Security hardening: invited user onboarding flow (C1–N7)
This commit is contained in:
@@ -68,6 +68,17 @@ if (empty($_SESSION['onboarding_user_id'])) {
|
||||
|
||||
$user_id = (int)$_SESSION['onboarding_user_id'];
|
||||
|
||||
// ── Step 1b: License guard ────────────────────────────────────────────────────
|
||||
// Invited users (license='user') must use invited_onboarding.php, not this flow.
|
||||
// If somehow an invited user's session reaches here, reject immediately.
|
||||
$sth = $pdo1->prepare("SELECT license FROM user WHERE user_id = :uid LIMIT 1");
|
||||
$sth->execute([':uid' => $user_id]);
|
||||
if ($sth->fetchColumn() !== 'owner') {
|
||||
$answer['message'] = 'Invalid session.';
|
||||
http_response_code(403);
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
|
||||
// ── Step 2: CSRF check ────────────────────────────────────────────────────────
|
||||
if ($_SERVER['REQUEST_METHOD'] === 'POST') {
|
||||
$csrf = $_SERVER['HTTP_X_CSRF_TOKEN'] ?? '';
|
||||
|
||||
Reference in New Issue
Block a user