Index: server.js
===================================================================
--- server.js	(revision 4dff800e0e61b01aeb1b15846b32fb42aed69027)
+++ server.js	(revision 79fff4f76fca5f42403a3ec1f9b04e1e66fd372d)
@@ -10,4 +10,5 @@
 
 const port = process.env.PORT || 3000;
+
 const sessions = new Map();
 const verificationCodes = new Map();
@@ -31,5 +32,7 @@
         }
     };
+
     emailTransporter = nodemailer.createTransport(emailConfig);
+
     emailTransporter.verify(function(error, success) {
         if (error) {
@@ -52,4 +55,5 @@
                 const codeMatch = mailOptions.html.match(/\b\d{6}\b/);
                 const code = codeMatch ? codeMatch[0] : 'unknown';
+
                 console.log('');
                 console.log('🎯 ===== VERIFICATION CODE =====');
@@ -60,4 +64,5 @@
                 console.log('================================');
                 console.log('');
+
                 resolve({ messageId: 'dev-' + Date.now() });
             });
@@ -932,7 +937,7 @@
                     }
                     rolesInserted++;
+
                     if (rolesInserted === roles.length) {
                         console.log('✅ Roles inserted');
-
                         // Create admin user with ID 000000
                         createAdminUser();
@@ -1151,4 +1156,5 @@
                 // Check if store owner or employee
                 const personalId = userId.replace('personal_', '');
+
                 database.database.get(
                     'SELECT boss_id FROM boss WHERE boss_id = ?',
@@ -1201,5 +1207,4 @@
             body += chunk.toString();
         });
-
         req.on('end', () => {
             const { username, email, password, userType, firstName, lastName } = JSON.parse(body);
@@ -1266,5 +1271,4 @@
                             console.log('✅ Verification email sent to:', email);
                             database.logAudit(null, 'REGISTER_ATTEMPT', 'user', null, `Registration attempt for ${email} as ${userType}`, ipAddress);
-
                             res.writeHead(200, { 'Content-Type': 'application/json' });
                             res.end(JSON.stringify({
@@ -1294,5 +1298,4 @@
             body += chunk.toString();
         });
-
         req.on('end', () => {
             const formData = JSON.parse(body);
@@ -1325,4 +1328,5 @@
 
             const emailRegex = /^[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\.[a-zA-Z]{2,}$/;
+
             if (!emailRegex.test(formData.ownerEmail)) {
                 res.writeHead(400, { 'Content-Type': 'application/json' });
@@ -1406,4 +1410,5 @@
                                 // Next store number is max + 1, starting from 1 if no stores exist
                                 let nextStoreNumber = 1;
+
                                 if (result && result.max_store_num) {
                                     // Extract numeric part from store_id (format: XXX)
@@ -1461,5 +1466,4 @@
                                         console.log('✅ Store registration email sent to:', formData.ownerEmail);
                                         database.logAudit(null, 'STORE_REGISTER_ATTEMPT', 'store', null, `Store registration attempt: ${formData.storeName}`, ipAddress);
-
                                         res.writeHead(200, { 'Content-Type': 'application/json' });
                                         res.end(JSON.stringify({
@@ -1494,5 +1498,4 @@
             body += chunk.toString();
         });
-
         req.on('end', () => {
             const { firstName, lastName, email, password, address, city, postcode, country, isDefaultAddress } = JSON.parse(body);
@@ -1559,5 +1562,4 @@
                         console.log('✅ Verification email sent to:', email);
                         database.logAudit(null, 'CLIENT_REGISTER_ATTEMPT', 'client', null, `Client registration attempt for ${email}`, ipAddress);
-
                         res.writeHead(200, { 'Content-Type': 'application/json' });
                         res.end(JSON.stringify({
@@ -1586,5 +1588,4 @@
             body += chunk.toString();
         });
-
         req.on('end', () => {
             const { email } = JSON.parse(body);
@@ -1721,5 +1722,4 @@
             body += chunk.toString();
         });
-
         req.on('end', () => {
             const { email, code } = JSON.parse(body);
@@ -1793,4 +1793,5 @@
                                         database.database.run('ROLLBACK');
                                         console.error('Error inserting personal:', err);
+
                                         if (err.code === '23505') {
                                             res.writeHead(400, { 'Content-Type': 'application/json' });
@@ -1841,36 +1842,54 @@
                                                             }
 
-                                                            database.database.run('COMMIT', (commitErr) => {
-                                                                if (commitErr) {
-                                                                    console.error('Error committing transaction:', commitErr);
-                                                                    database.database.run('ROLLBACK');
-                                                                    res.writeHead(500, { 'Content-Type': 'application/json' });
-                                                                    res.end(JSON.stringify({ success: false, message: 'Error completing registration' }));
-                                                                    return;
+                                                            // Also create entry in users table for login with force_password_change = 1
+                                                            database.database.run(
+                                                                'INSERT INTO users (id, username, email, password, user_type, force_password_change) VALUES (?, ?, ?, ?, ?, ?)',
+                                                                [
+                                                                    tempStoreData.personalId,
+                                                                    `${tempStoreData.ownerFirstName} ${tempStoreData.ownerLastName}`,
+                                                                    tempStoreData.ownerEmail,
+                                                                    bcrypt.hashSync(tempStoreData.password, 10),
+                                                                    'store_owner',
+                                                                    1
+                                                                ],
+                                                                (err) => {
+                                                                    if (err) {
+                                                                        console.error('Error creating user entry for store owner:', err);
+                                                                    }
+
+                                                                    database.database.run('COMMIT', (commitErr) => {
+                                                                        if (commitErr) {
+                                                                            console.error('Error committing transaction:', commitErr);
+                                                                            database.database.run('ROLLBACK');
+                                                                            res.writeHead(500, { 'Content-Type': 'application/json' });
+                                                                            res.end(JSON.stringify({ success: false, message: 'Error completing registration' }));
+                                                                            return;
+                                                                        }
+
+                                                                        tempStoreRegistrations.delete(code);
+                                                                        verificationCodes.delete(email);
+
+                                                                        console.log(`✅ Store registration completed successfully:`);
+                                                                        console.log(`   Store ID: ${tempStoreData.storeId}`);
+                                                                        console.log(`   Store Name: ${tempStoreData.storeName}`);
+                                                                        console.log(`   Personal ID: ${tempStoreData.personalId}`);
+                                                                        console.log(`   Owner: ${tempStoreData.ownerFirstName} ${tempStoreData.ownerLastName}`);
+
+                                                                        database.logAudit(tempStoreData.personalId, 'STORE_REGISTER_SUCCESS', 'store', tempStoreData.storeId, `Store registered: ${tempStoreData.storeName}`, ipAddress);
+
+                                                                        res.writeHead(200, { 'Content-Type': 'application/json' });
+                                                                        res.end(JSON.stringify({
+                                                                            success: true,
+                                                                            message: 'Store registration successful! You can now login.',
+                                                                            storeId: tempStoreData.storeId,
+                                                                            storeIdPadded: tempStoreData.storeIdPadded,
+                                                                            storeName: tempStoreData.storeName,
+                                                                            personalId: tempStoreData.personalId,
+                                                                            userType: 'store_owner',
+                                                                            redirectTo: 'login.html'
+                                                                        }));
+                                                                    });
                                                                 }
-
-                                                                tempStoreRegistrations.delete(code);
-                                                                verificationCodes.delete(email);
-
-                                                                console.log(`✅ Store registration completed successfully:`);
-                                                                console.log(`   Store ID: ${tempStoreData.storeId}`);
-                                                                console.log(`   Store Name: ${tempStoreData.storeName}`);
-                                                                console.log(`   Personal ID: ${tempStoreData.personalId}`);
-                                                                console.log(`   Owner: ${tempStoreData.ownerFirstName} ${tempStoreData.ownerLastName}`);
-
-                                                                database.logAudit(tempStoreData.personalId, 'STORE_REGISTER_SUCCESS', 'store', tempStoreData.storeId, `Store registered: ${tempStoreData.storeName}`, ipAddress);
-
-                                                                res.writeHead(200, { 'Content-Type': 'application/json' });
-                                                                res.end(JSON.stringify({
-                                                                    success: true,
-                                                                    message: 'Store registration successful! You can now login.',
-                                                                    storeId: tempStoreData.storeId,
-                                                                    storeIdPadded: tempStoreData.storeIdPadded,
-                                                                    storeName: tempStoreData.storeName,
-                                                                    personalId: tempStoreData.personalId,
-                                                                    userType: 'store_owner',
-                                                                    redirectTo: 'login.html'
-                                                                }));
-                                                            });
+                                                            );
                                                         }
                                                     );
@@ -1952,4 +1971,5 @@
             } else {
                 const userId = 'user_' + Date.now().toString().slice(-8);
+
                 database.createUser(userId, tempUserData.username, tempUserData.email, tempUserData.password, tempUserData.userType, (err, userId) => {
                     if (err) {
@@ -1982,5 +2002,4 @@
             body += chunk.toString();
         });
-
         req.on('end', () => {
             const { email, password } = JSON.parse(body);
@@ -2003,5 +2022,4 @@
 
                         const twoFACode = generateVerificationCode();
-
                         verificationCodes.set(adminUser.email, {
                             code: twoFACode,
@@ -2048,4 +2066,5 @@
                     }
                 });
+
                 return;
             }
@@ -2094,4 +2113,5 @@
                             'Set-Cookie': `sessionId=${sessionId}; HttpOnly; Path=/; Max-Age=3600; SameSite=Strict`
                         });
+
                         res.end(JSON.stringify({
                             success: true,
@@ -2155,5 +2175,4 @@
 
                                                 const twoFACode = generateVerificationCode();
-
                                                 verificationCodes.set(personal.email, {
                                                     code: twoFACode,
@@ -2216,5 +2235,4 @@
 
                                                         const twoFACode = generateVerificationCode();
-
                                                         verificationCodes.set(personal.email, {
                                                             code: twoFACode,
@@ -2278,5 +2296,4 @@
 
                                                                 const twoFACode = generateVerificationCode();
-
                                                                 verificationCodes.set(userByUsername.email, {
                                                                     code: twoFACode,
@@ -2329,5 +2346,4 @@
 
                                                         const twoFACode = generateVerificationCode();
-
                                                         verificationCodes.set(user.email, {
                                                             code: twoFACode,
@@ -2396,5 +2412,4 @@
             body += chunk.toString();
         });
-
         req.on('end', () => {
             const { email } = JSON.parse(body);
@@ -2419,5 +2434,4 @@
 
                             const newTwoFACode = generateVerificationCode();
-
                             verificationCodes.set(userByUsername.email, {
                                 code: newTwoFACode,
@@ -2456,5 +2470,4 @@
 
                     const newTwoFACode = generateVerificationCode();
-
                     verificationCodes.set(user.email, {
                         code: newTwoFACode,
@@ -2497,5 +2510,4 @@
             body += chunk.toString();
         });
-
         req.on('end', () => {
             const { email, code } = JSON.parse(body);
@@ -2532,8 +2544,21 @@
                 verificationCodes.delete(email);
 
+                // Determine redirect based on user type
+                let redirectTo = 'change-password.html?forced=true';
+                if (verificationData.userType === 'store_owner') {
+                    redirectTo = 'change-password.html?forced=true&redirect=store-owner.html';
+                } else if (verificationData.userType === 'store_employee') {
+                    redirectTo = 'change-password.html?forced=true&redirect=store-employee.html';
+                } else if (verificationData.userType === 'admin') {
+                    redirectTo = 'change-password.html?forced=true&redirect=admin.html';
+                } else if (verificationData.userType === 'client') {
+                    redirectTo = 'change-password.html?forced=true&redirect=client-dashboard.html';
+                }
+
                 res.writeHead(200, {
                     'Content-Type': 'application/json',
                     'Set-Cookie': `sessionId=${tempSessionId}; HttpOnly; Path=/; Max-Age=3600; SameSite=Strict`
                 });
+
                 res.end(JSON.stringify({
                     success: true,
@@ -2541,5 +2566,5 @@
                     requiresPasswordChange: true,
                     userType: verificationData.userType,
-                    redirectTo: 'change-password.html?forced=true'
+                    redirectTo: redirectTo
                 }));
 
@@ -2590,4 +2615,5 @@
                 'Set-Cookie': `sessionId=${sessionId}; HttpOnly; Path=/; Max-Age=3600; SameSite=Strict`
             });
+
             res.end(JSON.stringify({
                 success: true,
@@ -2616,4 +2642,5 @@
             'Set-Cookie': 'sessionId=; HttpOnly; Path=/; Expires=Thu, 01 Jan 1970 00:00:00 GMT; SameSite=Strict'
         });
+
         res.end(JSON.stringify({ success: true, message: 'Successfully logged out' }));
     }
@@ -2736,5 +2763,4 @@
                 });
             }
-
             else if (userIdStr.startsWith('personal_')) {
                 const personalId = userIdStr.replace('personal_', '');
@@ -2885,5 +2911,4 @@
                 body += chunk.toString();
             });
-
             req.on('end', () => {
                 const categoryData = JSON.parse(body);
@@ -2968,5 +2993,4 @@
                 body += chunk.toString();
             });
-
             req.on('end', () => {
                 const orderData = JSON.parse(body);
@@ -3066,5 +3090,4 @@
                 body += chunk.toString();
             });
-
             req.on('end', () => {
                 const reviewData = JSON.parse(body);
@@ -3073,5 +3096,4 @@
                 if (userIdStr.startsWith('client_')) {
                     const clientId = parseInt(userIdStr.replace('client_', ''));
-
                     reviewData.client_id = clientId;
 
@@ -3100,5 +3122,4 @@
                 body += chunk.toString();
             });
-
             req.on('end', () => {
                 const requestData = JSON.parse(body);
@@ -3170,5 +3191,4 @@
                 body += chunk.toString();
             });
-
             req.on('end', () => {
                 const refundData = JSON.parse(body);
@@ -3240,5 +3260,4 @@
                 body += chunk.toString();
             });
-
             req.on('end', () => {
                 const productData = JSON.parse(body);
@@ -3333,5 +3352,4 @@
                 body += chunk.toString();
             });
-
             req.on('end', () => {
                 const productData = JSON.parse(body);
@@ -3427,4 +3445,5 @@
     }
 
+    // Updated /api/force-change-password endpoint with redirect handling
     else if (pathname === '/api/force-change-password' && req.method === 'POST') {
         const cookies = parseCookies(req);
@@ -3439,12 +3458,10 @@
 
         let body = '';
-
         req.on('data', chunk => {
             body += chunk.toString();
         });
-
         req.on('end', () => {
             try {
-                const { newPassword, confirmPassword } = JSON.parse(body);
+                const { newPassword, confirmPassword, redirectTo } = JSON.parse(body);
 
                 if (!newPassword || !confirmPassword) {
@@ -3508,20 +3525,30 @@
                                 // Create new permanent session
                                 const newSessionId = generateSessionId();
-                                sessions.set(newSessionId, String(userId));
-
-                                // Determine redirect based on user type
-                                let redirectTo = 'dashboard.html';
-
-                                if (user.username === 'admin' || user.user_type === 'admin') {
-                                    redirectTo = 'admin.html';
-                                } else if (user.user_type === 'store_owner') {
-                                    redirectTo = 'store-owner.html';
-                                } else if (user.user_type === 'store_employee') {
-                                    redirectTo = 'store-employee.html';
-                                } else if (user.user_type === 'client') {
-                                    redirectTo = 'client-dashboard.html';
+
+                                // Determine how to store the user ID based on user type
+                                let sessionUserId = String(userId);
+
+                                if (user.user_type === 'store_owner' || user.user_type === 'store_employee') {
+                                    sessionUserId = `personal_${userId}`;
                                 }
 
-                                console.log(`Password changed successfully for user ${userId}, redirecting to ${redirectTo}`);
+                                sessions.set(newSessionId, sessionUserId);
+
+                                // Determine redirect based on user type or provided redirectTo
+                                let finalRedirect = redirectTo || 'dashboard.html';
+
+                                if (!redirectTo) {
+                                    if (user.username === 'admin' || user.user_type === 'admin') {
+                                        finalRedirect = 'admin.html';
+                                    } else if (user.user_type === 'store_owner') {
+                                        finalRedirect = 'store-owner.html';
+                                    } else if (user.user_type === 'store_employee') {
+                                        finalRedirect = 'store-employee.html';
+                                    } else if (user.user_type === 'client') {
+                                        finalRedirect = 'client-dashboard.html';
+                                    }
+                                }
+
+                                console.log(`Password changed successfully for user ${userId}, redirecting to ${finalRedirect}`);
 
                                 database.logAudit(userId, 'FORCED_PASSWORD_CHANGE', 'auth', userId.toString(),
@@ -3531,10 +3558,11 @@
                                 res.writeHead(200, {
                                     'Content-Type': 'application/json',
-                                    'Set-Cookie': `sessionId=${newSessionId}; HttpOnly; Path=/; Max-Age=3600; SameSite=Strict`
+                                    'Set-Cookie': `sessionId=${newSessionId}; HttpOnly; Path=/; Max-Age=86400; SameSite=Strict` // Extended to 24 hours
                                 });
+
                                 res.end(JSON.stringify({
                                     success: true,
                                     message: 'Password changed successfully.',
-                                    redirectTo: redirectTo,
+                                    redirectTo: finalRedirect,
                                     userType: user.user_type || 'user'
                                 }));
@@ -3584,9 +3612,9 @@
                                             (err, boss) => {
                                                 let userType = 'store_employee';
-                                                let redirectTo = 'store-employee.html';
+                                                let finalRedirect = redirectTo || 'store-employee.html';
 
                                                 if (boss) {
                                                     userType = 'store_owner';
-                                                    redirectTo = 'store-owner.html';
+                                                    finalRedirect = redirectTo || 'store-owner.html';
                                                 }
 
@@ -3594,22 +3622,23 @@
                                                 tempAdminSessions.delete(sessionId);
 
-                                                // Create new permanent session
+                                                // Create new permanent session with personal_ prefix
                                                 const newSessionId = generateSessionId();
                                                 sessions.set(newSessionId, `personal_${userId}`);
 
-                                                console.log(`Password changed successfully for ${userType} ${userId}, redirecting to ${redirectTo}`);
+                                                console.log(`Password changed successfully for ${userType} ${userId}, redirecting to ${finalRedirect}`);
 
                                                 database.logAudit(userId, 'FORCED_PASSWORD_CHANGE', 'auth', userId.toString(),
                                                     `${userType} forced password change completed`, ipAddress);
 
-                                                // Set the cookie with proper options
+                                                // Set the cookie with proper options - extended to 24 hours
                                                 res.writeHead(200, {
                                                     'Content-Type': 'application/json',
-                                                    'Set-Cookie': `sessionId=${newSessionId}; HttpOnly; Path=/; Max-Age=3600; SameSite=Strict`
+                                                    'Set-Cookie': `sessionId=${newSessionId}; HttpOnly; Path=/; Max-Age=86400; SameSite=Strict`
                                                 });
+
                                                 res.end(JSON.stringify({
                                                     success: true,
                                                     message: 'Password changed successfully.',
-                                                    redirectTo: redirectTo,
+                                                    redirectTo: finalRedirect,
                                                     userType: userType
                                                 }));
@@ -3668,5 +3697,4 @@
                         body += chunk.toString();
                     });
-
                     req.on('end', () => {
                         const { firstName, lastName, ssn, email, password, storeId, dateOfHire } = JSON.parse(body);
@@ -3775,7 +3803,11 @@
                                                     database.database.run('ROLLBACK');
                                                     console.error('Error inserting personal:', err);
+
                                                     if (err.code === '23505') {
                                                         res.writeHead(400, { 'Content-Type': 'application/json' });
-                                                        res.end(JSON.stringify({ success: false, message: 'This personal ID is already taken. Please try again.' }));
+                                                        res.end(JSON.stringify({
+                                                            success: false,
+                                                            message: 'This personal ID is already taken. Please try again.'
+                                                        }));
                                                     } else {
                                                         res.writeHead(400, { 'Content-Type': 'application/json' });
@@ -3817,23 +3849,41 @@
                                                                         }
 
-                                                                        database.database.run('COMMIT', (err) => {
-                                                                            if (err) {
-                                                                                database.database.run('ROLLBACK');
-                                                                                console.error('Error committing transaction:', err);
-                                                                                res.writeHead(500, { 'Content-Type': 'application/json' });
-                                                                                res.end(JSON.stringify({ success: false, message: 'Error completing registration' }));
-                                                                                return;
+                                                                        // Also create entry in users table for login with force_password_change = 1
+                                                                        database.database.run(
+                                                                            'INSERT INTO users (id, username, email, password, user_type, force_password_change) VALUES (?, ?, ?, ?, ?, ?)',
+                                                                            [
+                                                                                newPersonalId,
+                                                                                `${firstName} ${lastName}`,
+                                                                                email,
+                                                                                bcrypt.hashSync(password, 10),
+                                                                                'store_employee',
+                                                                                1
+                                                                            ],
+                                                                            (err) => {
+                                                                                if (err) {
+                                                                                    console.error('Error creating user entry for employee:', err);
+                                                                                }
+
+                                                                                database.database.run('COMMIT', (err) => {
+                                                                                    if (err) {
+                                                                                        database.database.run('ROLLBACK');
+                                                                                        console.error('Error committing transaction:', err);
+                                                                                        res.writeHead(500, { 'Content-Type': 'application/json' });
+                                                                                        res.end(JSON.stringify({ success: false, message: 'Error completing registration' }));
+                                                                                        return;
+                                                                                    }
+
+                                                                                    database.logAudit(personalId, 'EMPLOYEE_REGISTERED', 'employee', newPersonalId, `Employee registered: ${firstName} ${lastName}`, ipAddress);
+
+                                                                                    res.writeHead(200, { 'Content-Type': 'application/json' });
+                                                                                    res.end(JSON.stringify({
+                                                                                        success: true,
+                                                                                        message: 'Employee registered successfully!',
+                                                                                        employeeId: newPersonalId,
+                                                                                        name: `${firstName} ${lastName}`
+                                                                                    }));
+                                                                                });
                                                                             }
-
-                                                                            database.logAudit(personalId, 'EMPLOYEE_REGISTERED', 'employee', newPersonalId, `Employee registered: ${firstName} ${lastName}`, ipAddress);
-
-                                                                            res.writeHead(200, { 'Content-Type': 'application/json' });
-                                                                            res.end(JSON.stringify({
-                                                                                success: true,
-                                                                                message: 'Employee registered successfully!',
-                                                                                employeeId: newPersonalId,
-                                                                                name: `${firstName} ${lastName}`
-                                                                            }));
-                                                                        });
+                                                                        );
                                                                     }
                                                                 );
@@ -3887,5 +3937,4 @@
                         body += chunk.toString();
                     });
-
                     req.on('end', () => {
                         const { employeeId, storeId } = JSON.parse(body);
@@ -3975,21 +4024,32 @@
                                                                                     }
 
-                                                                                    database.database.run('COMMIT', (commitErr) => {
-                                                                                        if (commitErr) {
-                                                                                            database.database.run('ROLLBACK');
-                                                                                            console.error('Error committing transaction:', commitErr);
-                                                                                            res.writeHead(500, { 'Content-Type': 'application/json' });
-                                                                                            res.end(JSON.stringify({ success: false, message: 'Error completing deletion' }));
-                                                                                            return;
+                                                                                    // Also delete from users table
+                                                                                    database.database.run(
+                                                                                        'DELETE FROM users WHERE id = ?',
+                                                                                        [employeeId],
+                                                                                        (err) => {
+                                                                                            if (err) {
+                                                                                                console.error('Error deleting from users:', err);
+                                                                                            }
+
+                                                                                            database.database.run('COMMIT', (commitErr) => {
+                                                                                                if (commitErr) {
+                                                                                                    database.database.run('ROLLBACK');
+                                                                                                    console.error('Error committing transaction:', commitErr);
+                                                                                                    res.writeHead(500, { 'Content-Type': 'application/json' });
+                                                                                                    res.end(JSON.stringify({ success: false, message: 'Error completing deletion' }));
+                                                                                                    return;
+                                                                                                }
+
+                                                                                                database.logAudit(personalId, 'EMPLOYEE_DELETED', 'employee', employeeId, `Employee deleted from store ${storeId}`, ipAddress);
+
+                                                                                                res.writeHead(200, { 'Content-Type': 'application/json' });
+                                                                                                res.end(JSON.stringify({
+                                                                                                    success: true,
+                                                                                                    message: 'Employee deleted successfully'
+                                                                                                }));
+                                                                                            });
                                                                                         }
-
-                                                                                        database.logAudit(personalId, 'EMPLOYEE_DELETED', 'employee', employeeId, `Employee deleted from store ${storeId}`, ipAddress);
-
-                                                                                        res.writeHead(200, { 'Content-Type': 'application/json' });
-                                                                                        res.end(JSON.stringify({
-                                                                                            success: true,
-                                                                                            message: 'Employee deleted successfully'
-                                                                                        }));
-                                                                                    });
+                                                                                    );
                                                                                 }
                                                                             );
@@ -4046,5 +4106,4 @@
                         body += chunk.toString();
                     });
-
                     req.on('end', () => {
                         const { employeeId, storeId, status } = JSON.parse(body);
@@ -4153,5 +4212,4 @@
                         body += chunk.toString();
                     });
-
                     req.on('end', () => {
                         const { employeeId, storeId, firstName, lastName, email } = JSON.parse(body);
@@ -4223,4 +4281,38 @@
                                                     res.end(JSON.stringify({ success: false, message: 'Error updating employee information' }));
                                                     return;
+                                                }
+
+                                                // Also update in users table if email was changed
+                                                if (email) {
+                                                    database.database.run(
+                                                        'UPDATE users SET email = ? WHERE id = ?',
+                                                        [email, employeeId],
+                                                        (err) => {
+                                                            if (err) {
+                                                                console.error('Error updating user email:', err);
+                                                            }
+                                                        }
+                                                    );
+                                                }
+
+                                                if (firstName || lastName) {
+                                                    database.database.get(
+                                                        'SELECT first_name, last_name FROM personal WHERE id = ?',
+                                                        [employeeId],
+                                                        (err, personal) => {
+                                                            if (!err && personal) {
+                                                                const newUsername = `${personal.first_name} ${personal.last_name}`;
+                                                                database.database.run(
+                                                                    'UPDATE users SET username = ? WHERE id = ?',
+                                                                    [newUsername, employeeId],
+                                                                    (err) => {
+                                                                        if (err) {
+                                                                            console.error('Error updating user username:', err);
+                                                                        }
+                                                                    }
+                                                                );
+                                                            }
+                                                        }
+                                                    );
                                                 }
 
@@ -4582,5 +4674,4 @@
                 body += chunk.toString();
             });
-
             req.on('end', () => {
                 const { productCode, storeId } = JSON.parse(body);
@@ -4652,5 +4743,4 @@
                 body += chunk.toString();
             });
-
             req.on('end', () => {
                 const { storeId, period, startDate, endDate, type } = JSON.parse(body);
