login: block concurrent login, single-factor auth for staff/viewer

This commit is contained in:
Thanakorn S
2026-05-25 09:43:30 +07:00
parent 5ca6b49fd0
commit 45a78a3fed
9 changed files with 124 additions and 22 deletions
+5 -1
View File
@@ -103,6 +103,8 @@ CREATE TABLE IF NOT EXISTS `user` (
`verify_expires_at` datetime DEFAULT NULL,
`login_attempts` int(11) NOT NULL DEFAULT 0,
`locked_until` datetime DEFAULT NULL,
`session_token` varchar(64) DEFAULT NULL,
`session_token_at` datetime DEFAULT NULL,
PRIMARY KEY (`user_id`),
UNIQUE KEY `username` (`username`),
UNIQUE KEY `email` (`email`),
@@ -522,9 +524,11 @@ CREATE TABLE IF NOT EXISTS `td_stock` (
`description` text NOT NULL DEFAULT '',
`status` int(3) NOT NULL DEFAULT 0,
`log` mediumtext NOT NULL DEFAULT '{}',
`updated_at` datetime DEFAULT NULL,
PRIMARY KEY (`id`),
KEY `company_id` (`company_id`),
KEY `product_id` (`product_sku`)
KEY `product_id` (`product_sku`),
KEY `updated_at` (`updated_at`)
) ENGINE=InnoDB DEFAULT CHARSET=utf8mb3;
", 'td_stock (base template)');