Harden sign-in and password reset

- OTP attempt limits, constant-time compare, random reference codes
- DB-backed rate limits (429) on sign-in, OTP, reset, register, onboarding
- one generic sign-in failure message; reset request no longer reveals accounts
- no password kept in the session; real status codes on failures
This commit is contained in:
Thanakorn
2026-09-24 14:53:40 +07:00
parent ae98dcdcdd
commit 73c680e844
16 changed files with 538 additions and 282 deletions
+18 -10
View File
@@ -2,7 +2,7 @@
require '../session.php';
require '../config.php';
require_once '../assets/utils/otp_policy.php';
require '../include_header.php';
require __DIR__ . '/include_login_header.php';
// successful login — redirect based on app_access
if(!empty($_SESSION["login_status"])){
$redirect = ($_SESSION['login_app_access'] ?? 'wms') === 'accounting'
@@ -33,13 +33,9 @@
</div>
<form class="needs-validation mt-3" novalidate id="login-form">
<?php if (!otp_required()): ?>
<!-- OTP_REQUIRED is not true in config.php (the default): a password-only sign-in must never be invisible -->
<div class="alert alert-warning small py-2 mb-3" title="OTP_REQUIRED is not true in config.php">
<i class="ti ti-alert-triangle me-1"></i>
Email OTP is off — sign-in is password only.
</div>
<?php endif; ?>
<!-- Whether email OTP is on is server configuration and is not shown to
anonymous visitors; password-only sign-ins are logged as OTP_BYPASSED
(assets/utils/otp_policy.php). -->
<!-- first step login [OTP] -->
<?php if(!isset($_SESSION['login_data'])){?>
<div class="mb-3">
@@ -144,6 +140,16 @@
// The server ended the pending sign-in (too many wrong OTPs, or the verified
// password is too old): show why, then return to the username/password step.
function restart_login_on(xhr) {
if (xhr?.responseJSON?.code !== 'login_restart') return;
bootbox.hideAll();
bootbox.alert(escape_html(xhr.responseJSON.message || 'Please sign in again.'), function() {
window.location.href = "<?php echo $server_url?>login/index.php";
});
}
// reqquest new otp function
function request_new_otp() {
@@ -156,7 +162,8 @@
window.location.href = "<?php echo $server_url?>index.php";
}
},
onError: restart_login_on
});
}
@@ -194,7 +201,8 @@
window.location.href = "index.php";
}
},
onError: restart_login_on
});
}