diff --git a/app/login/api/engine/login_otp.php b/app/login/api/engine/login_otp.php index 4ff9ae1..5857962 100644 --- a/app/login/api/engine/login_otp.php +++ b/app/login/api/engine/login_otp.php @@ -140,36 +140,37 @@ if (password_verify(trim($data["password"]), $temp["password"])) { . '://' . $_SERVER['HTTP_HOST'] . rtrim($server_url, '/'); $verify_url = $base_url . '/login/verify.php?token=' . $token; - try { - require_once $include_url . 'assets/utils/module/mailer.php'; - $mailer = new mailer(['pdo1' => $pdo1]); - $mailer->send_email([ - 'company_id' => 0, - 'smtp' => $SMTP, - 'to' => $r['email'], - 'subject' => 'Verify your email — WMS', - 'message' => implode("\n", [ - "Hi {$r['name']},", - "", - "You attempted to login but your email is not yet verified.", - "Please verify your email address by clicking the button below:", - "", - "Verify Email Address", - "", - "Or copy and paste this link into your browser:", - "{$verify_url}", - "", - "This link will expire in 30 days.", - ]), - 'channel_name' => 'WMS', - 'key' => $pinkey, - ]); - } catch (Exception $e) { - // Log silently — do not expose mailer errors to the end user - error_log('[resend_verify] ' . $e->getMessage()); - } + require_once $include_url . 'assets/utils/module/mailer.php'; + $mailer = new mailer(['pdo1' => $pdo1]); + $mail_sent = $mailer->send_email([ + 'company_id' => 0, + 'smtp' => $SMTP, + 'silent' => true, + 'to' => $r['email'], + 'subject' => 'Verify your email — WMS', + 'message' => implode("\n", [ + "Hi {$r['name']},", + "", + "You attempted to login but your email is not yet verified.", + "Please verify your email address by clicking the button below:", + "", + "Verify Email Address", + "", + "Or copy and paste this link into your browser:", + "{$verify_url}", + "", + "This link will expire in 30 days.", + ]), + 'channel_name' => 'WMS', + 'key' => $pinkey, + ]); - $answer["message"] = "Your email is not verified. We've sent a new verification link to your inbox — please check your email."; + if ($mail_sent) { + $answer["message"] = "Your email is not verified. We've sent a new verification link to your inbox — please check your email."; + } else { + $answer["message"] = "Your email is not verified. Verification email could not be sent — please contact your administrator."; + $answer["verify_url"] = $verify_url; + } exit(json_encode($answer)); } @@ -306,22 +307,22 @@ if (password_verify(trim($data["password"]), $temp["password"])) { } } - if (!empty($smtp_config)) { + // if (!empty($smtp_config)) { - require "../../../assets/utils/module/mailer.php"; + // require "../../../assets/utils/module/mailer.php"; - $mailer = new mailer(["pdo1" => $pdo1, "pdo2" => $pdo2]); + // $mailer = new mailer(["pdo1" => $pdo1, "pdo2" => $pdo2]); - $mailer->send_email([ - "company_id" => $default_company, - "smtp" => $smtp_config, - "subject" => "One Time Password (OTP) For reference number " . $reference_number, - "message" => "Your OTP is " . $otp . " for reference number " . $reference_number, - "channel_name" => "WMS LOGIN OTP", - "to" => $user_email, - "key" => $pinkey, - ]); - } + // $mailer->send_email([ + // "company_id" => $default_company, + // "smtp" => $smtp_config, + // "subject" => "One Time Password (OTP) For reference number " . $reference_number, + // "message" => "Your OTP is " . $otp . " for reference number " . $reference_number, + // "channel_name" => "WMS LOGIN OTP", + // "to" => $user_email, + // "key" => $pinkey, + // ]); + // } // ── Step 9: Reset session and write OTP state ───────────────────────────── // The full session is cleared first to prevent session fixation — any data