Harden sign-in and password reset

- OTP attempt limits, constant-time compare, random reference codes
- DB-backed rate limits (429) on sign-in, OTP, reset, register, onboarding
- one generic sign-in failure message; reset request no longer reveals accounts
- no password kept in the session; real status codes on failures
This commit is contained in:
Thanakorn
2026-09-24 14:53:40 +07:00
parent ae98dcdcdd
commit 73c680e844
16 changed files with 538 additions and 282 deletions
+14 -1
View File
@@ -1,10 +1,23 @@
<?php
/**
* reset_password_otp.php — login page "Forgot password?" step 2.
*
* Unauthenticated. Needs the reset state written by request_reset_otp.php in
* this session. For a username that matched no account that state is a decoy
* (reset_user_id 0) which always answers "Incorrect OTP", so this step does not
* reveal whether the account exists either.
*/
require_once '../../../session.php';
define('UNAUTHENTICATED_ROUTE', true);
require_once '../../../assets/utils/db_auth.php';
require_once '../../../assets/utils/rate_limit.php';
if (empty($_SESSION['reset_user_id'])) {
rate_limit_guard($pdo1, [
['reset_confirm_ip', rate_limit_client_ip(), 30, 900],
]);
if (!isset($_SESSION['reset_user_id'])) {
http_response_code(400);
$answer['message'] = 'No active reset request. Please request a new OTP.';
exit(json_encode($answer));