Security hardening: invited user onboarding flow (C1–N7)

This commit is contained in:
Thanakorn S
2026-05-26 10:18:40 +07:00
parent 0815ae3292
commit 9e200d31fe
9 changed files with 562 additions and 163 deletions
+11
View File
@@ -68,6 +68,17 @@ if (empty($_SESSION['onboarding_user_id'])) {
$user_id = (int)$_SESSION['onboarding_user_id'];
// ── Step 1b: License guard ────────────────────────────────────────────────────
// Invited users (license='user') must use invited_onboarding.php, not this flow.
// If somehow an invited user's session reaches here, reject immediately.
$sth = $pdo1->prepare("SELECT license FROM user WHERE user_id = :uid LIMIT 1");
$sth->execute([':uid' => $user_id]);
if ($sth->fetchColumn() !== 'owner') {
$answer['message'] = 'Invalid session.';
http_response_code(403);
exit(json_encode($answer));
}
// ── Step 2: CSRF check ────────────────────────────────────────────────────────
if ($_SERVER['REQUEST_METHOD'] === 'POST') {
$csrf = $_SERVER['HTTP_X_CSRF_TOKEN'] ?? '';