login/ block concurrent login, allow single factor authen for staff and viewer

This commit is contained in:
Thanakorn S
2026-05-25 09:43:30 +07:00
parent b07882e3f4
commit 293097363b
9 changed files with 124 additions and 22 deletions
+13
View File
@@ -77,6 +77,19 @@ if(!empty($_SESSION["login_company_id"])){
$user_role = $map[0]['role'] ?? 'viewer';
$_SESSION['login_role'] = $user_role;
// Single-session enforcement: if a session_token was issued at login, verify
// it still matches the DB. A mismatch means a newer login has taken over.
if (!empty($_SESSION['session_token'])) {
$sth = $pdo1->prepare("SELECT session_token FROM user WHERE user_id = :uid LIMIT 1");
$sth->execute([':uid' => $_SESSION['login_user_id']]);
$db_token = $sth->fetchColumn();
if ($db_token !== $_SESSION['session_token']) {
session_destroy();
http_response_code(401);
exit(json_encode(['success' => 0, 'message' => 'You have been signed in from another device.', 'code' => 'signed_elsewhere']));
}
}
}
// Fail closed — reject any request that arrives without an authenticated session