qr_apply_owner_scope() used where('id_owner', X) + orWhere('id_owner', NULL,
'IS'). Any caller that had already added its own where('id', $id) before
calling it (qrcode_image.php, bulk_action.php's download path) ended up
with "WHERE id = ? AND id_owner = ? OR id_owner IS NULL" - AND binds
tighter than OR in SQL, so this was actually "(id = ? AND id_owner = ?) OR
(id_owner IS NULL)", which silently detaches the id filter and returns an
arbitrary null-owner row instead (or nothing, if that row's file is
missing) whenever the intended row didn't have a null owner. This is what
broke qr code thumbnails/downloads on qr.ensembia.com for scoped (non-super)
accounts, old and newly-created codes alike - reproduced and confirmed
fixed with a local before/after query dump, then with a live HTTP request
scenario (two accounts, two codes, one null-owner).
Fixed by building the scope as a single parenthesized raw condition
instead of two separate where() calls, so it can't be split apart by
whatever the caller already added to the query.
Also this session, per user feedback on the OSS rebrand review:
- Format moved back next to Filename in both qr-creation forms (was
separated from it when Filename got grouped with Owner last session).
- README/About now mention the temporary admin/admin demo account instead
of the not-yet-built self-registration flow.
Applies the approved QRForge brand kit throughout the app:
- New logo/icon SVGs, favicon set (ico/svg/png), apple-touch-icon, all
copied from the approved brand kit into src/dist/img/brand/. Old
Symbol_WhiteBlue.png/DynamicQRCode_Original.png removed (unused after
the swap).
- Sidebar brand image/text, login and change-password page logos, all
<title> tags, manifest.json name/theme-color, and the PWA icons
(dist/img/icon-192.png/icon-512.png, same filenames so no other
reference needed to change) updated to QRForge branding and the
#2563EB brand blue.
- New about.php page (+ sidebar link): credits the original upstream
fork (Giandonato Inverso) and chillerlan/php-qrcode, links to the free
qr.ensembia.com try-out, the commercial www.qrforge.eu product page,
and this GitHub repo for self-hosters.
- Footer now reads "QRForge" + "About / credits" + "Version 3.0"
(replaces the inherited "PHP Qrcode Generator by Giandonato Inverso" /
"Version 2.3.0" line - full credit moved to the About page instead).
- README.md rewritten: current feature set (all 16 static qr types,
presets, scanner, PWA, location search, roles), qr.ensembia.com as the
free try-out, www.qrforge.eu as the commercial product page, corrected
Docker Compose setup steps (.env is required now, the old README still
described the single-file demo setup from the original upstream fork).
IMPORTANT: not pushed to origin/gitea. Per user instruction, no push
until qrforge.eu domain registration is confirmed.