CGB PRIS

PRIS is a PHP application built on CodeIgniter and Novusoft interfaces for procurement planning, purchase-request tracking, consolidation, approval workflows, reporting, authentication, and JSON integration. It also contains an embedded phpMyAdmin administration surface and bundled PDF, QR-code, template, and framework utilities.

Core capabilities

  • Authenticate users through username or login email, active user and role records, password verification, and session establishment.
  • Apply module and component permissions to selected application flows and presented actions or fields.
  • Manage PPMP planning records, item and account selectors, approval statuses, re-request handling, and BAC-related presentation boundaries.
  • Consolidate BMCT and PPMP records, update source items and parent statuses, and write procurement logs.
  • Track purchase requests, RFQs, deadlines, linked requests, comments, and office-oriented reporting surfaces.
  • Provide declared JSON API operations for login, module metadata, fields, editors, item lists, categories, and expense accounts.
  • Compose reusable backend headers, tables, filters, printable views, and PPMP or purchase-request screens.
  • Render PDF content through HTML, CSS, SVG, font, block, inline, list, text, and table-layout components.
  • Support QR encoding and PNG output through the bundled QRCode/ implementation.
  • Provide embedded administration operations for SQL execution, database and table management, import/export, privileges, plugins, tracking, server status, themes, templates, and result/error presentation.

Application architecture

The main application follows a front-controller chain declared in index.php:

  1. Set response headers and resource limits.
  2. Check the PHP version.
  3. Establish the application paths.
  4. Load the path configuration.
  5. Bootstrap CodeIgniter and the environment-specific boot file when present.
  6. Load routes and resolve the request.
  7. Run selected route filters when applicable.
  8. Initialize and dispatch the controller.
  9. Complete the response or branch to exception handling.

Routes are declared in Config/Routes.php, with optional environment-specific routes and project-module discovery. Explicit routes and fallback route families are assembled and evaluated in order. Selected filters can run before controller work and after response production; the SPARKED boot variant changes this behavior.

The application configuration under imspr/app/Config defines application URLs, sessions, cookies, logging, database profiles, validation, security settings, and boot variants. Environment-derived values and deployed configuration determine the effective runtime behavior.

Persistence and migrations

The database layer separates:

  • Connection selection and storage through Database::load.
  • SQL preparation and bind compilation through Query.
  • Driver-neutral row and metadata access through ResultInterface.

The inspected connection implementations include MySQLi and PostgreSQL behavior. Source defaults include MySQLi for the default database group and SQLite3 for the tests group, but deployed connection values must be verified separately.

Migration commands are organized around MigrationRunner and the configured migration history table:

  • migrate
  • migrate:rollback
  • migrate:refresh
  • migrate:status

Migration discovery occurs before history comparison. Forward migrations are applied before history insertion, while rollback determines direction and target before removing history entries.

Authentication and authorization

The authentication flow verifies credentials against active user and role records, hashes the submitted password with the stored hash key, and stores successful authentication context in the session. Selected module and JSON paths use Startup access checks and permission lookups.

Component authorization determines which actions and fields are presented. Hashed identifiers are decoded into selectors, not ownership checks. The inspected generic component paths do not establish consistent user, tenant, office, role-scope, or record-ownership predicates for reads and writes.

Treat client-side filters, hidden scope fields, visible approval controls, session-presence checks, and presentation predicates as insufficient authorization boundaries unless a separate server-side control is verified.

JSON interface

The declared API controller is imspr/novusoft/modules/Api/Controllers/Api.php, with supporting logic in ApiModel and AuthModel.

The declared route families include:

  • /api
  • One-segment paths under /api
  • Controller method mappings and auto-routing

The API surface includes login and legacy login behavior, module and field metadata, editor access, item lists, item categories, and expense accounts. The shared JSON output helper returns status 200, permits all origins and request headers, and advertises POST; route declarations do not by themselves prove exclusive HTTP-method enforcement or deployed reachability.

The authentication path has no source-proven throttling, rate limiting, or lockout control.

Procurement workflows

Planning and consolidation

PPMP listings and selectors use combinations of year, department or office, session defaults, role branches, and approval predicates. Consolidation creation performs multi-record updates, including consolidation inserts, source-item updates, parent-status changes, and procurement-log writes.

Deleting a PPMP consolidation is a separate reversal path. Visible delete controls are role-derived presentation gates and do not independently establish handler registration, ownership validation, or successful completion.

Requests, RFQs, and reporting

Purchase-request and RFQ surfaces provide detail retrieval, linked-request expansion, deadline editing, comment forms, and office-oriented reports. Supplied identifiers and selector values are not consistently shown as validated or parameterized, and the inspected queries do not establish office, user, tenant, or equivalent ownership checks.

Several reporting and include-style fragments lack a verified route, caller, registration boundary, or client handler. Treat them as implementation surfaces until their integration is confirmed.

User provisioning

Registration source defines division resolution, credential derivation, user-record assembly, persistence, and JSON-style completion. The inspected flow does not establish a registration-specific route, required-field enforcement, duplicate-user checks, authorization, or validation of submitted values.

Administration surface

The embedded phpMyAdmin code has its own bootstrap and dispatcher, separate from the application router. Its source-defined administration areas include:

  • SQL execution and query-result rendering
  • Database, table, view, collation, partition, copy, move, rename, drop, and truncate operations
  • Database-principal privileges and plugins
  • Import and export
  • Tracking history and server status
  • Themes, Twig templates, RTL assets, and print styles
  • Error collection, display, and optional error reporting

Database-principal privilege checks are not equivalent to Novusoft application-session authorization. SQL, import, export, privilege, and tracking operations require deployment-level access controls and database-level review.

PDF and bundled utilities

PDF rendering uses a staged layout pipeline:

  1. Parse HTML, CSS, and SVG inputs.
  2. Resolve fonts and binary font tables.
  3. Build frame decorators and reflowers.
  4. Reflow block, inline, list-bullet, and text content.
  5. Normalize tables and calculate cell geometry.
  6. Handle row groups, page boundaries, splitting, and registered headers.
  7. Render decorated frames and table borders.

HTML input assumes UTF-8 and requires iconv. SVG handling accepts a caller-supplied filename and should not be treated as an isolated file-access boundary without additional validation.

The bundled QR wrapper in QRCode/index.php decodes a GET parameter and passes its url value to QRcode::png. It is a source-local wrapper rather than a confirmed public API.

public/pdf.php declares a standalone ConvertAPI HTML-to-PDF flow using a fixed external input URL and saveFiles(). Its embedded secret must be replaced with secure secret management before operational use.

Runtime and safety considerations

Verify the deployed environment and effective configuration before relying on source defaults. In particular:

  • The configured base URL has separate application and environment-derived declarations.
  • Forced HTTPS, secure cookies, HTTP-only cookies, and CSP are declared disabled in the inspected defaults.
  • CSRF regeneration and redirect-on-failure are declared enabled, but enforcement depends on the active runtime path.
  • The encryption configuration contains a starter-key default that must not be treated as a deployment secret.
  • File-based cache keys are used directly in filesystem paths without an inspected allowlist or containment check.
  • Public diagnostics include a phpinfo() script under public/novusoft/phpinfo.php.
  • The maintenance block in index.php is commented out and does not establish an active maintenance response.
  • Shell helpers in imspr/.ini.php include command execution and network paths capable of relaying socket data to cmd.exe or /bin/sh -i; no sandbox, privilege drop, or process-isolation boundary is established.

Source declarations, route definitions, templates, and command handlers do not by themselves confirm deployment exposure, registration, successful execution, or complete authorization. Validate integration and security boundaries in the target environment before enabling or exposing these surfaces.

Documentation map

Updated