login/ block concurrent login, allow single factor authen for staff and viewer
This commit is contained in:
@@ -77,6 +77,19 @@ if(!empty($_SESSION["login_company_id"])){
|
||||
$user_role = $map[0]['role'] ?? 'viewer';
|
||||
$_SESSION['login_role'] = $user_role;
|
||||
|
||||
// Single-session enforcement: if a session_token was issued at login, verify
|
||||
// it still matches the DB. A mismatch means a newer login has taken over.
|
||||
if (!empty($_SESSION['session_token'])) {
|
||||
$sth = $pdo1->prepare("SELECT session_token FROM user WHERE user_id = :uid LIMIT 1");
|
||||
$sth->execute([':uid' => $_SESSION['login_user_id']]);
|
||||
$db_token = $sth->fetchColumn();
|
||||
if ($db_token !== $_SESSION['session_token']) {
|
||||
session_destroy();
|
||||
http_response_code(401);
|
||||
exit(json_encode(['success' => 0, 'message' => 'You have been signed in from another device.', 'code' => 'signed_elsewhere']));
|
||||
}
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
// Fail closed — reject any request that arrives without an authenticated session
|
||||
|
||||
Reference in New Issue
Block a user