Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

[Bug]: Fix crash (Undefined variable $allowed_modules) when employee only has office modules assigned

オープン
#4,681 コメント 2 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 2 日以内に返信

まだ誰も着手していません。

評価

難易度
4/5
見積もり時間
3〜5日
初心者へのやさしさ
52/100
issue の種類
バグ
明瞭さ
おおむね明確
活発さ
停滞
技術スタック
php
領域
backend

調査の方向性

Start by reading app/Views/partial/header.php around line 143 and tracing how the home controller, likely Home.php, supplies $allowed_modules. Reproduce with an employee who has only office permissions, then check the routing and navigation behavior for that permission set. Done means the employee reaches a coherent interface without the undefined-variable crash, with appropriate office navigation.

索引モデルが issue の本文から書いたものです。

説明

bug
🐛 Bug Description

A crash occurs with ErrorException: Undefined variable $allowed_modules in app/Views/partial/header.php on line 143 when a logged-in employee has no modules assigned for the Main Home/Inicio dashboard, but does have permissions for back-office modules under the office section.

📋 Steps to Reproduce
  1. Create or modify an employee's permissions.
  2. Uncheck all standard/home modules (like Sales, Items, Customers) but leave administrative/office modules checked (like Permissions, Store Config).
  3. Log in with this employee account.
  4. The application automatically redirects to /home and crashes because $allowed_modules is never populated or passed to the header view by the controller.
✅ Expected Behavior

Instead of a hard crash due to an uninitialized array variable, the system should handle this permission structure gracefully.

Proposed Elegant Solution

A patch shouldn't just hide the error in the view using an isset() check. Instead, the logical core routing in the controller (likely Home.php) should check if the array is empty.

If the employee has no default home modules but holds at least one active backend permission, the system should automatically inject or fallback to the office module link in the main navigation header. This ensures the user lands on a coherent interface tailored to their back-office role.

📦 OpenSourcePOS Version

OpenSourcePOS 3.4.1

🔧 PHP Version

PHP 8.4

🌐 Browser(s)

Chrome

🖥️ Server Operating System

ubuntu 26.4

🗄️ Database

MySql 8

🌍 Web Server

apache 2.4

📊 System Information Report
Información de la Instalación OSPOS: 3.4.1 - 5f395d
Language Code: es-ES

Extensions & Modules:
» GD: Enabled ✓
» BC Math: Enabled ✓
» INTL: Enabled ✓
» OpenSSL: Enabled ✓
» MBString: Enabled ✓
» Curl: Enabled ✓
» Json: Enabled ✓
» Xml: Enabled ✓

User Configuration:
Browser: Chrome 151.0.0.0
Server Software: Apache/2.4.66 (Ubuntu)
PHP Version: 8.5.4
DB Version: 8.4.11-0ubuntu0.26.04.1
Server Port: 80
OS: Linux 7.0.0-1017-raspi

File Permissions:
» [writeable/logs:] - 0750 | Writable ✓ | Security Check Passed ✓
» [writable/uploads:] - 0755 | Writable ✓ | Vulnerable or Incorrect Permissions ✗
» [writable/uploads/item_pics:] - 0755 | Writable ✓ | Vulnerable or Incorrect Permissions ✗
» [importCustomers.csv:] - 0640 | Readable ✓ | Security Check Passed ✓
📜 Relevant Log Output

📸 Screenshots

No response

✓ Confirmation
  • I certify that this is an unmodified copy of OpenSourcePOS
  • I have searched existing issues to ensure this bug has not already been reported
  • I have provided all the information requested above
主要言語
PHP
スター
4.4k
フォーク
2.6k
平均マージ
2日 21時間
マージ済み PR(30日)
23

環境構築

  • Dockerfile または Docker Compose ファイルあり
  • プルリクエストのテンプレートなし
  • コントリビューションガイドなし

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

opensourcepos/opensourcepos のほかの issue

opensourcepos/opensourcepos の issue をすべて見る

似ている issue

PHP の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。