login: block concurrent login, single-factor auth for staff/viewer

This commit is contained in:
Thanakorn S
2026-05-25 09:43:30 +07:00
parent 5ca6b49fd0
commit 45a78a3fed
9 changed files with 124 additions and 22 deletions
+6
View File
@@ -25,6 +25,12 @@ require_once '../../../session.php';
define('UNAUTHENTICATED_ROUTE', true);
require_once '../../../assets/utils/db_auth.php';
// Clear session token so the account is free to log in elsewhere immediately
if (!empty($_SESSION['login_user_id'])) {
$pdo1->prepare("UPDATE user SET session_token = NULL, session_token_at = NULL WHERE user_id = :uid")
->execute([':uid' => (int)$_SESSION['login_user_id']]);
}
// Intentional 1-second delay — prevents timing attacks on session enumeration
sleep(1);