Harden sign-in and password reset
- OTP attempt limits, constant-time compare, random reference codes - DB-backed rate limits (429) on sign-in, OTP, reset, register, onboarding - one generic sign-in failure message; reset request no longer reveals accounts - no password kept in the session; real status codes on failures
This commit is contained in:
+18
-10
@@ -2,7 +2,7 @@
|
||||
require '../session.php';
|
||||
require '../config.php';
|
||||
require_once '../assets/utils/otp_policy.php';
|
||||
require '../include_header.php';
|
||||
require __DIR__ . '/include_login_header.php';
|
||||
// successful login — redirect based on app_access
|
||||
if(!empty($_SESSION["login_status"])){
|
||||
$redirect = ($_SESSION['login_app_access'] ?? 'wms') === 'accounting'
|
||||
@@ -33,13 +33,9 @@
|
||||
</div>
|
||||
|
||||
<form class="needs-validation mt-3" novalidate id="login-form">
|
||||
<?php if (!otp_required()): ?>
|
||||
<!-- OTP_REQUIRED is not true in config.php (the default): a password-only sign-in must never be invisible -->
|
||||
<div class="alert alert-warning small py-2 mb-3" title="OTP_REQUIRED is not true in config.php">
|
||||
<i class="ti ti-alert-triangle me-1"></i>
|
||||
Email OTP is off — sign-in is password only.
|
||||
</div>
|
||||
<?php endif; ?>
|
||||
<!-- Whether email OTP is on is server configuration and is not shown to
|
||||
anonymous visitors; password-only sign-ins are logged as OTP_BYPASSED
|
||||
(assets/utils/otp_policy.php). -->
|
||||
<!-- first step login [OTP] -->
|
||||
<?php if(!isset($_SESSION['login_data'])){?>
|
||||
<div class="mb-3">
|
||||
@@ -144,6 +140,16 @@
|
||||
|
||||
|
||||
|
||||
// The server ended the pending sign-in (too many wrong OTPs, or the verified
|
||||
// password is too old): show why, then return to the username/password step.
|
||||
function restart_login_on(xhr) {
|
||||
if (xhr?.responseJSON?.code !== 'login_restart') return;
|
||||
bootbox.hideAll();
|
||||
bootbox.alert(escape_html(xhr.responseJSON.message || 'Please sign in again.'), function() {
|
||||
window.location.href = "<?php echo $server_url?>login/index.php";
|
||||
});
|
||||
}
|
||||
|
||||
// reqquest new otp function
|
||||
function request_new_otp() {
|
||||
|
||||
@@ -156,7 +162,8 @@
|
||||
|
||||
window.location.href = "<?php echo $server_url?>index.php";
|
||||
|
||||
}
|
||||
},
|
||||
onError: restart_login_on
|
||||
});
|
||||
|
||||
}
|
||||
@@ -194,7 +201,8 @@
|
||||
|
||||
window.location.href = "index.php";
|
||||
|
||||
}
|
||||
},
|
||||
onError: restart_login_on
|
||||
});
|
||||
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user