From 79e66bd354aea7b8ee91ebca31b547f07e3cd4a4 Mon Sep 17 00:00:00 2001 From: Thanakorn S Date: Tue, 12 May 2026 17:19:22 +0700 Subject: [PATCH] add forget password --- app/login/api/engine/login_otp.php | 4 +- app/login/api/engine/request_reset_otp.php | 32 +++ app/login/api/engine/reset_password_otp.php | 17 ++ app/login/forgot_password.php | 234 ++++++++++++++++++++ app/login/index.php | 1 + 5 files changed, 286 insertions(+), 2 deletions(-) create mode 100644 app/login/api/engine/request_reset_otp.php create mode 100644 app/login/api/engine/reset_password_otp.php create mode 100644 app/login/forgot_password.php diff --git a/app/login/api/engine/login_otp.php b/app/login/api/engine/login_otp.php index d9fa974..4ff9ae1 100644 --- a/app/login/api/engine/login_otp.php +++ b/app/login/api/engine/login_otp.php @@ -349,7 +349,7 @@ if (password_verify(trim($data["password"]), $temp["password"])) { // don't count so a typo in your own name doesn't eat your own attempts. if ($user_id) { $attempts = (int)($temp['login_attempts'] ?? 0) + 1; - if ($attempts >= 10) { + if ($attempts >= 5) { $locked_until = date('Y-m-d H:i:s', strtotime('+30 minutes')); $pdo1->prepare("UPDATE user SET login_attempts = :a, locked_until = :l WHERE user_id = :id") ->execute([':a' => $attempts, ':l' => $locked_until, ':id' => $user_id]); @@ -361,7 +361,7 @@ if (password_verify(trim($data["password"]), $temp["password"])) { $answer['message'] = "Incorrect Password"; } } else { - $answer['message'] = "Incorrect Password"; + $answer['message'] = "Incorrect Username"; } setcookie("u", "", time() - 1, "/"); diff --git a/app/login/api/engine/request_reset_otp.php b/app/login/api/engine/request_reset_otp.php new file mode 100644 index 0000000..48df661 --- /dev/null +++ b/app/login/api/engine/request_reset_otp.php @@ -0,0 +1,32 @@ + 0, 'message' => 'Please enter your username or email.'])); +} + +$sth = $pdo1->prepare( + "SELECT user_id, default_company FROM user WHERE username = :i OR email = :i LIMIT 1" +); +$sth->execute([':i' => $identifier]); +$user = $sth->fetch(PDO::FETCH_ASSOC); + +if (!$user) { + http_response_code(404); + exit(json_encode(['success' => 0, 'message' => 'No account found with that username or email.'])); +} + +$user_id = (int)$user['user_id']; +$company_id = (int)($user['default_company'] ?? 0); + +require_once $include_url . 'assets/utils/classes/PasswordResetManager.php'; + +$manager = new PasswordResetManager($pdo1, $pdo2, $include_url, $SMTP, $pinkey); +$manager->handleRequestOtp($user_id, $company_id); diff --git a/app/login/api/engine/reset_password_otp.php b/app/login/api/engine/reset_password_otp.php new file mode 100644 index 0000000..8ee3230 --- /dev/null +++ b/app/login/api/engine/reset_password_otp.php @@ -0,0 +1,17 @@ + 0, 'message' => 'No active reset request. Please request a new OTP.'])); +} + +$user_id = (int)$_SESSION['reset_user_id']; + +require_once $include_url . 'assets/utils/classes/PasswordResetManager.php'; + +$manager = new PasswordResetManager($pdo1, $pdo2, $include_url, $SMTP, $pinkey); +$manager->handleConfirmReset($user_id, $data); diff --git a/app/login/forgot_password.php b/app/login/forgot_password.php new file mode 100644 index 0000000..3eb75d3 --- /dev/null +++ b/app/login/forgot_password.php @@ -0,0 +1,234 @@ + + + + + + +
+
+
+ +
+ + + +

Reset your password

+

Enter your username or email to receive an OTP.

+
+ + +
+
+ + +
+ +

+ Remember your password? + Sign in +

+
+ + +
+
+ + OTP sent to + — reference +
+
+ + +
+
+ +
+ + +
+
+
+
+
+
+ — + +
+
+
+
+ +
+ + +
+
+ +

+ + Use a different account + +

+
+ +
+
+
+ + + + + + + diff --git a/app/login/index.php b/app/login/index.php index 21707cf..6a89447 100644 --- a/app/login/index.php +++ b/app/login/index.php @@ -43,6 +43,7 @@
Please provide a password (min 6 characters).