+        ["excel_column" => ["col_name" => "benef_name", "col_index" => 24], "db_column" => "benef_name"],
+        ["excel_column" => ["col_name" => "benef_gender", "col_index" => 25], "db_column" => "benef_gender"],
+        ["excel_column" => ["col_name" => "benef_relation", "col_index" => 26], "db_column" => "benef_relation"],
+        ["excel_column" => ["col_name" => "benef_age", "col_index" => 27], "db_column" => "benef_age"],
+        ["excel_column" => ["col_name" => "benef_sum_insured", "col_index" => 28], "db_column" => "benef_sum_insured"],
+        ["excel_column" => ["col_name" => "balance_sum_insured", "col_index" => 29], "db_column" => "balance_sum_insured"],
+        ["excel_column" => ["col_name" => "intimation_id", "col_index" => 30], "db_column" => "intimation_id"],
+        ["excel_column" => ["col_name" => "intimation_date", "col_index" => 31], "db_column" => "intimation_date"],
+        ["excel_column" => ["col_name" => "settled_date", "col_index" => 32], "db_column" => "settled_date"],
+        ["excel_column" => ["col_name" => "ClaimSource", "col_index" => 33], "db_column" => "claim_source"],
+        ["excel_column" => ["col_name" => "claim_mode_of_rcpt", "col_index" => 34], "db_column" => "claim_mode_of_rcpt"],
+        ["excel_column" => ["col_name" => "claim_type", "col_index" => 35], "db_column" => "claim_type"],
+        ["excel_column" => ["col_name" => "claim_sub_type", "col_index" => 36], "db_column" => "claim_sub_type"],
+        ["excel_column" => ["col_name" => "claim_stage", "col_index" => 37], "db_column" => "claim_stage"],
+        ["excel_column" => ["col_name" => "claim_status", "col_index" => 38], "db_column" => "claim_status"],
+        ["excel_column" => ["col_name" => "is_cashlessanywhere", "col_index" => 39], "db_column" => "is_cashlessanywhere"],
+        ["excel_column" => ["col_name" => "date_of_admission", "col_index" => 40], "db_column" => "date_of_admission"],
+        ["excel_column" => ["col_name" => "date_of_discharge", "col_index" => 41], "db_column" => "date_of_discharge"],
+        ["excel_column" => ["col_name" => "claim_amount", "col_index" => 42], "db_column" => "claim_amount"],
+        ["excel_column" => ["col_name" => "claim_approved_amount", "col_index" => 43], "db_column" => "claim_approved_amount"],
+        ["excel_column" => ["col_name" => "incurred_amount", "col_index" => 44], "db_column" => "incurred_amount"],
+        ["excel_column" => ["col_name" => "primary_icd_group", "col_index" => 45], "db_column" => "primary_icd_group"],
+        ["excel_column" => ["col_name" => "primary_ailment_name", "col_index" => 46], "db_column" => "primary_ailment_name"],
+        ["excel_column" => ["col_name" => "primary_ailment_code", "col_index" => 47], "db_column" => "primary_ailment_code"],
+        ["excel_column" => ["col_name" => "treatment_type", "col_index" => 48], "db_column" => "treatment_type"],
+        ["excel_column" => ["col_name" => "treatment_name", "col_index" => 49], "db_column" => "treatment_name"],
+        ["excel_column" => ["col_name" => "hospital_id", "col_index" => 50], "db_column" => "hospital_id"],
+        ["excel_column" => ["col_name" => "hospital_name", "col_index" => 51], "db_column" => "hospital_name"],
+        ["excel_column" => ["col_name" => "hospital_city", "col_index" => 52], "db_column" => "hospital_city"],
+        ["excel_column" => ["col_name" => "hospital_state", "col_index" => 53], "db_column" => "hospital_state"],
+        ["excel_column" => ["col_name" => "hospital_pincode", "col_index" => 54], "db_column" => "hospital_pincode"],
+        ["excel_column" => ["col_name" => "hospital_address", "col_index" => 55], "db_column" => "hospital_address"],
+        ["excel_column" => ["col_name" => "Clinic_DoctorName_Hospital", "col_index" => 56], "db_column" => "clinic_doctorname_hospital"],
+        ["excel_column" => ["col_name" => "OPD_pincode", "col_index" => 57], "db_column" => "opd_pincode"],
+        ["excel_column" => ["col_name" => "payable_amount_OPD_Consultation", "col_index" => 58], "db_column" => "payable_amount_opd_consultation"],
+        ["excel_column" => ["col_name" => "payable_amount_Dental", "col_index" => 59], "db_column" => "payable_amount_dental"],
+        ["excel_column" => ["col_name" => "payable_amount_Diagnostics", "col_index" => 60], "db_column" => "payable_amount_diagnostics"],
+        ["excel_column" => ["col_name" => "payable_amount_Other", "col_index" => 61], "db_column" => "payable_amount_other"],
+        ["excel_column" => ["col_name" => "payable_amount_Pharmacy", "col_index" => 62], "db_column" => "payable_amount_pharmacy"],
+        ["excel_column" => ["col_name" => "payable_amount_Vaccination", "col_index" => 63], "db_column" => "payable_amount_vaccination"],
+        ["excel_column" => ["col_name" => "payable_amount_Miscellaneous_Charges", "col_index" => 64], "db_column" => "payable_amount_miscellaneous_charges"],
+        ["excel_column" => ["col_name" => "payable_amount_Health_Checkup", "col_index" => 65], "db_column" => "payable_amount_health_checkup"],
+        ["excel_column" => ["col_name" => "deduction_amount_copay", "col_index" => 66], "db_column" => "deduction_amount_copay"],
+        ["excel_column" => ["col_name" => "deduction_amount_excess_ailment", "col_index" => 67], "db_column" => "deduction_amount_excess_ailment"],
+        ["excel_column" => ["col_name" => "deduction_amount_excess_policy", "col_index" => 68], "db_column" => "deduction_amount_excess_policy"],
+        ["excel_column" => ["col_name" => "deduction_amount_prorata", "col_index" => 69], "db_column" => "deduction_amount_prorata"],
+        ["excel_column" => ["col_name" => "deduction_amount_hospital_discount", "col_index" => 70], "db_column" => "deduction_amount_hospital_discount"],
+        ["excel_column" => ["col_name" => "deduction_amount_paid_by_patient", "col_index" => 71], "db_column" => "deduction_amount_paid_by_patient"],
+        ["excel_column" => ["col_name" => "deduction_amount_issurer_approved", "col_index" => 72], "db_column" => "deduction_amount_issurer_approved"],
+        ["excel_column" => ["col_name" => "deduction_amount_deductible", "col_index" => 73], "db_column" => "deduction_amount_deductible"],
+        ["excel_column" => ["col_name" => "deduction_amount_intimation_penalty", "col_index" => 74], "db_column" => "deduction_amount_intimation_penalty"],
+        ["excel_column" => ["col_name" => "claim_payable_to_name", "col_index" => 75], "db_column" => "claim_payable_to_name"],
+        ["excel_column" => ["col_name" => "utr_no", "col_index" => 76], "db_column" => "utr_no"],
+        ["excel_column" => ["col_name" => "utr_date", "col_index" => 77], "db_column" => "utr_date"],
+        ["excel_column" => ["col_name" => "denial_short_description", "col_index" => 78], "db_column" => "denial_short_description"],
+        ["excel_column" => ["col_name" => "claim_received_date", "col_index" => 79], "db_column" => "claim_received_date"],
+        ["excel_column" => ["col_name" => "last_necessary_doc_rec_date", "col_index" => 80], "db_column" => "last_necessary_doc_rec_date"],
+        ["excel_column" => ["col_name" => "processed_date", "col_index" => 81], "db_column" => "processed_date"],
+        ["excel_column" => ["col_name" => "first_document_attached_date", "col_index" => 82], "db_column" => "first_document_attached_date"],
+        ["excel_column" => ["col_name" => "claim_processing_tat_days", "col_index" => 83], "db_column" => "claim_processing_tat_days"],
+        ["excel_column" => ["col_name" => "ready_for_payment_date", "col_index" => 84], "db_column" => "ready_for_payment_date"],
+        ["excel_column" => ["col_name" => "payment_date", "col_index" => 85], "db_column" => "payment_date"],
+        ["excel_column" => ["col_name" => "claim_payment_tat_days", "col_index" => 86], "db_column" => "claim_payment_tat_days"],
+        ["excel_column" => ["col_name" => "denial_description", "col_index" => 87], "db_column" => "denial_description"],
+        ["excel_column" => ["col_name" => "error_group", "col_index" => 88], "db_column" => "error_group"],
+        ["excel_column" => ["col_name" => "tpa_name", "col_index" => 89], "db_column" => "tpa_name"],
+        ["excel_column" => ["col_name" => "new_short_error_group", "col_index" => 90], "db_column" => "new_short_error_group"],
+        ["excel_column" => ["col_name" => "death_claim", "col_index" => 91], "db_column" => "death_claim"],
+        ["excel_column" => ["col_name" => "vip_claim", "col_index" => 92], "db_column" => "vip_claim"],
+        ["excel_column" => ["col_name" => "balance_sum_insured_exhausted", "col_index" => 93], "db_column" => "balance_sum_insured_exhausted"],
+    ];
+
+    protected $ticketMasterMapping = [
+
+        // Employee / Beneficiary details
+        'pribenef_employee_code' => 'emp_code',
+        'benef_relation'         => 'relationship',
+
+        // Policy / Claim identifiers
+        'policy_no'              => 'policy_no',
+        'claim_id'               => 'claim_number',
+        'event_id'               => 'tpa_no',
+        'claim_pre_auths'        => 'tpa_claim_push_reference_no',
+
+        // Claim type & status
+        'claim_status'           => 'tpa_claim_status',
+
+        // Dates
+        'date_of_admission'      => 'doa',
+        'date_of_discharge'      => 'dod',
+        'intimation_date'        => 'date_of_intimat',
+        'settled_date'           => 'settled_date',
+        'claim_received_date'    => 'registration_date',
+        'processed_date'         => 'approved_date',
+
+        // Amounts
+        'claim_amount'           => 'claim_amount',
+        'claim_approved_amount'  => 'approved_amount',
+
+        // Hospital details
+        'hospital_name'          => 'hospital_name',
+        'hospital_address'       => 'hospital_address',
+        'hospital_city'          => 'hospital_city',
+        'hospital_state'         => 'hospital_state',
+        'hospital_pincode'       => 'hospital_pin_code',
+        'hospital_phone_no'      => 'hospital_phone_no',
+
+        // Denial / approval
+        'denial_description'     => 'denial_reason',
+        'approved_description'   => 'approved_description',
+
+        // Payment
+        'utr_no'                 => 'utr_details',
+    ];
+
+    protected $statusMapping = [
+        'Settled' => 11,
+        'Rejected' => 8,
+        'Denied' => 8,
+        'Cancelled' => 13,
+        'Processed' => 61,
+        'Information Awaited' => 4,
+        'Denied Letter Sent' => 66,
+        'Cashless Document Awaited' => 3,
+    ];
+
+
+    /**
+     * ABSTRACT FUNCTIONs 
+     */
+    public function bulkInsertTPATable(array $data): bool
+    {
+        if (empty($data)) {
+            return false;
+        }
+        
+        $builder = $this->db->table('claims_dump_medi_assist');
+        $builder->insertBatch($data);
+
+        return true;
+    }
+
+
+    public function importClaimMaster(array $data): bool
+    {
+        if (empty($data)) {
+            return false;
+        }
+        
+        $ticketMasterModel = new TicketMasterModel();
+        $ticketMasterModel->insertBatch($data);
+
+        return true;
+    }
+
+
+    public function updateTicketIdInTPATable(): bool
+    {
+        if (empty($data)) {
+            return false;
+        }
+        
+        $builder = $this->db->table('claims_dump_medi_assist');
+        $builder->insertBatch($data);
+
+        return true;
+    }
+
+
+    public function updateTicketMasterRejectedReasonInTPATable($data): bool
+    {   
+        if (empty($data)) {
+            return false;
+        }
+        
+        $builder = $this->db->table('claims_dump_medi_assist');
+        $builder->insertBatch($data);
+
+        return true;
+    }
+
+
+    /**
+     * MAPPING FUNCTIONs 
+     */
+
+    public function mapTPAData(array $rows, $file_id): array
+    {   
+        $ClientPolicyModel = new ClaimDumpFileModel();
+        $file_data = $ClientPolicyModel->where('id', $file_id)->first();
+
+        $mapped = [];
+
+        foreach ($rows as $row) {
+
+            $item = [];
+
+            foreach ($this->mapping as $map) {
+                $excelColumn = $map['excel_column']['col_name'];
+                $dbColumn    = $map['db_column'];
+
+                $value = $row[$excelColumn] ?? null;
+                $item[$dbColumn] = $value;
+            }
+
+            $params = [
+                'date_of_admission' => change_date_format($item['date_of_admission'] ?? '') ?? null,
+                'pribenef_employee_code' => $item['pribenef_employee_code'] ?? null,
+                'claim_amount' => $item['claim_amount'] ?? null,
+                'event_id' => $item['event_id'] ?? null
+            ];
+
+            $is_duplicate = $this->checkDuplicateTpaClaim('claims_dump_medi_assist', $params);
+
+            if ($is_duplicate) {
+                $item = [];
+                continue;
+            }
+
+            $item['file_id'] = $file_id ?? null;
+            $item['client_id'] = $file_data['client_id'] ?? null;
+            $item['client_policy_id'] = $file_data['client_policy_id'] ?? null;
+            $item['created_by'] = $file_data['created_by'] ?? null;
+
+            $mapped[] = $item;
+        }
+
+        return $mapped;
+    }
+
+    public function mapClaimMasterData($file_id): array
+    {
+
+        $ClientPolicyModel = new ClaimDumpFileModel();
+        $file_data = $ClientPolicyModel->where('id', $file_id)->first();
+
+        $tpaClaimDumpData = $this->getTpaClaimDumpData('claims_dump_medi_assist', ['file_id' => $file_id]);
+
+        if (empty($tpaClaimDumpData)) {
+            return ['status' => false, 'message' => "No data to insert in TICKET MASTER"];
+        }
+
+
+        $ClientPolicyModel = new ClientPolicyModel();
+        $client_policy_data = $ClientPolicyModel
+            ->select("
+                client_policy.*,
+                (
+                    SELECT id
+                    FROM client_rm
+                    WHERE is_active = 1
+                    AND level = 3
+                    AND client_id = client_policy.client_id
+                    ORDER BY id ASC
+                    LIMIT 1
+                ) AS acm_id
+            ")
+            ->where('client_policy.id', $file_data['client_policy_id'])
+            ->where('client_policy.is_active', 1)
+            ->first();
+
+        try {
+
+            $mapped = [];
+            $rejecetd_reason = [];
+
+            foreach ($tpaClaimDumpData as $row) {
+
+                $params = [
+                    'doa' => change_date_format($row['date_of_admission'] ?? '') ?? null,
+                    'emp_code' => $row['pribenef_employee_code'] ?? null,
+                    'claim_amount' => $row['claim_amount'] ?? null,
+                    'tpa_no' => $row['event_id'] ?? null
+                ];
+
+                $isduplicate = $this->checkDublicateTicketMasterClaim($params);
+
+                if ($isduplicate) {
+                    $reason = "This claim already exists in our system.";
+                    $rejecetd_reason[$row['id']] = ["ticket_master_insert_reject_reason" => $reason];
+                    continue;
+                }
+
+                $item = [];
+
+                $item['client_id']    = $client_policy_data['client_id'] ?? null;
+                $item['client_policy_id'] = $client_policy_data['id'] ?? null;
+                $item['insurer_id']  = $client_policy_data['insurer_id'] ?? null;
+                $item['tpa_id']  = $client_policy_data['tpa_id'] ?? null;
+                $item['acm_id']  = $client_policy_data['acm_id'] ?? null;
+                $item['policy_no']  = $client_policy_data['policy_no'] ?? null;
+                $item['relationship']  = $this->convertRelation($row['benef_relation'] ?? null);
+
+                $employee_data = $this->getEmployeeDetails($file_data['client_id'], $file_data['client_policy_id'], $row['pribenef_employee_code'], $item['relationship']);
+
+                if (!empty($employee_data)) {
+                    $item['emp_id']    = $employee_data['id'] ?? null;
+                    $item['emp_name'] = $employee_data['name'] ?? null;
+                    $item['emp_mail']  = $employee_data['email_corporate'] ?? null;
+                    $item['emp_mobile']  = $employee_data['mobile'] ?? null;
+                    $item['insured_emp_id']  = $employee_data['insured_emp_id'] ?? null;
+                    $item['insured_name']  = $employee_data['insured_name'] ?? null;
+                } else {
+
+                    $reason = sprintf(
+                        'The policy number "%s" does not exist in our system. ' .
+                            'Details - Client ID: %s, Client Policy ID: %s, Employee Number: %s, Relationship: %s',
+                        $row['insurer_policy_number'],
+                        $file_data['client_id'],
+                        $file_data['client_policy_id'],
+                        $row['employee_number'],
+                        $item['relationship']
+                    );
+
+                    $rejecetd_reason[$row['id']] = ["ticket_master_insert_reject_reason" => $reason];
+                    continue;
+                }
+
+                foreach ($this->ticketMasterMapping as $tpaKey => $ticketMasterKey) {
+                    $item[$ticketMasterKey] = array_key_exists($tpaKey, $row) ? $row[$tpaKey] : null;
+                }
+
+                // Meta fields
+                $item['claim_dump_ref_id']    = $row['id'];
+                $item['file_id']    = $file_id;
+                $item['claim_status_id'] = $statusMapping[$row['claim_status']] ?? 61;
+                $item['created_by'] = $file_data['created_by'] ?? null;
+                $item['claim_type'] = 1;
+                $item['priority']           = 1;
+                $item['mode_of_intimation'] = 5;
+                $item['ticket_type_id']     = 1;
+
+                $mapped[] = $item;
+            }
+
+            return ['status' => true, 'mapped_array' => $mapped, 'rejected_reason_array' => $rejecetd_reason];
+            
+        } catch (\Throwable $th) {
+
+            $errorData = [
+                'message' => $th->getMessage(),
+                'file'    => $th->getFile(),
+                'line'    => $th->getLine(),
+                'code'    => $th->getCode(),
+                'trace'   => $th->getTraceAsString(),
+                'trace_array' => $th->getTrace(), // full array version (optional)
+                'function' => $th->getTrace()[0]['function'] ?? null,
+                'class' => $th->getTrace()[0]['class'] ?? null,
+            ];
+
+            return ['status' => false, "message" => $errorData['message'], 'error_data' => $errorData];
+        }
+    }
+
+
+    /**
+     * HELPER FUNCTIONs 
+     */
+
+    public function convertRelation(?string $relation): ?string
+    {
+        if (empty($relation)) {
+            return null;
+        }
+
+        $relation = strtolower($relation);
+
+        if (str_contains($relation, 'self')) {
+            return 'self';
+        }
+
+        if (str_contains($relation, 'spouse') || str_contains($relation, 'wife') || str_contains($relation, 'husband')) {
+            return 'spouse';
+        }
+
+        if (str_contains($relation, 'daughter')) {
+            return 'daughter';
+        }
+
+        if (str_contains($relation, 'son')) {
+            return 'son';
+        }
+
+        if (str_contains($relation, 'father in law') || str_contains($relation, 'father-in-law')) {
+            return 'father-in-law';
+        }
+
+        if (str_contains($relation, 'mother in law') || str_contains($relation, 'mother-in-law')) {
+            return 'mother-in-law';
+        }
+
+        if (str_contains($relation, 'father')) {
+            return 'father';
+        }
+
+        if (str_contains($relation, 'mother')) {
+            return 'mother';
+        }
+
+        return null; // unmatched case
+    }
+
+
+}
diff --git a/app/Libraries/TPAClaimsImportServices/RcareClaimImportService.php b/app/Libraries/TPAClaimsImportServices/RcareClaimImportService.php
new file mode 100644
index 00000000..4808d89e
--- /dev/null
+++ b/app/Libraries/TPAClaimsImportServices/RcareClaimImportService.php
@@ -0,0 +1,420 @@
+ ["col_name" => "CLInwardNo", "col_index" => 0], "db_column" => "cl_inward_no"],
+        ["excel_column" => ["col_name" => "Inward Date", "col_index" => 1], "db_column" => "inward_date"],
+        ["excel_column" => ["col_name" => "Claim Classification", "col_index" => 2], "db_column" => "claim_classification"],
+        ["excel_column" => ["col_name" => "Policy Name", "col_index" => 3], "db_column" => "policy_name"],
+        ["excel_column" => ["col_name" => "Policy Number", "col_index" => 4], "db_column" => "policy_number"],
+        ["excel_column" => ["col_name" => "Policy Start Date", "col_index" => 5], "db_column" => "policy_start_date"],
+        ["excel_column" => ["col_name" => "Policy End Date", "col_index" => 6], "db_column" => "policy_end_date"],
+        ["excel_column" => ["col_name" => "UHID", "col_index" => 7], "db_column" => "uhid"],
+        ["excel_column" => ["col_name" => "Insured Name", "col_index" => 8], "db_column" => "insured_name"],
+        ["excel_column" => ["col_name" => "Patient Name", "col_index" => 9], "db_column" => "patient_name"],
+        ["excel_column" => ["col_name" => "Employee/Member Id", "col_index" => 10], "db_column" => "employee_member_id"],
+        ["excel_column" => ["col_name" => "Grade", "col_index" => 11], "db_column" => "grade"],
+        ["excel_column" => ["col_name" => "Relation", "col_index" => 12], "db_column" => "relation"],
+        ["excel_column" => ["col_name" => "Age", "col_index" => 13], "db_column" => "age"],
+        ["excel_column" => ["col_name" => "Gender", "col_index" => 14], "db_column" => "gender"],
+        ["excel_column" => ["col_name" => "DF/DNF idenitifcation", "col_index" => 15], "db_column" => "df_dnf_identification"],
+        ["excel_column" => ["col_name" => "Sum Insured", "col_index" => 16], "db_column" => "sum_insured"],
+        ["excel_column" => ["col_name" => "DOA/OPD Treatment From", "col_index" => 17], "db_column" => "doa_opd_treatment_from"],
+        ["excel_column" => ["col_name" => "DOD/OPD Treatment To", "col_index" => 18], "db_column" => "dod_opd_treatment_to"],
+        ["excel_column" => ["col_name" => "Hospital Name", "col_index" => 19], "db_column" => "hospital_name"],
+        ["excel_column" => ["col_name" => "Hospital District", "col_index" => 20], "db_column" => "hospital_district"],
+        ["excel_column" => ["col_name" => "Hospital State", "col_index" => 21], "db_column" => "hospital_state"],
+        ["excel_column" => ["col_name" => "ICDCode", "col_index" => 22], "db_column" => "icd_code"],
+        ["excel_column" => ["col_name" => "Disease Category", "col_index" => 23], "db_column" => "disease_category"],
+        ["excel_column" => ["col_name" => "Final Status", "col_index" => 24], "db_column" => "final_status"],
+        ["excel_column" => ["col_name" => "Approved Date", "col_index" => 25], "db_column" => "approved_date"],
+        ["excel_column" => ["col_name" => "Claimed Amount", "col_index" => 26], "db_column" => "claimed_amount"],
+        ["excel_column" => ["col_name" => "Disallowed Amount", "col_index" => 27], "db_column" => "disallowed_amount"],
+        ["excel_column" => ["col_name" => "Net Sanct Amt", "col_index" => 28], "db_column" => "net_sanction_amount"],
+        ["excel_column" => ["col_name" => "Reason For Disallowance", "col_index" => 29], "db_column" => "reason_for_disallowance"],
+        ["excel_column" => ["col_name" => "External Query Remarks", "col_index" => 30], "db_column" => "external_query_remarks"],
+        ["excel_column" => ["col_name" => "Rejection Remarks", "col_index" => 31], "db_column" => "rejection_remarks"],
+        ["excel_column" => ["col_name" => "Cheque/NEFT Number", "col_index" => 32], "db_column" => "cheque_neft_number"],
+        ["excel_column" => ["col_name" => "Cheque/NEFT Date", "col_index" => 33], "db_column" => "cheque_neft_date"],
+        ["excel_column" => ["col_name" => "Diagnosis", "col_index" => 34], "db_column" => "diagnosis"],
+        ["excel_column" => ["col_name" => "Treatment Detail", "col_index" => 35], "db_column" => "treatment_detail"],
+        ["excel_column" => ["col_name" => "Member Reimbursement CL Type", "col_index" => 36], "db_column" => "member_reimbursement_cl_type"],
+    ];
+
+    protected $ticketMasterMapping = [
+
+        // Employee / Member
+        'employee_member_id'   => 'emp_code',
+        'relation'             => 'relationship',
+
+        // Policy
+        'policy_number'        => 'policy_no',
+        'policy_start_date'    => 'date_of_incep',
+
+        // Claim Dates
+        'doa_opd_treatment_from' => 'doa',
+        'dod_opd_treatment_to'   => 'dod',
+        'approved_date'          => 'approved_date',
+
+        // Claim Amounts
+        'claimed_amount'        => 'claim_amount',
+        'net_sanction_amount'   => 'approved_amount',
+
+        // Status / Remarks
+        'final_status'          => 'tpa_claim_status',
+        'reason_for_disallowance' => 'denial_reason',
+        'rejection_remarks'     => 'return_remark',
+
+        // Hospital
+        'hospital_name'         => 'hospital_name',
+        'hospital_state'        => 'hospital_state',
+        'hospital_district'     => 'hospital_city',
+
+        'diagnosis'             => 'claim_description',
+
+        // Payment
+        'cheque_neft_number'    => 'utr_details',
+        'cheque_neft_date'      => 'settled_date',
+
+        // References
+        'cl_inward_no'          => 'claim_number',
+    ];
+
+    protected $statusMapping = [
+        'Settled' => 11,
+        'Rejected' => 8,
+        'Denied' => 8,
+        'Cancelled' => 13,
+        'Processed' => 61,
+        'Information Awaited' => 4,
+        'Denied Letter Sent' => 66,
+        'Cashless Document Awaited' => 3,
+    ];
+
+    protected $dateColumns = [
+        'inward_date',
+        'policy_start_date',
+        'policy_end_date',
+        'doa_opd_treatment_from',
+        'dod_opd_treatment_to',
+        'approved_date',
+        'cheque_neft_date'
+    ];
+
+
+    /**
+     * ABSTRACT FUNCTIONs 
+     */
+    public function bulkInsertTPATable(array $data): bool
+    {
+        if (empty($data)) {
+            return false;
+        }
+
+        try {
+
+            $builder = $this->db->table('claims_dump_reliance');
+            $builder->insertBatch($data);
+
+            return true;
+
+        } catch (\Throwable $th) {
+
+            $errorData = [
+                'message' => $th->getMessage(),
+                'file'    => $th->getFile(),
+                'line'    => $th->getLine(),
+                'code'    => $th->getCode(),
+                'trace'   => $th->getTraceAsString(),
+                'trace_array' => $th->getTrace(), // full array version (optional)
+                'function' => $th->getTrace()[0]['function'] ?? null,
+                'class' => $th->getTrace()[0]['class'] ?? null,
+            ];
+            dd($errorData);
+            return false;
+        }
+
+    }
+
+
+    public function importClaimMaster(array $data): bool
+    {
+        if (empty($data)) {
+            return false;
+        }
+        
+        $ticketMasterModel = new TicketMasterModel();
+        $ticketMasterModel->insertBatch($data);
+
+        return true;
+    }
+
+
+    public function updateTicketIdInTPATable(): bool
+    {
+        if (empty($data)) {
+            return false;
+        }
+        
+        $builder = $this->db->table('claims_dump_reliance');
+        $builder->insertBatch($data);
+
+        return true;
+    }
+
+
+    public function updateTicketMasterRejectedReasonInTPATable($data): bool
+    {   
+        if (empty($data)) {
+            return false;
+        }
+        
+        $builder = $this->db->table('claims_dump_reliance');
+        $builder->insertBatch($data);
+
+        return true;
+    }
+
+
+    /**
+     * MAPPING FUNCTIONs 
+     */
+
+    public function mapTPAData(array $rows, $file_id): array
+    {   
+        $ClientPolicyModel = new ClaimDumpFileModel();
+        $file_data = $ClientPolicyModel->where('id', $file_id)->first();
+
+        $mapped = [];
+        foreach ($rows as $row) {
+
+            $item = [];
+
+            foreach ($this->mapping as $map) {
+                $excelColumn = $map['excel_column']['col_name'];
+                $dbColumn    = $map['db_column'];
+
+                $value = $row[$excelColumn] ?? null;
+                $item[$dbColumn] = $value;
+            }
+
+            foreach ($this->dateColumns as $key => $value) {
+                $item[$value] = change_date_format($item[$value] ?? null, 'd-M-y', 'Y-m-d');
+            }
+
+            $params = [
+                'doa_opd_treatment_from' => $item['doa_opd_treatment_from'] ?? null,
+                'employee_member_id' => $item['employee_member_id'] ?? null,
+                'claimed_amount' => $item['claimed_amount'] ?? null,
+                'uhid' => $item['uhid'] ?? null
+            ];
+
+            $is_duplicate = $this->checkDuplicateTpaClaim('claims_dump_reliance', $params);
+
+            if ($is_duplicate) {
+                $item = [];
+                continue;
+            }
+
+            $item['file_id'] = $file_id ?? null;
+            $item['client_id'] = $file_data['client_id'] ?? null;
+            $item['client_policy_id'] = $file_data['client_policy_id'] ?? null;
+            $item['created_by'] = $file_data['created_by'] ?? null;
+
+            $mapped[] = $item;
+        }
+
+        return $mapped;
+    }
+
+    public function mapClaimMasterData($file_id): array
+    {
+
+        $ClientPolicyModel = new ClaimDumpFileModel();
+        $file_data = $ClientPolicyModel->where('id', $file_id)->first();
+
+        $tpaClaimDumpData = $this->getTpaClaimDumpData('claims_dump_reliance', ['file_id' => $file_id]);
+
+        if (empty($tpaClaimDumpData)) {
+            return ['status' => false, 'message' => "No data to insert in TICKET MASTER"];
+        }
+
+
+        $ClientPolicyModel = new ClientPolicyModel();
+        $client_policy_data = $ClientPolicyModel
+            ->select("
+                client_policy.*,
+                (
+                    SELECT id
+                    FROM client_rm
+                    WHERE is_active = 1
+                    AND level = 3
+                    AND client_id = client_policy.client_id
+                    ORDER BY id ASC
+                    LIMIT 1
+                ) AS acm_id
+            ")
+            ->where('client_policy.id', $file_data['client_policy_id'])
+            ->where('client_policy.is_active', 1)
+            ->first();
+
+        try {
+
+            $mapped = [];
+            $rejecetd_reason = [];
+
+            foreach ($tpaClaimDumpData as $row) {
+
+                $params = [
+                    'doa' => change_date_format($row['doa_opd_treatment_from'] ?? '') ?? null,
+                    'emp_code' => $row['employee_member_id'] ?? null,
+                    'claim_amount' => $row['claimed_amount'] ?? null,
+                    'tpa_no' => $row['uhid'] ?? null
+                ];
+
+                $isduplicate = $this->checkDublicateTicketMasterClaim($params);
+
+                if ($isduplicate) {
+                    $reason = "This claim already exists in our system.";
+                    $rejecetd_reason[$row['id']] = ["ticket_master_insert_reject_reason" => $reason];
+                    continue;
+                }
+
+                $item = [];
+
+                $item['client_id']    = $client_policy_data['client_id'] ?? null;
+                $item['client_policy_id'] = $client_policy_data['id'] ?? null;
+                $item['insurer_id']  = $client_policy_data['insurer_id'] ?? null;
+                $item['tpa_id']  = $client_policy_data['tpa_id'] ?? null;
+                $item['acm_id']  = $client_policy_data['acm_id'] ?? null;
+                $item['policy_no']  = $client_policy_data['policy_no'] ?? null;
+                $item['relationship']  = $this->convertRelation($row['relation'] ?? null);
+
+                $employee_data = $this->getEmployeeDetails($file_data['client_id'], $file_data['client_policy_id'], $row['employee_member_id'], $item['relationship']);
+
+                if (!empty($employee_data)) {
+                    $item['emp_id']    = $employee_data['id'] ?? null;
+                    $item['emp_name'] = $employee_data['name'] ?? null;
+                    $item['emp_mail']  = $employee_data['email_corporate'] ?? null;
+                    $item['emp_mobile']  = $employee_data['mobile'] ?? null;
+                    $item['insured_emp_id']  = $employee_data['insured_emp_id'] ?? null;
+                    $item['insured_name']  = $employee_data['insured_name'] ?? null;
+                } else {
+
+                    $reason = sprintf(
+                        'The policy number "%s" does not exist in our system. ' .
+                            'Details - Client ID: %s, Client Policy ID: %s, Employee Number: %s, Relationship: %s',
+                        $row['insurer_policy_number'],
+                        $file_data['client_id'],
+                        $file_data['client_policy_id'],
+                        $row['employee_number'],
+                        $item['relationship']
+                    );
+
+                    $rejecetd_reason[$row['id']] = ["ticket_master_insert_reject_reason" => $reason];
+                    continue;
+                }
+
+                foreach ($this->ticketMasterMapping as $tpaKey => $ticketMasterKey) {
+                    $item[$ticketMasterKey] = array_key_exists($tpaKey, $row) ? $row[$tpaKey] : null;
+                }
+
+                // Meta fields
+                $item['claim_status_id'] = $statusMapping[$row['final_status']] ?? 61;
+                $item['file_id']    = $file_id;
+                $item['created_by'] = $file_data['created_by'] ?? null;
+                $item['claim_dump_ref_id']    = $row['id'];
+                $item['claim_type'] = 1;
+                $item['priority']           = 1;
+                $item['mode_of_intimation'] = 5;
+                $item['ticket_type_id']     = 1;
+
+
+                $mapped[] = $item;
+            }
+
+            return ['status' => true, 'mapped_array' => $mapped, 'rejected_reason_array' => $rejecetd_reason];
+            
+        } catch (\Throwable $th) {
+
+            $errorData = [
+                'message' => $th->getMessage(),
+                'file'    => $th->getFile(),
+                'line'    => $th->getLine(),
+                'code'    => $th->getCode(),
+                'trace'   => $th->getTraceAsString(),
+                'trace_array' => $th->getTrace(), // full array version (optional)
+                'function' => $th->getTrace()[0]['function'] ?? null,
+                'class' => $th->getTrace()[0]['class'] ?? null,
+            ];
+
+            return ['status' => false, "message" => $errorData['message'], 'error_data' => $errorData];
+        }
+    }
+
+
+    /**
+     * HELPER FUNCTIONs 
+     */
+
+    public function convertRelation(?string $relation): ?string
+    {
+        if (empty($relation)) {
+            return null;
+        }
+
+        $relation = strtolower($relation);
+
+        if (str_contains($relation, 'self')) {
+            return 'self';
+        }
+
+        if (str_contains($relation, 'spouse') || str_contains($relation, 'wife') || str_contains($relation, 'husband')) {
+            return 'spouse';
+        }
+
+        if (str_contains($relation, 'daughter')) {
+            return 'daughter';
+        }
+
+        if (str_contains($relation, 'son')) {
+            return 'son';
+        }
+
+        if (str_contains($relation, 'father in law') || str_contains($relation, 'father-in-law')) {
+            return 'father-in-law';
+        }
+
+        if (str_contains($relation, 'mother in law') || str_contains($relation, 'mother-in-law')) {
+            return 'mother-in-law';
+        }
+
+        if (str_contains($relation, 'father')) {
+            return 'father';
+        }
+
+        if (str_contains($relation, 'mother')) {
+            return 'mother';
+        }
+
+        return null; // unmatched case
+    }
+
+
+
+}
diff --git a/app/Libraries/TPAClaimsImportServices/VidalClaimImportService.php b/app/Libraries/TPAClaimsImportServices/VidalClaimImportService.php
new file mode 100644
index 00000000..b8bc92b8
--- /dev/null
+++ b/app/Libraries/TPAClaimsImportServices/VidalClaimImportService.php
@@ -0,0 +1,811 @@
+ "TPA Policy Number", "db_column" => "tpa_policy_number"],
+        ["excel_column" => "Insurer Policy Number", "db_column" => "insurer_policy_number"],
+        ["excel_column" => "Corporate Name", "db_column" => "corporate_name"],
+        ["excel_column" => "Proposer Name", "db_column" => "proposer_name"],
+        ["excel_column" => "Corporate Group ID", "db_column" => "corporate_group_id"],
+
+        ["excel_column" => "Policy Start Date", "db_column" => "policy_start_date"],
+        ["excel_column" => "Policy End date", "db_column" => "policy_end_date"],
+
+        ["excel_column" => "Insurance Company Name", "db_column" => "insurance_company_name"],
+
+        ["excel_column" => "Employee Number", "db_column" => "employee_number"],
+        ["excel_column" => "Employee Location", "db_column" => "employee_location"],
+
+        ["excel_column" => "Primary Policy Holder Name", "db_column" => "primary_policy_holder_name"],
+        ["excel_column" => "Primary Policy Holder Card ID", "db_column" => "primary_policy_holder_card_id"],
+
+        ["excel_column" => "Employee Grade", "db_column" => "employee_grade"],
+
+        ["excel_column" => "Patient Health Card ID", "db_column" => "patient_health_card_id"],
+        ["excel_column" => "Patient Name", "db_column" => "patient_name"],
+        ["excel_column" => "Date of Birth", "db_column" => "date_of_birth"],
+        ["excel_column" => "Age", "db_column" => "age"],
+        ["excel_column" => "Gender", "db_column" => "gender"],
+        ["excel_column" => "Relation", "db_column" => "relation"],
+
+        ["excel_column" => "Sum Insured", "db_column" => "sum_insured"],
+        ["excel_column" => "Balance Sum Insured", "db_column" => "balance_sum_insured"],
+        ["excel_column" => "Top Up Sum Insured", "db_column" => "top_up_sum_insured"],
+
+        ["excel_column" => "Enrollment status", "db_column" => "enrollment_status"],
+
+        ["excel_column" => "Policy Inception date", "db_column" => "policy_inception_date"],
+        ["excel_column" => "Policy Exit Date", "db_column" => "policy_exit_date"],
+
+        ["excel_column" => "Insurer Risk ID", "db_column" => "insurer_risk_id"],
+
+        ["excel_column" => "Claim Preauth Identifier", "db_column" => "claim_preauth_identifier"],
+        ["excel_column" => "TPA Claim Number", "db_column" => "tpa_claim_number"],
+        ["excel_column" => "Preauth Number", "db_column" => "preauth_number"],
+        ["excel_column" => "Insurer Claim Number", "db_column" => "insurer_claim_number"],
+
+        ["excel_column" => "Claim Received date", "db_column" => "claim_received_date"],
+        ["excel_column" => "Date of Admission", "db_column" => "date_of_admission"],
+        ["excel_column" => "Date of Discharge", "db_column" => "date_of_discharge"],
+
+        ["excel_column" => "Hospital Name", "db_column" => "hospital_name"],
+        ["excel_column" => "Hospital ID", "db_column" => "hospital_id"],
+        ["excel_column" => "Hospital Address", "db_column" => "hospital_address"],
+        ["excel_column" => "Hospital City", "db_column" => "hospital_city"],
+        ["excel_column" => "Hospital State", "db_column" => "hospital_state"],
+        ["excel_column" => "Hospital Pincode", "db_column" => "hospital_pincode"],
+        ["excel_column" => "Hospital Network status", "db_column" => "hospital_network_status"],
+        ["excel_column" => "PPN Hospital Status", "db_column" => "ppn_hospital_status"],
+
+        ["excel_column" => "Room Category", "db_column" => "room_category"],
+        ["excel_column" => "Room Days", "db_column" => "room_days"],
+        ["excel_column" => "ICU Days", "db_column" => "icu_days"],
+
+        ["excel_column" => "Medical Surgical Identifier", "db_column" => "medical_surgical_identifier"],
+        ["excel_column" => "Treatment Type of AYUSH", "db_column" => "treatment_type_of_ayush"],
+        ["excel_column" => "Package", "db_column" => "package"],
+
+        ["excel_column" => "Diagnosis", "db_column" => "diagnosis"],
+        ["excel_column" => "Illness Details", "db_column" => "illness_details"],
+        ["excel_column" => "Ailment Grouping", "db_column" => "ailment_grouping"],
+
+        ["excel_column" => "Primary ICD Code", "db_column" => "primary_icd_code"],
+        ["excel_column" => "Secondary ICD Code", "db_column" => "secondary_icd_code"],
+
+        ["excel_column" => "Procedure Code", "db_column" => "procedure_code"],
+        ["excel_column" => "Procedure Description", "db_column" => "procedure_description"],
+        ["excel_column" => "Procedure Grouping", "db_column" => "procedure_grouping"],
+
+        ["excel_column" => "Claim Submission mode", "db_column" => "claim_submission_mode"],
+        ["excel_column" => "Admission Category", "db_column" => "admission_category"],
+        ["excel_column" => "Type of Claim", "db_column" => "type_of_claim"],
+        ["excel_column" => "MainClaim_Prepost type", "db_column" => "mainclaim_prepost_type"],
+        ["excel_column" => "Type of Hospitalization", "db_column" => "type_of_hospitalization"],
+        ["excel_column" => "Death Status", "db_column" => "death_status"],
+        ["excel_column" => "Treatement Given", "db_column" => "treatment_given"],
+
+        ["excel_column" => "Claim Amount", "db_column" => "claim_amount"],
+        ["excel_column" => "Total Billed Amount", "db_column" => "total_billed_amount"],
+
+        ["excel_column" => "Claim Consultation Charges", "db_column" => "claim_consultation_charges"],
+        ["excel_column" => "Claim Investigation Charges", "db_column" => "claim_investigation_charges"],
+        ["excel_column" => "Claim Medicines", "db_column" => "claim_medicines"],
+        ["excel_column" => "Claim Nursing", "db_column" => "claim_nursing"],
+        ["excel_column" => "Claim Room Charges", "db_column" => "claim_room_charges"],
+        ["excel_column" => "Claim Icu Charges", "db_column" => "claim_icu_charges"],
+        ["excel_column" => "Claim Stay Charges", "db_column" => "claim_stay_charges"],
+        ["excel_column" => "Claim Surgeon Charges", "db_column" => "claim_surgeon_charges"],
+        ["excel_column" => "Claim Surgery Charges", "db_column" => "claim_surgery_charges"],
+        ["excel_column" => "Claim Miscellaneous Charges", "db_column" => "claim_miscellaneous_charges"],
+        ["excel_column" => "Claim Other Charges", "db_column" => "claim_other_charges"],
+
+        ["excel_column" => "Approved Consultation Charges", "db_column" => "approved_consultation_charges"],
+        ["excel_column" => "Approved Investigation Charges", "db_column" => "approved_investigation_charges"],
+        ["excel_column" => "Approved Medicines", "db_column" => "approved_medicines"],
+        ["excel_column" => "Approved Nursing", "db_column" => "approved_nursing"],
+        ["excel_column" => "Approved Room Charges", "db_column" => "approved_room_charges"],
+        ["excel_column" => "Approved Icu Charges", "db_column" => "approved_icu_charges"],
+        ["excel_column" => "Approved Stay Charges", "db_column" => "approved_stay_charges"],
+        ["excel_column" => "Approved Surgeon Charges", "db_column" => "approved_surgeon_charges"],
+        ["excel_column" => "Approved Surgery Charges", "db_column" => "approved_surgery_charges"],
+        ["excel_column" => "Approved Miscellaneous Charges", "db_column" => "approved_miscellaneous_charges"],
+        ["excel_column" => "Approved Others Charges", "db_column" => "approved_others_charges"],
+
+        ["excel_column" => "Total Disallowed Amount", "db_column" => "total_disallowed_amount"],
+        ["excel_column" => "Copayment Amount", "db_column" => "copayment_amount"],
+        ["excel_column" => "Deposit Amount", "db_column" => "deposit_amount"],
+
+        ["excel_column" => "Exceeds Policy Limit", "db_column" => "exceeds_policy_limit"],
+        ["excel_column" => "Copay Buffer", "db_column" => "copay_buffer"],
+        ["excel_column" => "Hospital Discount Amount", "db_column" => "hospital_discount_amount"],
+        ["excel_column" => "Deductible Amount", "db_column" => "deductible_amount"],
+
+        ["excel_column" => "Approved Amount", "db_column" => "approved_amount"],
+        ["excel_column" => "Total Incurred Amount", "db_column" => "total_incurred_amount"],
+        ["excel_column" => "Total Buffer Approved", "db_column" => "total_buffer_approved"],
+        ["excel_column" => "Total Buffer Utlilized", "db_column" => "total_buffer_utilized"],
+
+        ["excel_column" => "TDS Amount", "db_column" => "tds_amount"],
+        ["excel_column" => "Net Amount", "db_column" => "net_amount"],
+
+        ["excel_column" => "Claim Decision date", "db_column" => "claim_decision_date"],
+        ["excel_column" => "Payment Reference Number", "db_column" => "payment_reference_number"],
+        ["excel_column" => "Payment Reference Date", "db_column" => "payment_reference_date"],
+
+        ["excel_column" => "Claim Status", "db_column" => "claim_status"],
+        ["excel_column" => "Deduction Remarks", "db_column" => "deduction_remarks"],
+        ["excel_column" => "Rejection Reasons", "db_column" => "rejection_reasons"],
+        ["excel_column" => "Claim Query Reasons", "db_column" => "claim_query_reasons"],
+
+        ["excel_column" => "Insurer Request Sent date", "db_column" => "insurer_request_sent_date"],
+        ["excel_column" => "Insurer Conf. Received date", "db_column" => "insurer_conf_received_date"],
+        ["excel_column" => "Claim Reopen Date", "db_column" => "claim_reopen_date"],
+
+        ["excel_column" => "First Query Raised date", "db_column" => "first_query_raised_date"],
+        ["excel_column" => "First Query response date", "db_column" => "first_query_response_date"],
+        ["excel_column" => "Last Query Raised date", "db_column" => "last_query_raised_date"],
+        ["excel_column" => "Last Query response date", "db_column" => "last_query_response_date"],
+        ["excel_column" => "Last Document Received date", "db_column" => "last_document_received_date"],
+    ];
+
+
+    protected $mapping = [
+
+        ["excel_column" => ["col_name" => "TPA Policy Number", "col_index" => 0], "db_column" => "tpa_policy_number"],
+        ["excel_column" => ["col_name" => "Insurer Policy Number", "col_index" => 1], "db_column" => "insurer_policy_number"],
+        ["excel_column" => ["col_name" => "Corporate Name", "col_index" => 2], "db_column" => "corporate_name"],
+        ["excel_column" => ["col_name" => "Proposer Name", "col_index" => 3], "db_column" => "proposer_name"],
+        ["excel_column" => ["col_name" => "Corporate Group ID", "col_index" => 4], "db_column" => "corporate_group_id"],
+
+        ["excel_column" => ["col_name" => "Policy Start Date", "col_index" => 5], "db_column" => "policy_start_date"],
+        ["excel_column" => ["col_name" => "Policy End date", "col_index" => 6], "db_column" => "policy_end_date"],
+
+        ["excel_column" => ["col_name" => "Insurance Company Name", "col_index" => 7], "db_column" => "insurance_company_name"],
+
+        ["excel_column" => ["col_name" => "Employee Number", "col_index" => 8], "db_column" => "employee_number"],
+        ["excel_column" => ["col_name" => "Employee Location", "col_index" => 9], "db_column" => "employee_location"],
+
+        ["excel_column" => ["col_name" => "Primary Policy Holder Name", "col_index" => 10], "db_column" => "primary_policy_holder_name"],
+        ["excel_column" => ["col_name" => "Primary Policy Holder Card ID", "col_index" => 11], "db_column" => "primary_policy_holder_card_id"],
+
+        ["excel_column" => ["col_name" => "Employee Grade", "col_index" => 12], "db_column" => "employee_grade"],
+
+        ["excel_column" => ["col_name" => "Patient Health Card ID", "col_index" => 13], "db_column" => "patient_health_card_id"],
+        ["excel_column" => ["col_name" => "Patient Name", "col_index" => 14], "db_column" => "patient_name"],
+        ["excel_column" => ["col_name" => "Date of Birth", "col_index" => 15], "db_column" => "date_of_birth"],
+        ["excel_column" => ["col_name" => "Age", "col_index" => 16], "db_column" => "age"],
+        ["excel_column" => ["col_name" => "Gender", "col_index" => 17], "db_column" => "gender"],
+        ["excel_column" => ["col_name" => "Relation", "col_index" => 18], "db_column" => "relation"],
+
+        ["excel_column" => ["col_name" => "Sum Insured", "col_index" => 19], "db_column" => "sum_insured"],
+        ["excel_column" => ["col_name" => "Balance Sum Insured", "col_index" => 20], "db_column" => "balance_sum_insured"],
+        ["excel_column" => ["col_name" => "Top Up Sum Insured", "col_index" => 21], "db_column" => "top_up_sum_insured"],
+
+        ["excel_column" => ["col_name" => "Enrollment status", "col_index" => 22], "db_column" => "enrollment_status"],
+
+        ["excel_column" => ["col_name" => "Policy Inception date", "col_index" => 23], "db_column" => "policy_inception_date"],
+        ["excel_column" => ["col_name" => "Policy Exit Date", "col_index" => 24], "db_column" => "policy_exit_date"],
+
+        ["excel_column" => ["col_name" => "Insurer Risk ID", "col_index" => 25], "db_column" => "insurer_risk_id"],
+
+        ["excel_column" => ["col_name" => "Claim Preauth Identifier", "col_index" => 26], "db_column" => "claim_preauth_identifier"],
+        ["excel_column" => ["col_name" => "TPA Claim Number", "col_index" => 27], "db_column" => "tpa_claim_number"],
+        ["excel_column" => ["col_name" => "Preauth Number", "col_index" => 28], "db_column" => "preauth_number"],
+        ["excel_column" => ["col_name" => "Insurer Claim Number", "col_index" => 29], "db_column" => "insurer_claim_number"],
+
+        ["excel_column" => ["col_name" => "Claim Received date", "col_index" => 30], "db_column" => "claim_received_date"],
+        ["excel_column" => ["col_name" => "Date of Admission", "col_index" => 31], "db_column" => "date_of_admission"],
+        ["excel_column" => ["col_name" => "Date of Discharge", "col_index" => 32], "db_column" => "date_of_discharge"],
+
+        ["excel_column" => ["col_name" => "Hospital Name", "col_index" => 33], "db_column" => "hospital_name"],
+        ["excel_column" => ["col_name" => "Hospital ID", "col_index" => 34], "db_column" => "hospital_id"],
+        ["excel_column" => ["col_name" => "Hospital Address", "col_index" => 35], "db_column" => "hospital_address"],
+        ["excel_column" => ["col_name" => "Hospital City", "col_index" => 36], "db_column" => "hospital_city"],
+        ["excel_column" => ["col_name" => "Hospital State", "col_index" => 37], "db_column" => "hospital_state"],
+        ["excel_column" => ["col_name" => "Hospital Pincode", "col_index" => 38], "db_column" => "hospital_pincode"],
+        ["excel_column" => ["col_name" => "Hospital Network status", "col_index" => 39], "db_column" => "hospital_network_status"],
+        ["excel_column" => ["col_name" => "PPN Hospital Status", "col_index" => 40], "db_column" => "ppn_hospital_status"],
+
+        ["excel_column" => ["col_name" => "Room Category", "col_index" => 41], "db_column" => "room_category"],
+        ["excel_column" => ["col_name" => "Room Days", "col_index" => 42], "db_column" => "room_days"],
+        ["excel_column" => ["col_name" => "ICU Days", "col_index" => 43], "db_column" => "icu_days"],
+
+        ["excel_column" => ["col_name" => "Medical Surgical Identifier", "col_index" => 44], "db_column" => "medical_surgical_identifier"],
+        ["excel_column" => ["col_name" => "Treatment Type of AYUSH", "col_index" => 45], "db_column" => "treatment_type_of_ayush"],
+        ["excel_column" => ["col_name" => "Package", "col_index" => 46], "db_column" => "package"],
+
+        ["excel_column" => ["col_name" => "Diagnosis", "col_index" => 47], "db_column" => "diagnosis"],
+        ["excel_column" => ["col_name" => "Illness Details", "col_index" => 48], "db_column" => "illness_details"],
+        ["excel_column" => ["col_name" => "Ailment Grouping", "col_index" => 49], "db_column" => "ailment_grouping"],
+
+        ["excel_column" => ["col_name" => "Primary ICD Code", "col_index" => 50], "db_column" => "primary_icd_code"],
+        ["excel_column" => ["col_name" => "Secondary ICD Code", "col_index" => 51], "db_column" => "secondary_icd_code"],
+
+        ["excel_column" => ["col_name" => "Procedure Code", "col_index" => 52], "db_column" => "procedure_code"],
+        ["excel_column" => ["col_name" => "Procedure Description", "col_index" => 53], "db_column" => "procedure_description"],
+        ["excel_column" => ["col_name" => "Procedure Grouping", "col_index" => 54], "db_column" => "procedure_grouping"],
+
+        ["excel_column" => ["col_name" => "Claim Submission mode", "col_index" => 55], "db_column" => "claim_submission_mode"],
+        ["excel_column" => ["col_name" => "Admission Category", "col_index" => 56], "db_column" => "admission_category"],
+        ["excel_column" => ["col_name" => "Type of Claim", "col_index" => 57], "db_column" => "type_of_claim"],
+        ["excel_column" => ["col_name" => "MainClaim_Prepost type", "col_index" => 58], "db_column" => "mainclaim_prepost_type"],
+        ["excel_column" => ["col_name" => "Type of Hospitalization", "col_index" => 59], "db_column" => "type_of_hospitalization"],
+        ["excel_column" => ["col_name" => "Death Status", "col_index" => 60], "db_column" => "death_status"],
+        ["excel_column" => ["col_name" => "Treatement Given", "col_index" => 61], "db_column" => "treatment_given"],
+
+        ["excel_column" => ["col_name" => "Claim Amount", "col_index" => 62], "db_column" => "claim_amount"],
+        ["excel_column" => ["col_name" => "Total Billed Amount", "col_index" => 63], "db_column" => "total_billed_amount"],
+
+        ["excel_column" => ["col_name" => "Claim Consultation Charges", "col_index" => 64], "db_column" => "claim_consultation_charges"],
+        ["excel_column" => ["col_name" => "Claim Investigation Charges", "col_index" => 65], "db_column" => "claim_investigation_charges"],
+        ["excel_column" => ["col_name" => "Claim Medicines", "col_index" => 66], "db_column" => "claim_medicines"],
+        ["excel_column" => ["col_name" => "Claim Nursing", "col_index" => 67], "db_column" => "claim_nursing"],
+        ["excel_column" => ["col_name" => "Claim Room Charges", "col_index" => 68], "db_column" => "claim_room_charges"],
+        ["excel_column" => ["col_name" => "Claim Icu Charges", "col_index" => 69], "db_column" => "claim_icu_charges"],
+        ["excel_column" => ["col_name" => "Claim Stay Charges", "col_index" => 70], "db_column" => "claim_stay_charges"],
+        ["excel_column" => ["col_name" => "Claim Surgeon Charges", "col_index" => 71], "db_column" => "claim_surgeon_charges"],
+        ["excel_column" => ["col_name" => "Claim Surgery Charges", "col_index" => 72], "db_column" => "claim_surgery_charges"],
+        ["excel_column" => ["col_name" => "Claim Miscellaneous Charges", "col_index" => 73], "db_column" => "claim_miscellaneous_charges"],
+        ["excel_column" => ["col_name" => "Claim Other Charges", "col_index" => 74], "db_column" => "claim_other_charges"],
+
+        ["excel_column" => ["col_name" => "Approved Consultation Charges", "col_index" => 75], "db_column" => "approved_consultation_charges"],
+        ["excel_column" => ["col_name" => "Approved Investigation Charges", "col_index" => 76], "db_column" => "approved_investigation_charges"],
+        ["excel_column" => ["col_name" => "Approved Medicines", "col_index" => 77], "db_column" => "approved_medicines"],
+        ["excel_column" => ["col_name" => "Approved Nursing", "col_index" => 78], "db_column" => "approved_nursing"],
+        ["excel_column" => ["col_name" => "Approved Room Charges", "col_index" => 79], "db_column" => "approved_room_charges"],
+        ["excel_column" => ["col_name" => "Approved Icu Charges", "col_index" => 80], "db_column" => "approved_icu_charges"],
+        ["excel_column" => ["col_name" => "Approved Stay Charges", "col_index" => 81], "db_column" => "approved_stay_charges"],
+        ["excel_column" => ["col_name" => "Approved Surgeon Charges", "col_index" => 82], "db_column" => "approved_surgeon_charges"],
+        ["excel_column" => ["col_name" => "Approved Surgery Charges", "col_index" => 83], "db_column" => "approved_surgery_charges"],
+        ["excel_column" => ["col_name" => "Approved Miscellaneous Charges", "col_index" => 84], "db_column" => "approved_miscellaneous_charges"],
+        ["excel_column" => ["col_name" => "Approved Others Charges", "col_index" => 85], "db_column" => "approved_others_charges"],
+
+        ["excel_column" => ["col_name" => "Total Disallowed Amount", "col_index" => 86], "db_column" => "total_disallowed_amount"],
+        ["excel_column" => ["col_name" => "Copayment Amount", "col_index" => 87], "db_column" => "copayment_amount"],
+        ["excel_column" => ["col_name" => "Deposit Amount", "col_index" => 88], "db_column" => "deposit_amount"],
+
+        ["excel_column" => ["col_name" => "Exceeds Policy Limit", "col_index" => 89], "db_column" => "exceeds_policy_limit"],
+        ["excel_column" => ["col_name" => "Copay Buffer", "col_index" => 90], "db_column" => "copay_buffer"],
+        ["excel_column" => ["col_name" => "Hospital Discount Amount", "col_index" => 91], "db_column" => "hospital_discount_amount"],
+        ["excel_column" => ["col_name" => "Deductible Amount", "col_index" => 92], "db_column" => "deductible_amount"],
+
+        ["excel_column" => ["col_name" => "Approved Amount", "col_index" => 93], "db_column" => "approved_amount"],
+        ["excel_column" => ["col_name" => "Total Incurred Amount", "col_index" => 94], "db_column" => "total_incurred_amount"],
+        ["excel_column" => ["col_name" => "Total Buffer Approved", "col_index" => 95], "db_column" => "total_buffer_approved"],
+        ["excel_column" => ["col_name" => "Total Buffer Utlilized", "col_index" => 96], "db_column" => "total_buffer_utilized"],
+
+        ["excel_column" => ["col_name" => "TDS Amount", "col_index" => 97], "db_column" => "tds_amount"],
+        ["excel_column" => ["col_name" => "Net Amount", "col_index" => 98], "db_column" => "net_amount"],
+
+        ["excel_column" => ["col_name" => "Claim Decision date", "col_index" => 99], "db_column" => "claim_decision_date"],
+        ["excel_column" => ["col_name" => "Payment Reference Number", "col_index" => 100], "db_column" => "payment_reference_number"],
+        ["excel_column" => ["col_name" => "Payment Reference Date", "col_index" => 101], "db_column" => "payment_reference_date"],
+
+        ["excel_column" => ["col_name" => "Claim Status", "col_index" => 102], "db_column" => "claim_status"],
+        ["excel_column" => ["col_name" => "Deduction Remarks", "col_index" => 103], "db_column" => "deduction_remarks"],
+        ["excel_column" => ["col_name" => "Rejection Reasons", "col_index" => 104], "db_column" => "rejection_reasons"],
+        ["excel_column" => ["col_name" => "Claim Query Reasons", "col_index" => 105], "db_column" => "claim_query_reasons"],
+
+        ["excel_column" => ["col_name" => "Insurer Request Sent date", "col_index" => 106], "db_column" => "insurer_request_sent_date"],
+        ["excel_column" => ["col_name" => "Insurer Conf. Received date", "col_index" => 107], "db_column" => "insurer_conf_received_date"],
+        ["excel_column" => ["col_name" => "Claim Reopen Date", "col_index" => 108], "db_column" => "claim_reopen_date"],
+
+        ["excel_column" => ["col_name" => "First Query Raised date", "col_index" => 109], "db_column" => "first_query_raised_date"],
+        ["excel_column" => ["col_name" => "First Query response date", "col_index" => 110], "db_column" => "first_query_response_date"],
+        ["excel_column" => ["col_name" => "Last Query Raised date", "col_index" => 111], "db_column" => "last_query_raised_date"],
+        ["excel_column" => ["col_name" => "Last Query response date", "col_index" => 112], "db_column" => "last_query_response_date"],
+        ["excel_column" => ["col_name" => "Last Document Received date", "col_index" => 113], "db_column" => "last_document_received_date"],
+    ];
+
+
+    protected $ticketMasterMapping = [
+
+        // Policy / Claim identifiers
+        'insurer_policy_number'    => 'policy_no',
+        'insurer_claim_number'     => 'claim_number',
+        'tpa_claim_number'         => 'tpa_claim_id',
+
+        // Employee / Insured details
+        'employee_number'          => 'emp_code',
+        'primary_policy_holder_name' => 'emp_name',
+        'patient_name'             => 'insured_name',
+
+        // Dates
+        'date_of_admission'        => 'doa',
+        'date_of_discharge'        => 'dod',
+        'date_of_birth'            => 'dob',
+        'claim_received_date'      => 'registration_date',
+
+        // Claim details
+        'claim_amount'             => 'claim_amount',
+        'approved_amount'          => 'approved_amount',
+        'sum_insured'              => 'si_amt',
+        'claim_status'             => 'tpa_claim_status',
+
+        // Hospital details
+        'hospital_name'            => 'hospital_name',
+        'hospital_address'         => 'hospital_address',
+        'hospital_city'            => 'hospital_city',
+        'hospital_state'           => 'hospital_state',
+        'hospital_pincode'         => 'hospital_pin_code',
+
+        // Meta
+        'file_id'                  => 'file_id',
+    ];
+
+
+    protected $statusMapping = [
+        'CL Paid with Settlement Letter' => 11,
+        'CL Rejected' => 8,
+        'CL Approved' => 9,
+        'AL Closed' => 12,
+    ];
+
+
+    /**
+     * ABSTRACT FUNCTIONs 
+     */
+    public function bulkInsertTPATable(array $data): bool
+    {
+        if (empty($data)) {
+            return false;
+        }
+        
+        $builder = $this->db->table('claims_dump_vidal');
+        $builder->insertBatch($data);
+
+        return true;
+    }
+
+
+    public function importClaimMaster(array $data): bool
+    {
+        if (empty($data)) {
+            return false;
+        }
+        
+        $ticketMasterModel = new TicketMasterModel();
+        $ticketMasterModel->insertBatch($data);
+
+        return true;
+    }
+
+
+    public function updateTicketIdInTPATable(): bool
+    {
+        if (empty($data)) {
+            return false;
+        }
+        
+        $builder = $this->db->table('claims_dump_vidal');
+        $builder->insertBatch($data);
+
+        return true;
+    }
+
+
+    public function updateTicketMasterRejectedReasonInTPATable($data): bool
+    {   
+        if (empty($data)) {
+            return false;
+        }
+        
+        $builder = $this->db->table('claims_dump_vidal');
+        $builder->insertBatch($data);
+
+        return true;
+    }
+
+
+    /**
+     * MAPPING FUNCTIONs 
+     */
+
+    public function mapTPAData(array $rows, $file_id): array
+    {   
+        $ClientPolicyModel = new ClaimDumpFileModel();
+        $file_data = $ClientPolicyModel->where('id', $file_id)->first();
+
+        $mapped = [];
+
+        foreach ($rows as $row) {
+
+            $item = [];
+
+            foreach ($this->mapping as $map) {
+                $excelColumn = $map['excel_column']['col_name'];
+                $dbColumn    = $map['db_column'];
+
+                $value = $row[$excelColumn] ?? null;
+
+                if ($this->isDateValue($value)) {
+                    $value = $this->normalizeDate($value);
+                }
+
+                $item[$dbColumn] = $value;
+            }
+
+            $params = [
+                'date_of_admission' => change_date_format($item['date_of_admission'] ?? '') ?? null,
+                'employee_number' => $item['employee_number'] ?? null,
+                'claim_amount' => $item['claim_amount'] ?? null,
+                'primary_policy_holder_card_id' => $item['primary_policy_holder_card_id'] ?? null
+            ];
+
+            $is_duplicate = $this->checkDuplicateTpaClaim('claims_dump_vidal', $params);
+
+            if ($is_duplicate) {
+                $item = [];
+                continue;
+            }
+
+            $item['file_id'] = $file_id ?? null;
+            $item['client_id'] = $file_data['client_id'] ?? null;
+            $item['client_policy_id'] = $file_data['client_policy_id'] ?? null;
+            $item['created_by'] = $file_data['created_by'] ?? null;
+
+            $mapped[] = $item;
+        }
+
+        return $mapped;
+    }
+
+    public function mapClaimMasterData($file_id): array
+    {
+
+        $ClientPolicyModel = new ClaimDumpFileModel();
+        $file_data = $ClientPolicyModel->where('id', $file_id)->first();
+
+        $tpaClaimDumpData = $this->getTpaClaimDumpData('claims_dump_vidal', ['file_id' => $file_id]);
+
+        if (empty($tpaClaimDumpData)) {
+            return ['status' => false, 'message' => "No data to insert in TICKET MASTER"];
+        }
+
+
+        $ClientPolicyModel = new ClientPolicyModel();
+        $client_policy_data = $ClientPolicyModel
+            ->select("
+                client_policy.*,
+                (
+                    SELECT id
+                    FROM client_rm
+                    WHERE is_active = 1
+                    AND level = 3
+                    AND client_id = client_policy.client_id
+                    ORDER BY id ASC
+                    LIMIT 1
+                ) AS acm_id
+            ")
+            ->where('client_policy.id', $file_data['client_policy_id'])
+            ->where('client_policy.is_active', 1)
+            ->first();
+
+        try {
+
+            $mapped = [];
+            $rejecetd_reason = [];
+
+            foreach ($tpaClaimDumpData as $row) {
+
+                $params = [
+                    'doa' => change_date_format($row['date_of_admission'] ?? '') ?? null,
+                    'emp_code' => $row['employee_number'] ?? null,
+                    'claim_amount' => $row['claim_amount'] ?? null,
+                    'tpa_no' => $row['primary_policy_holder_card_id'] ?? null
+                ];
+
+                $isduplicate = $this->checkDublicateTicketMasterClaim($params);
+
+                if ($isduplicate) {
+                    $reason = "This claim already exists in our system.";
+                    $rejecetd_reason[$row['id']] = ["ticket_master_insert_reject_reason" => $reason];
+                    continue;
+                }
+
+                $item = [];
+
+                $item['client_id']    = $client_policy_data['client_id'] ?? null;
+                $item['client_policy_id'] = $client_policy_data['id'] ?? null;
+                $item['insurer_id']  = $client_policy_data['insurer_id'] ?? null;
+                $item['tpa_id']  = $client_policy_data['tpa_id'] ?? null;
+                $item['acm_id']  = $client_policy_data['acm_id'] ?? null;
+                $item['policy_no']  = $client_policy_data['policy_no'] ?? null;
+                $item['relationship']  = $this->convertRelation($row['relation'] ?? null, $row['gender'] ?? null);
+
+                $employee_data = $this->getEmployeeDetails($file_data['client_id'], $file_data['client_policy_id'], $row['employee_number'], $item['relationship']);
+
+                if (!empty($employee_data)) {
+                    $item['emp_id']    = $employee_data['id'] ?? null;
+                    $item['emp_name'] = $employee_data['name'] ?? null;
+                    $item['emp_mail']  = $employee_data['email_corporate'] ?? null;
+                    $item['emp_mobile']  = $employee_data['mobile'] ?? null;
+                    $item['insured_emp_id']  = $employee_data['insured_emp_id'] ?? null;
+                    $item['insured_name']  = $employee_data['insured_name'] ?? null;
+                } else {
+
+                    $reason = sprintf(
+                        'The policy number "%s" does not exist in our system. ' .
+                            'Details - Client ID: %s, Client Policy ID: %s, Employee Number: %s, Relationship: %s',
+                        $row['insurer_policy_number'],
+                        $file_data['client_id'],
+                        $file_data['client_policy_id'],
+                        $row['employee_number'],
+                        $item['relationship']
+                    );
+
+                    $rejecetd_reason[$row['id']] = ["ticket_master_insert_reject_reason" => $reason];
+                    continue;
+                }
+
+                foreach ($this->ticketMasterMapping as $tpaKey => $ticketMasterKey) {
+                    $item[$ticketMasterKey] = array_key_exists($tpaKey, $row) ? $row[$tpaKey] : null;
+                }
+
+                // Meta fields
+                $item['claim_status_id'] = $statusMapping[$row['status']] ?? 61;
+                $item['file_id']    = $file_id;
+                $item['claim_dump_ref_id']    = $row['id'];
+                $item['created_by'] = $file_data['created_by'] ?? null;
+                $item['claim_type'] = isset($row['mainclaim_prepost_type']) && !empty($row['mainclaim_prepost_type']) && strtolower($row['mainclaim_prepost_type']) == 'normal' ? 1 : 3;
+                $item['priority']           = 1;
+                $item['mode_of_intimation'] = 5;
+                $item['ticket_type_id']     = 1;
+
+                $mapped[] = $item;
+            }
+
+            return ['status' => true, 'mapped_array' => $mapped, 'rejected_reason_array' => $rejecetd_reason];
+            
+        } catch (\Throwable $th) {
+
+            $errorData = [
+                'message' => $th->getMessage(),
+                'file'    => $th->getFile(),
+                'line'    => $th->getLine(),
+                'code'    => $th->getCode(),
+                'trace'   => $th->getTraceAsString(),
+                'trace_array' => $th->getTrace(), // full array version (optional)
+                'function' => $th->getTrace()[0]['function'] ?? null,
+                'class' => $th->getTrace()[0]['class'] ?? null,
+            ];
+
+            return ['status' => false, "message" => $errorData['message'], 'error_data' => $errorData];
+        }
+    }
+
+    public function mapClaimMasterDataOld($file_id): array
+    {
+
+        $tpaClaimDumpData = $this->db
+            ->table('claims_dump_vidal')
+            ->where('is_active', 1)
+            ->where('file_id', $file_id)
+            ->where('ticket_id IS NULL')
+            ->get()
+            ->getResultArray();
+
+        if (empty($tpaClaimDumpData)) {
+            return [];
+        }
+
+        $ClientPolicyModel = new ClientPolicyModel();
+        $client_policy_data = $ClientPolicyModel->where('is_active', 1)->findAll();
+
+        $mapped = [];
+        $rejecetd_reason = [];
+
+        foreach ($tpaClaimDumpData as $row) {
+
+            $item = [];
+
+            if(isset($row['insurer_policy_number']) && !empty($row['insurer_policy_number'])){
+
+                $basic_claim_data = $this->getClientPolicyDataBypolicyNo($client_policy_data, $row['insurer_policy_number']);
+                if(empty($basic_claim_data)){
+                    $reason = " This policy no ( " . $row['insurer_policy_number'] ." ) does not exist in our system";
+                    $rejecetd_reason[$row['id']] = ["ticket_master_insert_reject_reason" => $reason];
+                    continue;
+                }
+
+                $item['client_id']    = $basic_claim_data['client_id'] ?? null;
+                $item['client_policy_id'] = $basic_claim_data['id'] ?? null;
+                $item['insurer_id']  = $basic_claim_data['insurer_id'] ?? null;
+                $item['tpa_id']  = $basic_claim_data['tpa_id'] ?? null;
+                $item['acm_id']  = $basic_claim_data['acm_id'] ?? null;
+                $item['policy_no']  = $basic_claim_data['policy_no'] ?? null;
+                $item['relationship']  = $this->convertRelation($row['relation'] ?? null, $row['gender'] ?? null);
+
+                $employee_data = $this->getEmployeeDetails($item['client_id'], $item['client_policy_id'], $row['employee_number'], $item['relationship']);
+                if(!empty($employee_data)){
+                    $item['emp_id']    = $employee_data['client_id'] ?? null;
+                    $item['emp_name'] = $employee_data['id'] ?? null;
+                    $item['emp_mail']  = $employee_data['insurer_id'] ?? null;
+                    $item['emp_mobile']  = $employee_data['tpa_id'] ?? null;
+                    $item['insured_emp_id']  = $employee_data['insured_emp_id'] ?? null;
+                    $item['insured_name']  = $employee_data['insured_name'] ?? null;
+                }else{
+                    $reason = " This policy no ( " . $row['insurer_policy_number'] ." ) does not exist in our system";
+                    $rejecetd_reason[$row['id']] = ["ticket_master_insert_reject_reason" => $reason];
+                    continue;
+                }
+
+            }else{
+                $reason = " Policy Number is empty";
+                $rejecetd_reason[$row['id']] = ["ticket_master_insert_reject_reason" => $reason];
+                continue;
+            }
+
+            foreach ($this->ticketMasterMapping as $tpaKey => $ticketMasterKey) {
+                $item[$ticketMasterKey] = array_key_exists($tpaKey, $row)
+                    ? $row[$tpaKey]
+                    : null;
+            }
+
+            $isduplicate = checkDuplicateClaim([
+                'doa' => change_date_format($item['doa'] ?? '') ?? null, 
+                'emp_code' => $item['emp_code'] ?? null, 
+                'claim_amount' => $item['claim_amount'] ?? null, 
+                'policy_no' => $item['policy_no'] ?? null
+            ]);
+
+            if($isduplicate){
+                $reason = " This claim ( " . $row['insurer_policy_number'] ." ) does not exist in our system";
+                $rejecetd_reason[$row['id']] = ["ticket_master_insert_reject_reason" => $reason];
+                continue;
+            }
+
+            // Meta fields
+            $item['file_id']    = $file_id;
+            $item['created_by'] = get_session_userid() ?? null;
+            $item['claim_type'] = isset($row['mainclaim_prepost_type']) && !empty($row['mainclaim_prepost_type']) && strtolower($row['mainclaim_prepost_type']) == 'normal' ? 1 : 3;
+            
+            $mapped[] = $item;
+            
+        }
+
+        return ['mapped_array' => $mapped, 'rejected_reason_array' => $rejecetd_reason];
+    }
+
+
+    /**
+     * HELPER FUNCTIONs 
+     */
+
+    public function isDateValue($value): bool
+    {
+        if (empty($value)) {
+            return false;
+        }
+
+        // Excel numeric date (e.g. 44927)
+        if (is_numeric($value) && $value > 30000) {
+            return true;
+        }
+
+        // Common date formats
+        return preg_match(
+            '/^\d{1,2}[\/\-]\d{1,2}[\/\-]\d{2,4}$|^\d{4}[\/\-]\d{1,2}[\/\-]\d{1,2}$/',
+            (string) $value
+        ) === 1;
+    }
+
+
+    public function normalizeDate($value): ?string
+    {
+        try {
+            // Excel numeric date
+            if (is_numeric($value)) {
+                return date('Y-m-d', \PhpOffice\PhpSpreadsheet\Shared\Date::excelToTimestamp($value));
+            }
+
+            // String date
+            return date('Y-m-d', strtotime(str_replace('/', '-', $value)));
+        } catch (\Throwable $e) {
+            return null;
+        }
+    }
+
+
+    public function looksLikeDate($value): bool
+    {
+        if (empty($value)) {
+            return false;
+        }
+
+        // Excel numeric date
+        if (is_numeric($value) && $value > 30000) {
+            return true;
+        }
+
+        return preg_match(
+            '/\d{1,2}[\/\-]\d{1,2}[\/\-]\d{2,4}|
+         \d{4}[\/\-]\d{1,2}[\/\-]\d{1,2}|
+         \d{1,2}\s?[A-Za-z]{3,}\s?\d{2,4}|
+         \d{8}/x',
+            (string) $value
+        ) === 1;
+    }
+
+
+    public function convertRelation(string $relation, string $gender): ?string
+    {
+        if (empty($relation)) {
+            return null;
+        }
+
+        $relation = strtolower($relation);
+        $gender = strtolower($gender);
+
+        if ($relation == 'self') {
+            return $relation;
+        }
+
+        if ($relation == 'spouse') {
+            return $relation;
+        }
+
+        if ($relation == 'child' && $gender == 'male') {
+            return 'son';
+        }
+
+        if ($relation == 'child' && $gender == 'female') {
+            return 'daughter';
+        }
+
+        if ($relation == 'parents' && $gender == 'male') {
+            return 'father';
+        }
+
+        if ($relation == 'parents' && $gender == 'female') {
+            return 'mother';
+        }
+
+        if ($relation == 'parents-in-law' && $gender == 'male') {
+            return 'father-in-law';
+        }
+
+        if ($relation == 'parents-in-law' && $gender == 'female') {
+            return 'mother-in-law';
+        }
+
+        return null;
+    }
+
+
+    public function getClientPolicyDataBypolicyNo(array $client_policy_data, string $policy_number): array
+    {   
+        $matched_data = [];
+        foreach ($client_policy_data as $key => $value) {
+            if(trim($value) == trim($policy_number)){
+                $matched_data = $value;
+            }
+        }
+
+        if(!empty($matched_data)){
+            $ClientRMModel = new ClientRMModel();
+           $acm_data = $ClientRMModel->where('is_active', 1)->where('level', 3)->where('client_id', $matched_data['client_id'])->orderBy('id', 'asc')->first();
+            if(!empty($acm_data)){
+                $matched_data['acm_id'] = $acm_data['id'] ?? null;
+            }
+        }
+
+        return  $matched_data;
+    }
+
+}
diff --git a/app/Libraries/TpaClaimsImportFactory.php b/app/Libraries/TpaClaimsImportFactory.php
new file mode 100644
index 00000000..baeef074
--- /dev/null
+++ b/app/Libraries/TpaClaimsImportFactory.php
@@ -0,0 +1,37 @@
+ new VidalClaimImportService(),
+            (int) env('ABHI_PRIMARY_KEY_CONSTANT') => new AbhiClaimImportService(),
+            (int) env('MEDI_ASSIST_PRIMARY_KEY_CONSTANT') => new MediAssistClaimImportService(),
+            (int) env('FHPL_PRIMARY_KEY_CONSTANT') => new FhplClaimImportService(),
+            (int) env('R_CARE_PRIMARY_KEY_CONSTANT') => new RcareClaimImportService(),
+            (int) env('ICICI_PRIMARY_KEY_CONSTANT') => new IciciClaimImportService(),
+            default => throw new InvalidArgumentException(
+                "Unsupported TPA ID: {$tpaId}"
+            ),
+        };
+    }
+}
diff --git a/app/Models/ClaimDumpFileModel.php b/app/Models/ClaimDumpFileModel.php
index 224adafc..e34d6116 100644
--- a/app/Models/ClaimDumpFileModel.php
+++ b/app/Models/ClaimDumpFileModel.php
@@ -10,6 +10,9 @@ class ClaimDumpFileModel extends Model
     protected $primaryKey       = 'id';
     protected $allowedFields    = [
         "id",
+        "client_id",
+        "client_policy_id",
+        "tpa_id",
         "file_name",
         "status",
         "reason",
diff --git a/app/Models/ClaimsDumpFhplModel.php b/app/Models/ClaimsDumpFhplModel.php
new file mode 100644
index 00000000..d8cd6632
--- /dev/null
+++ b/app/Models/ClaimsDumpFhplModel.php
@@ -0,0 +1,141 @@
+db->table('client_policy')
-            ->select('client_policy.*')
+            ->select('
+
+                    client_policy.*,
+                    CASE
+                        WHEN client_policy.policy_entry_from = 3
+                            AND client_policy.cd_ac_pk IS NULL
+                        THEN leads.cd_amount
+                        ELSE NULL
+                    END AS lead_cd_amount
+            ', false)
             ->select('insurers.name as insurer_name, insurers.short_name as insurer_short')
             ->select('tpa.name as tpa_name, tpa.short_name as tpa_short')
             ->select('policy_type.policy_type as policy_type_name')
@@ -132,6 +141,7 @@ class ClientPolicyModel extends Model
             ->join('tpa_branch', 'client_policy.tpa_branch_id = tpa_branch.id', 'left')
             ->join('policy_type', 'policy_type.id = client_policy.policy_type_id')
             ->join('client_branch', 'client_branch.id = client_policy.client_branch_id')
+            ->join('leads', 'client_policy.is_from_lead = leads.id', 'left')
             ->where('client_policy.client_id', $client_id)
             // ->where('client_policy.policy_status', 1)
             ->where('client_policy.is_active', 1)
@@ -183,9 +193,14 @@ class ClientPolicyModel extends Model
                             ->join('clients', 'clients.id = client_policy.client_id')
                             ->join('insurers', 'insurers.id = client_policy.insurer_id')
                             ->join('insurer_branch', 'client_policy.insurer_branch_id = insurer_branch.id', 'left')
-                            ->join('cd_master', 'cd_master.insurer_id = insurers.id AND cd_master.client_id = client_policy.client_id')
-                            ->where('client_policy.client_id', $id)
-                            ->where('cd_master.id = client_policy.cd_ac_pk')
+                            ->join('cd_master', 'cd_master.insurer_id = insurers.id AND cd_master.client_id = client_policy.client_id');
+                            // ->where('client_policy.client_id', $id)
+                            if (is_string($id) && preg_match('/^[a-f0-9]{32}$/i', $id)) {
+                                $builder->where('MD5(client_policy.client_id)', $id);
+                            } else {
+                                $builder->where('client_policy.client_id', $id);
+                            }
+                            $builder->where('cd_master.id = client_policy.cd_ac_pk')
                             ->where('cd_master.is_active', 1)
                             ->groupBy('client_policy.client_id')
                             ->groupBy('client_policy.insurer_id')
@@ -248,14 +263,33 @@ class ClientPolicyModel extends Model
     }
 
 
-    public function getClientById($id)
+    // public function getClientById($id)
+    // {
+    //     $query = $this->db->table('clients')->getWhere(['id' => $id]);
+    //     // Debug statement
+    //     return $query->getRow();
+    // }
+
+    public function getClientById($client_id)
     {
-        $query = $this->db->table('clients')->getWhere(['id' => $id]);
-        // Debug statement
-        return $query->getRow();
+        if (empty($client_id)) {
+            return null;
+        }
+
+        $builder = $this->db->table('clients');
+
+        // MD5 vs normal ID check
+        if (is_string($client_id) && preg_match('/^[a-f0-9]{32}$/i', $client_id)) {
+            $builder->where('MD5(id)', $client_id);
+        } else {
+            $builder->where('id', $client_id);
+        }
+
+        return $builder->get()->getRow();
     }
 
 
+
     public function getDepositData($clientId, $insurerId, $cd_ac_pk = null, $subTypeOptions = null)
     {   
 
@@ -285,9 +319,16 @@ class ClientPolicyModel extends Model
             ->join('client_policy', 'client_policy.id = cash_deposit.client_policy_id', 'left')
             ->join('cd_master', 'cd_master.id = cash_deposit.cd_ac_pk', 'left')
             // ->join('policies', 'policies.id = client_policy.policy_id', 'left')
-            ->join('policy_type', 'policy_type.id = client_policy.policy_type_id', 'left')
-            ->where('cash_deposit.client_id', $clientId)
-            ->where('cash_deposit.insurer_id', $insurerId)
+            ->join('policy_type', 'policy_type.id = client_policy.policy_type_id', 'left');
+            // ->where('cash_deposit.client_id', $clientId)
+             if (!empty($clientId)) {
+                if (is_string($clientId) && preg_match('/^[a-f0-9]{32}$/i', $clientId)) {
+                    $query->where('MD5(cash_deposit.client_id)', $clientId);
+                } else {
+                    $query->where('cash_deposit.client_id', $clientId);
+                }
+            }
+            $query->where('cash_deposit.insurer_id', $insurerId)
             ->where('cash_deposit.is_active', 1)
             ->where('cd_master.is_active', 1);
             // ->where('cash_deposit.cd_ac_pk = cd_master.id')
@@ -300,12 +341,56 @@ class ClientPolicyModel extends Model
     }
 
 
+    // public function getDepositSummary($clientId, $insurerId, $cd_ac_pk)
+    // {
+
+    //     $subQuery = $this->db->table('cash_deposit')
+    //         ->select('balance')
+    //         ->where('client_id', $clientId)
+    //         ->where('insurer_id', $insurerId)
+    //         ->where('cd_ac_pk', $cd_ac_pk)
+    //         ->where('is_active', 1)
+    //         ->orderBy('id', 'DESC')
+    //         ->limit(1)
+    //         ->getCompiledSelect();
+
+    //     // Fetch the sum of credit and debit transactions and calculate the balance
+    //     $data = $this->db->table('cash_deposit')
+    //         ->select("($subQuery) AS balance", false)
+    //         ->select('SUM(CASE WHEN transaction_type = "Credit" THEN amount ELSE 0 END) AS total_credit')
+    //         ->select('SUM(CASE WHEN transaction_type = "Debit" THEN amount ELSE 0 END) AS total_withdraw')
+    //         // ->select('SUM(CASE WHEN transaction_type = "Credit" THEN amount ELSE -amount END) AS balance')
+    //         ->select('SUM(CASE WHEN sub_type = 3 THEN amount ELSE 0 END) AS total_refund')
+    //         ->where('client_id', $clientId)
+    //         ->where('insurer_id', $insurerId)
+    //         ->where('cd_ac_pk', $cd_ac_pk)
+    //         ->where('cash_deposit.is_active', 1)
+    //         ->get()
+    //         ->getRow();
+
+    //     // dd($this->db->getLastQuery());
+    //     return $data;
+    // }
+
     public function getDepositSummary($clientId, $insurerId, $cd_ac_pk)
     {
+        if (empty($clientId)) {
+            return null;
+        }
 
+        //  Build SAFE client condition (NO BINDS!)
+        if (is_string($clientId) && preg_match('/^[a-f0-9]{32}$/i', $clientId)) {
+            $clientCondition = 'MD5(client_id) = ' . $this->db->escape($clientId);
+        } else {
+            $clientCondition = 'client_id = ' . $this->db->escape($clientId);
+        }
+
+        /* -------------------------------------------------
+        Subquery: latest balance
+        ------------------------------------------------- */
         $subQuery = $this->db->table('cash_deposit')
             ->select('balance')
-            ->where('client_id', $clientId)
+            ->where($clientCondition, null, false) 
             ->where('insurer_id', $insurerId)
             ->where('cd_ac_pk', $cd_ac_pk)
             ->where('is_active', 1)
@@ -313,14 +398,15 @@ class ClientPolicyModel extends Model
             ->limit(1)
             ->getCompiledSelect();
 
-        // Fetch the sum of credit and debit transactions and calculate the balance
+        /* -------------------------------------------------
+        Main query: totals
+        ------------------------------------------------- */
         $data = $this->db->table('cash_deposit')
             ->select("($subQuery) AS balance", false)
             ->select('SUM(CASE WHEN transaction_type = "Credit" THEN amount ELSE 0 END) AS total_credit')
             ->select('SUM(CASE WHEN transaction_type = "Debit" THEN amount ELSE 0 END) AS total_withdraw')
-            // ->select('SUM(CASE WHEN transaction_type = "Credit" THEN amount ELSE -amount END) AS balance')
             ->select('SUM(CASE WHEN sub_type = 3 THEN amount ELSE 0 END) AS total_refund')
-            ->where('client_id', $clientId)
+            ->where($clientCondition, null, false)
             ->where('insurer_id', $insurerId)
             ->where('cd_ac_pk', $cd_ac_pk)
             ->where('cash_deposit.is_active', 1)
@@ -330,6 +416,8 @@ class ClientPolicyModel extends Model
         // dd($this->db->getLastQuery());
         return $data;
     }
+
+
     // Inside your clientPolicyModel
     // Inside your clientPolicyModel
     // public function getDepositDataWithBalance($clientId, $insurerId)
@@ -402,6 +490,35 @@ class ClientPolicyModel extends Model
         //     ORDER BY cd.id DESC
         // ";
 
+        // $sql = "
+        //     SELECT cd.insurer_id, cd.cd_ac_pk, cd.balance
+        //     FROM cash_deposit cd
+        //     JOIN cd_master cdm ON cdm.id = cd.cd_ac_pk
+        //     JOIN (
+        //         SELECT MAX(id) AS max_id
+        //         FROM cash_deposit
+        //         WHERE is_active = 1 AND client_id = :id:
+        //         GROUP BY insurer_id, cd_ac_pk
+        //     ) latest ON latest.max_id = cd.id
+        //     JOIN insurers on cd.insurer_id = insurers.id
+        //     WHERE cd.is_active = 1 AND cd.client_id = :id: AND cdm.is_active = 1
+        //     ORDER BY cd.insurer_id;
+        // ";
+
+        // $binds = ['id'=>(int)$id];
+        // return $this->db->query($sql,$binds)->getResult();
+
+        $whereClient = 'cd.client_id = :id:';
+        $subWhereClient = 'client_id = :id:';
+
+        $binds = ['id' => $id];
+
+        // 🔐 MD5 handling
+        if (is_string($id) && preg_match('/^[a-f0-9]{32}$/i', $id)) {
+            $whereClient = 'MD5(cd.client_id) = :id:';
+            $subWhereClient = 'MD5(client_id) = :id:';
+        }
+
         $sql = "
             SELECT cd.insurer_id, cd.cd_ac_pk, cd.balance
             FROM cash_deposit cd
@@ -409,16 +526,17 @@ class ClientPolicyModel extends Model
             JOIN (
                 SELECT MAX(id) AS max_id
                 FROM cash_deposit
-                WHERE is_active = 1 AND client_id = :id:
+                WHERE is_active = 1 AND {$subWhereClient}
                 GROUP BY insurer_id, cd_ac_pk
             ) latest ON latest.max_id = cd.id
-            JOIN insurers on cd.insurer_id = insurers.id
-            WHERE cd.is_active = 1 AND cd.client_id = :id: AND cdm.is_active = 1
-            ORDER BY cd.insurer_id;
+            JOIN insurers ON cd.insurer_id = insurers.id
+            WHERE cd.is_active = 1
+            AND {$whereClient}
+            AND cdm.is_active = 1
+            ORDER BY cd.insurer_id
         ";
 
-        $binds = ['id'=>(int)$id];
-        return $this->db->query($sql,$binds)->getResult();
+        return $this->db->query($sql, $binds)->getResult();
 
     }
 
diff --git a/app/Models/EmployeePolicyModel.php b/app/Models/EmployeePolicyModel.php
index 036f2c19..70f0485c 100755
--- a/app/Models/EmployeePolicyModel.php
+++ b/app/Models/EmployeePolicyModel.php
@@ -295,7 +295,10 @@ class EmployeePolicyModel extends Model
             ->orderBy('emp.emp_code', 'ASC')
             ->orderBy('employee_polices.employee_id', 'ASC');
         // Conditionally add where clauses
-        if ($client_id != 0 && !empty($client_id)) {
+        if (is_string($client_id) && preg_match('/^[a-f0-9]{32}$/i', $client_id)) {
+            // MD5 hash → compare using md5()
+            $result->where('md5(emp.client_id)', $client_id);
+        }else if ($client_id != 0 && !empty($client_id)) {
             $result->where('emp.client_id', $client_id);
         }
         if ($branch_id != 0 && !empty($branch_id)) {
diff --git a/app/Models/InsurerModel.php b/app/Models/InsurerModel.php
index dcb7fe8b..d264c231 100755
--- a/app/Models/InsurerModel.php
+++ b/app/Models/InsurerModel.php
@@ -37,27 +37,67 @@ class InsurerModel extends Model
             ->getResult();
     }
 
+    // public function getInsurerName($insurerId, $client_id)
+    // {
+    //     // Fetch the insurer name based on the insurer ID
+    //     $query = $this->db->table('client_policy')
+    //     ->select('insurers.id, insurers.name, cd_master.cd_ac_no as cd_master_account_no')
+    //     ->join('insurers', 'insurers.id = client_policy.insurer_id')
+    //     ->join('cd_master', 'cd_master.insurer_id = insurers.id AND cd_master.client_id = client_policy.client_id')
+    //     ->where('client_policy.insurer_id', $insurerId)
+    //     ->where('client_policy.client_id', $client_id) 
+    //     ->where('cd_master.id = client_policy.cd_ac_pk')
+    //     ->where('cd_master.is_active', 1)
+    //     ->get();
+
+    //     if ($query->resultID->num_rows > 0) {
+    //         $result = $query->getRow();
+    //         return $result;
+    //     }
+
+    //     return null; // or handle accordingly if the insurer is not found
+    // }
+
     public function getInsurerName($insurerId, $client_id)
     {
-        // Fetch the insurer name based on the insurer ID
-        $query = $this->db->table('client_policy')
-        ->select('insurers.id, insurers.name, cd_master.cd_ac_no as cd_master_account_no')
-        ->join('insurers', 'insurers.id = client_policy.insurer_id')
-        ->join('cd_master', 'cd_master.insurer_id = insurers.id AND cd_master.client_id = client_policy.client_id')
-        ->where('client_policy.insurer_id', $insurerId)
-        ->where('client_policy.client_id', $client_id) 
-        ->where('cd_master.id = client_policy.cd_ac_pk')
-        ->where('cd_master.is_active', 1)
-        ->get();
+        $builder = $this->db->table('client_policy')
+            ->select('
+                insurers.id,
+                insurers.name,
+                cd_master.cd_ac_no AS cd_master_account_no
+            ')
+            ->join('insurers', 'insurers.id = client_policy.insurer_id')
+            ->join(
+                'cd_master',
+                'cd_master.insurer_id = insurers.id
+                AND cd_master.client_id = client_policy.client_id
+                AND cd_master.id = client_policy.cd_ac_pk
+                AND cd_master.is_active = 1'
+            )
+            ->where('client_policy.insurer_id', $insurerId);
 
-        if ($query->resultID->num_rows > 0) {
-            $result = $query->getRow();
-            return $result;
+        // Handle raw client_id vs MD5
+        if (!empty($client_id)) {
+            if (is_string($client_id) && preg_match('/^[a-f0-9]{32}$/i', $client_id)) {
+                $builder->where('MD5(client_policy.client_id)', $client_id);
+            } else {
+                $builder->where('client_policy.client_id', $client_id);
+            }
         }
 
-        return null; // or handle accordingly if the insurer is not found
+        $result = $builder
+            ->groupBy([
+                'insurers.id',
+                'cd_master.cd_ac_no'
+            ])
+            ->limit(1)
+            ->get()
+            ->getRow();
+
+        return $result ?? null;
     }
 
+
     public function getInsurerTemplateByInsurerID($insurer_id)
     {
         $insurer_data = $this->db->table('insurer_excel_export_template')
diff --git a/app/Models/PolicyTransactionModel.php b/app/Models/PolicyTransactionModel.php
index 9bd5f0ed..98243549 100644
--- a/app/Models/PolicyTransactionModel.php
+++ b/app/Models/PolicyTransactionModel.php
@@ -2569,8 +2569,10 @@
                         pt.action_type as action_type_string,
 
                         c.client_name,
+                        c.id as client_id,
                         c.short_name AS client_short_name,
                         cb.branch_name AS client_branch_name,
+                        cb.id AS client_branch_id,
                         cb.address1 AS client_address,
                         ptype.policy_type,
                         ptype.bap,
@@ -2578,6 +2580,7 @@
                         ins.name AS insurer_name,
                         ins.short_name AS insurer_short_name,
                         ib.branch_name AS insurer_branch_name,
+                        ib.id AS insurer_branch_id,
                         ib.branch_code AS insurer_branch_code,
 
                         created_user.first_name AS user_name,
@@ -2735,8 +2738,10 @@
                         pt.action_type as action_type_string,
 
                         c.client_name,
+                        c.id as client_id,
                         c.short_name AS client_short_name,
                         cb.branch_name AS client_branch_name,
+                        cb.id AS client_branch_id,
                         cb.address1 AS client_address,
                         ptype.policy_type,
                         ptype.bap,
@@ -2744,6 +2749,7 @@
                         ins.name AS insurer_name,
                         ins.short_name AS insurer_short_name,
                         ib.branch_name AS insurer_branch_name,
+                        ib.id AS insurer_branch_id,
                         ib.branch_code AS insurer_branch_code,
 
                         created_user.first_name as user_name,
@@ -3003,13 +3009,14 @@
 
         public function getBDSReportList($start_date = 0, $end_date = 0, $client_id = 0, $insurer_id = 0, $policy_type_id = 0, $date_type = 0, $issuer = 0, $client_branch_id = 0, $insurer_branch_id = 0, $client_policy_id = 0, $user_id = 0, $where = [])
         {   
-
+            $whereAdded = false;
             $statement_month_condition = '';
             if ($date_type == 'statement_month' && $start_date != 0 && $end_date != 0) {
                 $statement_month_condition = "
                     WHERE statement_month >= '" . $start_date . "'
                     AND statement_month <= '" . $end_date . "'
                 ";
+                $whereAdded = true;
             }
 
             $default_date_filter = '';
@@ -3072,7 +3079,7 @@
             }
 
             if ($insurer_id != 0) {
-                $conditions .= " AND pt.insurer_id = $insurer_id ";
+                $conditions .= " AND pcsd.insurer_id = $insurer_id ";
             }
 
             if ($client_branch_id != 0) {
@@ -3080,7 +3087,7 @@
             }
 
             if ($insurer_branch_id != 0) {
-                $conditions .= " AND pt.insurer_branch_id = $insurer_branch_id ";
+                $conditions .= " AND pcsd.insurer_branch_id = $insurer_branch_id ";
             }
 
             if ($client_policy_id != 0) {
@@ -3099,6 +3106,33 @@
                 $conditions .= " AND pt.issuer = $issuer ";
             }
 
+            $main_conditions = '';
+            function addCondition(&$main_conditions, &$whereAdded, $condition)
+            {
+                if (!$whereAdded) {
+                    $main_conditions .= " WHERE $condition ";
+                    $whereAdded = true;
+                } else {
+                    $main_conditions .= " AND $condition ";
+                }
+            }
+
+            // 4. Common filters
+            if ($client_id != 0) {
+                addCondition($main_conditions, $whereAdded, "client_id = $client_id");
+            }
+
+            if ($insurer_id != 0) {
+                addCondition($main_conditions, $whereAdded, "insurer_id = $insurer_id");
+            }
+
+            if ($client_branch_id != 0) {
+                addCondition($main_conditions, $whereAdded, "client_branch_id = $client_branch_id");
+            }
+
+            if ($insurer_branch_id != 0) {
+                addCondition($main_conditions, $whereAdded, "insurer_branch_id = $insurer_branch_id");
+            }
 
             $sql = "
                 SELECT * FROM (
@@ -3138,8 +3172,10 @@
                         pt.action_type as action_type_string,
 
                         c.client_name,
+                        c.id as client_id,
                         c.short_name AS client_short_name,
                         cb.branch_name AS client_branch_name,
+                        cb.id AS client_branch_id,
                         cb.address1 AS client_address,
                         ptype.policy_type,
                         ptype.bap,
@@ -3147,6 +3183,7 @@
                         ins.name AS insurer_name,
                         ins.short_name AS insurer_short_name,
                         ib.branch_name AS insurer_branch_name,
+                        ib.id AS insurer_branch_id,
                         ib.branch_code AS insurer_branch_code,
 
                         created_user.first_name AS user_name,
@@ -3295,8 +3332,10 @@
                         pt.action_type as action_type_string,
 
                         c.client_name,
+                        c.id as client_id,
                         c.short_name AS client_short_name,
                         cb.branch_name AS client_branch_name,
+                        cb.id AS client_branch_id,
                         cb.address1 AS client_address,
                         ptype.policy_type,
                         ptype.bap,
@@ -3304,6 +3343,7 @@
                         ins.name AS insurer_name,
                         ins.short_name AS insurer_short_name,
                         ib.branch_name AS insurer_branch_name,
+                        ib.id AS insurer_branch_id,
                         ib.branch_code AS insurer_branch_code,
 
                         created_user.first_name as user_name,
@@ -3480,8 +3520,10 @@
                         pt.action_type as action_type_string,
 
                         c.client_name,
+                        c.id as client_id,
                         c.short_name AS client_short_name,
                         cb.branch_name AS client_branch_name,
+                        cb.id AS client_branch_id,
                         cb.address1 AS client_address,
                         ptype.policy_type,
                         ptype.bap,
@@ -3489,6 +3531,7 @@
                         ins.name AS insurer_name,
                         ins.short_name AS insurer_short_name,
                         ib.branch_name AS insurer_branch_name,
+                        ib.id AS insurer_branch_id,
                         ib.branch_code AS insurer_branch_code,
 
                         created_user.first_name as user_name,
@@ -3617,6 +3660,7 @@
                 ) AS final_result
                    
                    $statement_month_condition
+                   $main_conditions
                 -- GROUP BY statement_month, insurer_name, policy_no
                 -- WHERE id = 6143
 
@@ -3632,7 +3676,7 @@
             $result = $query->getResultArray();
             // $countofalldata = count($result);
             // dd($result);
-            // dd($this->db->getLastQuery());
+            dd($this->db->getLastQuery()->getQuery());
 
             $keys     = [];
             $filtered = [];
diff --git a/app/Views/UserList.php b/app/Views/UserList.php
index e1f0f127..28cde270 100755
--- a/app/Views/UserList.php
+++ b/app/Views/UserList.php
@@ -684,7 +684,7 @@ table.dataTable tbody td {
                             
- +
@@ -1134,6 +1134,16 @@ table.dataTable tbody td { console.error("Response Headers:", xhr.getAllResponseHeaders()); console.error("Error Thrown:", error); console.error("Status:", status); + if (xhr.status === 400) { + let response = JSON.parse(xhr.responseText); + if (response.errors) { + $.each(response.errors, function (field, message) { + toastr.warning(message, 'Validation Error'); + }); + } else { + toastr.warning(response.message || 'Validation failed', 'Warning'); + } + }else{toastr.error('Server error occurred.', 'Error');} } }); @@ -1333,7 +1343,16 @@ table.dataTable tbody td { }, error: function(xhr) { console.log("Error: " + xhr.statusText); - toastr.error('Server error occurred.', 'Error'); + if (xhr.status === 400) { + let response = JSON.parse(xhr.responseText); + if (response.errors) { + $.each(response.errors, function (field, message) { + toastr.warning(message, 'Validation Error'); + }); + } else { + toastr.warning(response.message || 'Validation failed', 'Warning'); + } + }else{toastr.error('Server error occurred.', 'Error');} }, complete: function() { btn.disabled = false; @@ -1395,6 +1414,16 @@ table.dataTable tbody td { error: function(xhr) { console.log("Error: " + xhr.statusText); toastr.error('Server error occurred.', 'Error'); + if (xhr.status === 400) { + let response = JSON.parse(xhr.responseText); + if (response.errors) { + $.each(response.errors, function (field, message) { + toastr.warning(message, 'Validation Error'); + }); + } else { + toastr.warning(response.message || 'Validation failed', 'Warning'); + } + }else{toastr.error('Server error occurred.', 'Error');} }, complete: function() { btn.disabled = false; diff --git a/app/Views/add_image_list.php b/app/Views/add_image_list.php index a69924ea..113ce962 100755 --- a/app/Views/add_image_list.php +++ b/app/Views/add_image_list.php @@ -56,7 +56,7 @@ table.dataTable thead th {