# StockFlow implementation log

## 2026-09-28 — Ver2 reporting and debt foundation

- Switched delivery work to branch `ver2` and recorded the implementation roadmap in `ROADMAP.md`.
- Added the stock-balance report with opening, imports, exports, transfers, adjustments, closing, physical count and variance, including date, warehouse, product and category filters.
- Added receivable and payable reports with opening/period/closing debit-credit columns, partner/category views, Vietnamese report categories and safe decimal money aggregation.
- Added opening-balance and debt-ledger tables, validation, draft/confirmed/cancelled workflow and APIs. Existing issued VAT invoices are included as trade debt; manual opening balances, payments and adjustments remain explicit entries.
- Added optional opening-balance dimensions for Chương/Loại/Khoản/Mục so the opening-debt report can follow the supplied accounting form.
- Fixed report money fallbacks to use receipt detail `unit_price` when legacy price columns are empty, and aligned top-exported-product filtering with `transaction_date`.
- Added cPanel deployment runbook, Apache SPA fallback, portable migration commands and production environment requirements.
- Added production configuration validation for database/JWT/CORS settings, removed local `.env` files from Git tracking, restricted CORS by `CORS_ORIGIN`, and upgraded bcrypt/Express dependency locks to audited versions.

## 2026-09-23

- Replaced the fresh-install schema and seed with the verified full StockFlow document model.
- Added `002_align_full_stockflow_schema.sql` for existing databases, preserving current rows while adding customers, transfers, adjustments, VAT and stock-card views.
- Added APIs for transfers, stock adjustments, VAT lookup and stock-card lookup.
- Added the warehouse operations screen with responsive tabbed views for transfer, adjustment, VAT and stock-card workflows.
- Completed multi-line transfer/adjustment entry and added confirm/cancel actions for draft documents.
- Backed up the live local database and normalized legacy stock-check statuses to `CONFIRMED`.
- Replaced invalid demo password placeholders in the seed and live local users with valid bcrypt hashes; verified login and new document endpoints.
- Fixed export receipt persistence to use the verified `reason` column and verified transfer, adjustment and insufficient-stock rollback behavior on a cloned database.
- Added customer CRUD API and integrated customers into the master-data screen; verified create, update and delete flows.
- Added VAT draft create/update, issue/cancel APIs and a VAT entry form with source receipt linking; verified the workflow on a cloned database.
- Restricted stock-affecting confirmation to admins, added transfer/adjustment detail endpoints, and verified staff receives HTTP 403 while admins can approve.
- Added a detail modal for transfer, adjustment and VAT documents; double-clicking a row loads header and detail lines from the API.
- Added warehouse/date filters to Dashboard API and UI, fixed MySQL 9 collation handling, and added keyboard focus/reduced-motion accessibility defaults.
- Added paginated product and inventory endpoints with page controls in both list screens; verified page metadata against live data.
- Updated unit management to write the required `unit_code` and `symbol` fields.
- Replaced sidebar character icons with inline SVG icons and added accessible labels for navigation controls.
- Added route-level lazy loading with an accessible loading state; the initial JavaScript chunk is now about 236 kB before gzip, with heavy pages loaded separately.
- Added the shared `StatusBadge` component and localized status labels for master data and stock-check workflows.
- Refactored the reports screen and localized inventory status badges there while preserving all existing report filters and endpoints.
- Localized the status badge in transfer, adjustment and VAT detail modals while preserving the original status code for styling and actions.
- Added `audit_logs` schema/migration, automatic successful write-operation logging with sensitive-field redaction, and the admin-only paginated `/api/audit-logs` endpoint.
- Applied `003_add_audit_logs.sql` to the live `stockflow_db`; verified the audit-log endpoint with the admin account.
- Added `scripts/db-backup.sh` and `scripts/db-restore.sh`, npm shortcuts, and production backup/restore guidance; verified a live compressed backup on September 23, 2026 with `gzip -t`.
- Added the canonical repository ERD at `docs/stockflow_erd.md`, synchronized migration documentation, and generated the visually verified updated plan document at `docs/StockFlow_Ke_Hoach_Cai_Tien_UIUX_cap_nhat.docx`.
- Added `scripts/api-smoke-test.sh`, root npm smoke-test commands, and documentation for API permission/pagination checks without creating new business data.
- Added MySQL-aware `/health`, request ID propagation, structured backend error logs, and production monitoring guidance for transaction/API failures.
