Harden sign-in and password reset
- OTP attempt limits, constant-time compare, random reference codes - DB-backed rate limits (429) on sign-in, OTP, reset, register, onboarding - one generic sign-in failure message; reset request no longer reveals accounts - no password kept in the session; real status codes on failures
This commit is contained in:
@@ -1,8 +1,16 @@
|
||||
<?php
|
||||
/**
|
||||
* request_reset_otp.php — login page "Forgot password?" step 1.
|
||||
*
|
||||
* Unauthenticated. Answers the same way whether or not the username/email
|
||||
* matches an account (see PasswordResetManager::handleRequestOtpPublic), and is
|
||||
* throttled per client IP and per identifier because every hit can send email.
|
||||
*/
|
||||
|
||||
require_once '../../../session.php';
|
||||
define('UNAUTHENTICATED_ROUTE', true);
|
||||
require_once '../../../assets/utils/db_auth.php';
|
||||
require_once '../../../assets/utils/rate_limit.php';
|
||||
|
||||
// Resolve user by username or email
|
||||
$identifier = strtolower(trim($data['identifier'] ?? ''));
|
||||
@@ -13,22 +21,21 @@ if (!$identifier) {
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
|
||||
rate_limit_guard($pdo1, [
|
||||
['reset_req_ip', rate_limit_client_ip(), 10, 900],
|
||||
['reset_req_id', $identifier, 3, 900],
|
||||
]);
|
||||
|
||||
$sth = $pdo1->prepare(
|
||||
"SELECT user_id, default_company FROM user WHERE username = :i OR email = :i LIMIT 1"
|
||||
);
|
||||
$sth->execute([':i' => $identifier]);
|
||||
$user = $sth->fetch(PDO::FETCH_ASSOC);
|
||||
|
||||
if (!$user) {
|
||||
http_response_code(404);
|
||||
$answer['message'] = 'No account found with that username or email.';
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
|
||||
$user_id = (int)$user['user_id'];
|
||||
$company_id = (int)($user['default_company'] ?? 0);
|
||||
$user_id = $user ? (int)$user['user_id'] : null;
|
||||
$company_id = $user ? (int)($user['default_company'] ?? 0) : 0;
|
||||
|
||||
require_once '../../../assets/utils/classes/PasswordResetManager.php';
|
||||
|
||||
$manager = new PasswordResetManager($pdo1, $pdo2, $include_url, $SMTP, $pinkey);
|
||||
$manager->handleRequestOtp($user_id, $company_id);
|
||||
$manager->handleRequestOtpPublic($user_id, $company_id);
|
||||
|
||||
Reference in New Issue
Block a user