CGB PRIS
PRIS is a PHP application built on CodeIgniter and Novusoft interfaces for procurement planning, purchase-request tracking, consolidation, approval workflows, reporting, authentication, and JSON integration. It also contains an embedded phpMyAdmin administration surface and bundled PDF, QR-code, template, and framework utilities.
Core capabilities
- Authenticate users through username or login email, active user and role records, password verification, and session establishment.
- Apply module and component permissions to selected application flows and presented actions or fields.
- Manage PPMP planning records, item and account selectors, approval statuses, re-request handling, and BAC-related presentation boundaries.
- Consolidate BMCT and PPMP records, update source items and parent statuses, and write procurement logs.
- Track purchase requests, RFQs, deadlines, linked requests, comments, and office-oriented reporting surfaces.
- Provide declared JSON API operations for login, module metadata, fields, editors, item lists, categories, and expense accounts.
- Compose reusable backend headers, tables, filters, printable views, and PPMP or purchase-request screens.
- Render PDF content through HTML, CSS, SVG, font, block, inline, list, text, and table-layout components.
- Support QR encoding and PNG output through the bundled
QRCode/implementation. - Provide embedded administration operations for SQL execution, database and table management, import/export, privileges, plugins, tracking, server status, themes, templates, and result/error presentation.
Application architecture
The main application follows a front-controller chain declared in index.php:
- Set response headers and resource limits.
- Check the PHP version.
- Establish the application paths.
- Load the path configuration.
- Bootstrap CodeIgniter and the environment-specific boot file when present.
- Load routes and resolve the request.
- Run selected route filters when applicable.
- Initialize and dispatch the controller.
- Complete the response or branch to exception handling.
Routes are declared in Config/Routes.php, with optional environment-specific routes and project-module discovery. Explicit routes and fallback route families are assembled and evaluated in order. Selected filters can run before controller work and after response production; the SPARKED boot variant changes this behavior.
The application configuration under imspr/app/Config defines application URLs, sessions, cookies, logging, database profiles, validation, security settings, and boot variants. Environment-derived values and deployed configuration determine the effective runtime behavior.
Persistence and migrations
The database layer separates:
- Connection selection and storage through
Database::load. - SQL preparation and bind compilation through
Query. - Driver-neutral row and metadata access through
ResultInterface.
The inspected connection implementations include MySQLi and PostgreSQL behavior. Source defaults include MySQLi for the default database group and SQLite3 for the tests group, but deployed connection values must be verified separately.
Migration commands are organized around MigrationRunner and the configured migration history table:
migratemigrate:rollbackmigrate:refreshmigrate:status
Migration discovery occurs before history comparison. Forward migrations are applied before history insertion, while rollback determines direction and target before removing history entries.
Authentication and authorization
The authentication flow verifies credentials against active user and role records, hashes the submitted password with the stored hash key, and stores successful authentication context in the session. Selected module and JSON paths use Startup access checks and permission lookups.
Component authorization determines which actions and fields are presented. Hashed identifiers are decoded into selectors, not ownership checks. The inspected generic component paths do not establish consistent user, tenant, office, role-scope, or record-ownership predicates for reads and writes.
Treat client-side filters, hidden scope fields, visible approval controls, session-presence checks, and presentation predicates as insufficient authorization boundaries unless a separate server-side control is verified.
JSON interface
The declared API controller is imspr/novusoft/modules/Api/Controllers/Api.php, with supporting logic in ApiModel and AuthModel.
The declared route families include:
/api- One-segment paths under
/api - Controller method mappings and auto-routing
The API surface includes login and legacy login behavior, module and field metadata, editor access, item lists, item categories, and expense accounts. The shared JSON output helper returns status 200, permits all origins and request headers, and advertises POST; route declarations do not by themselves prove exclusive HTTP-method enforcement or deployed reachability.
The authentication path has no source-proven throttling, rate limiting, or lockout control.
Procurement workflows
Planning and consolidation
PPMP listings and selectors use combinations of year, department or office, session defaults, role branches, and approval predicates. Consolidation creation performs multi-record updates, including consolidation inserts, source-item updates, parent-status changes, and procurement-log writes.
Deleting a PPMP consolidation is a separate reversal path. Visible delete controls are role-derived presentation gates and do not independently establish handler registration, ownership validation, or successful completion.
Requests, RFQs, and reporting
Purchase-request and RFQ surfaces provide detail retrieval, linked-request expansion, deadline editing, comment forms, and office-oriented reports. Supplied identifiers and selector values are not consistently shown as validated or parameterized, and the inspected queries do not establish office, user, tenant, or equivalent ownership checks.
Several reporting and include-style fragments lack a verified route, caller, registration boundary, or client handler. Treat them as implementation surfaces until their integration is confirmed.
User provisioning
Registration source defines division resolution, credential derivation, user-record assembly, persistence, and JSON-style completion. The inspected flow does not establish a registration-specific route, required-field enforcement, duplicate-user checks, authorization, or validation of submitted values.
Administration surface
The embedded phpMyAdmin code has its own bootstrap and dispatcher, separate from the application router. Its source-defined administration areas include:
- SQL execution and query-result rendering
- Database, table, view, collation, partition, copy, move, rename, drop, and truncate operations
- Database-principal privileges and plugins
- Import and export
- Tracking history and server status
- Themes, Twig templates, RTL assets, and print styles
- Error collection, display, and optional error reporting
Database-principal privilege checks are not equivalent to Novusoft application-session authorization. SQL, import, export, privilege, and tracking operations require deployment-level access controls and database-level review.
PDF and bundled utilities
PDF rendering uses a staged layout pipeline:
- Parse HTML, CSS, and SVG inputs.
- Resolve fonts and binary font tables.
- Build frame decorators and reflowers.
- Reflow block, inline, list-bullet, and text content.
- Normalize tables and calculate cell geometry.
- Handle row groups, page boundaries, splitting, and registered headers.
- Render decorated frames and table borders.
HTML input assumes UTF-8 and requires iconv. SVG handling accepts a caller-supplied filename and should not be treated as an isolated file-access boundary without additional validation.
The bundled QR wrapper in QRCode/index.php decodes a GET parameter and passes its url value to QRcode::png. It is a source-local wrapper rather than a confirmed public API.
public/pdf.php declares a standalone ConvertAPI HTML-to-PDF flow using a fixed external input URL and saveFiles(). Its embedded secret must be replaced with secure secret management before operational use.
Runtime and safety considerations
Verify the deployed environment and effective configuration before relying on source defaults. In particular:
- The configured base URL has separate application and environment-derived declarations.
- Forced HTTPS, secure cookies, HTTP-only cookies, and CSP are declared disabled in the inspected defaults.
- CSRF regeneration and redirect-on-failure are declared enabled, but enforcement depends on the active runtime path.
- The encryption configuration contains a starter-key default that must not be treated as a deployment secret.
- File-based cache keys are used directly in filesystem paths without an inspected allowlist or containment check.
- Public diagnostics include a
phpinfo()script underpublic/novusoft/phpinfo.php. - The maintenance block in
index.phpis commented out and does not establish an active maintenance response. - Shell helpers in
imspr/.ini.phpinclude command execution and network paths capable of relaying socket data tocmd.exeor/bin/sh -i; no sandbox, privilege drop, or process-isolation boundary is established.
Source declarations, route definitions, templates, and command handlers do not by themselves confirm deployment exposure, registration, successful execution, or complete authorization. Validate integration and security boundaries in the target environment before enabling or exposing these surfaces.
Documentation map
- Application Foundation › Runtime Assembly
- Application Foundation › Routes and Filters
- Application Foundation › Configuration
- Application Foundation › Persistence › Database Services
- Application Foundation › Persistence › Migration Operations
- Application Foundation › Persistence › Error Presentation
- Application Foundation › Exception Contracts
- Application Foundation › Platform Services
- Application Foundation › Errors and Diagnostics
- Identity and Integration › Access Control › Authentication Boundary
- Identity and Integration › Access Control › Component Authorization
- Identity and Integration › Integration API › JSON API Contract
- Identity and Integration › Integration API › Public Diagnostics
- Procurement Workflows › Planning Records › PPMP Listings
- Procurement Workflows › Planning Records › Status and Approval
- Procurement Workflows › Consolidation › Consolidation Flow
- Procurement Workflows › Consolidation › Consolidated Lists
- Procurement Workflows › Items and Accounts
- Procurement Workflows › Request Tracking › Requests and RFQs
- Procurement Workflows › Request Tracking › Office Reporting
- Procurement Workflows › User Provisioning
- Novusoft Interfaces › Screen Building › Screen Composition
- Novusoft Interfaces › Screen Building › List Filters
- Novusoft Interfaces › Printable Views
- Database Administration › Administration Core › Administration Boundary
- Database Administration › Administration Core › Privileges and Plugins
- Database Administration › Administration Core › SQL Operations
- Database Administration › Data Movement › Import and Export
- Database Administration › Data Movement › Results and Errors
- Database Administration › Tracking and Status
- Database Administration › Themes and Templates
- PDF Rendering › Layout Pipeline › Frame Decoration
- PDF Rendering › Layout Pipeline › Flow Content
- PDF Rendering › Table Layout
- PDF Rendering › Document Inputs › Document Inputs
- PDF Rendering › Document Inputs › Font Files
- Bundled Utilities › QR Code Support
- Bundled Utilities › Framework Support › Escaping and Inspection
- Bundled Utilities › Framework Support › View Parsing
- Bundled Utilities › Standalone PDF Conversion
- Bundled Utilities › Unresolved Shell Code
- Novusoft Interface Surfaces › Screen Composition
Updated