stock aggregate table

This commit is contained in:
Thanakorn S
2026-05-25 13:30:10 +07:00
parent 45a78a3fed
commit 1237888ab9
20 changed files with 725 additions and 62 deletions
+8 -8
View File
@@ -99,21 +99,21 @@ $_SESSION["diff"] = $otp_diff_minutes;
// If session_token is non-NULL AND was set within the last 8 hours, another
// session is active — reject. Tokens older than 8 hours are treated as
// abandoned (browser crash, PHP GC expiry, etc.) and cleared automatically.
$sth_token = $pdo1->prepare("SELECT session_token, session_token_at FROM user WHERE user_id = :uid LIMIT 1");
$sth_token = $pdo1->prepare("SELECT session_token, session_last_seen FROM user WHERE user_id = :uid LIMIT 1");
$sth_token->execute([':uid' => $user_id]);
$token_row = $sth_token->fetch(PDO::FETCH_ASSOC);
$token_row = $sth_token->fetch(PDO::FETCH_ASSOC);
$existing_token = $token_row['session_token'] ?? null;
if (!empty($existing_token)) {
$token_age_hours = PHP_INT_MAX;
if (!empty($token_row['session_token_at'])) {
$token_age_hours = (time() - strtotime($token_row['session_token_at'])) / 3600;
$idle_seconds = PHP_INT_MAX;
if (!empty($token_row['session_last_seen'])) {
$idle_seconds = time() - strtotime($token_row['session_last_seen']);
}
if ($token_age_hours < 8) {
if ($idle_seconds < (int)ini_get('session.gc_maxlifetime')) {
$answer["message"] = "This account is currently logged in on another device. Please wait for the other session to end.";
exit(json_encode($answer));
}
// Stale token — clear it and proceed with login
$pdo1->prepare("UPDATE user SET session_token = NULL, session_token_at = NULL WHERE user_id = :uid")
// PHP GC has expired this session — clear token and allow login
$pdo1->prepare("UPDATE user SET session_token = NULL, session_token_at = NULL, session_last_seen = NULL WHERE user_id = :uid")
->execute([':uid' => $user_id]);
}
+3
View File
@@ -361,6 +361,9 @@ if (password_verify(trim($data["password"]), $temp["password"])) {
$_SESSION["user_email"] = $user_email; // shown masked on OTP screen
$_SESSION["login_user_id"] = $user_id; // used by login_confirm.php to build the login session
$_SESSION["no_smtp"] = empty($smtp_config); // true = skip OTP step on login page
if (empty($smtp_config)) {
$_SESSION['skip_otp'] = true;
}
// ── Step 10: Respond ──────────────────────────────────────────────────────
$answer["success"] = 1;