closing security gap [ignore guarding change for now]
This commit is contained in:
@@ -77,6 +77,13 @@ if(!empty($_SESSION["login_company_id"])){
|
||||
|
||||
}
|
||||
|
||||
// Fail closed — reject any request that arrives without an authenticated session
|
||||
// unless the engine explicitly declared itself a pre-auth route.
|
||||
if (empty($_SESSION['login_company_id']) && !defined('UNAUTHENTICATED_ROUTE')) {
|
||||
http_response_code(401);
|
||||
exit(json_encode(['success' => 0, 'message' => 'Authentication required.']));
|
||||
}
|
||||
|
||||
// set up ANSWER
|
||||
$answer = array("success"=>0, "message"=>"");
|
||||
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
<div class="col-12">
|
||||
<footer class="text-center py-2 mt-6 text-secondary ">
|
||||
<p class="mb-0">Copyright © 2026 TRx WMS. Developed by <a href="https://codescandy.com/"
|
||||
target="_blank" class="text-primary">CodesCandy</a> </p>
|
||||
target="_blank" class="text-primary">TR3</a> </p>
|
||||
</footer>
|
||||
</div>
|
||||
|
||||
|
||||
@@ -1,3 +1,12 @@
|
||||
<?php
|
||||
// Security headers — emitted before any HTML output.
|
||||
// X-Content-Type-Options: prevents MIME-sniffing attacks.
|
||||
header('X-Content-Type-Options: nosniff');
|
||||
// X-Frame-Options: blocks this page from being embedded in a cross-origin iframe.
|
||||
header('X-Frame-Options: SAMEORIGIN');
|
||||
// Referrer-Policy: sends origin only on same-origin; omits on cross-origin navigations.
|
||||
header('Referrer-Policy: strict-origin-when-cross-origin');
|
||||
?>
|
||||
<!DOCTYPE html>
|
||||
<html lang="en">
|
||||
|
||||
|
||||
@@ -22,6 +22,7 @@
|
||||
*/
|
||||
|
||||
require '../../../session.php';
|
||||
define('UNAUTHENTICATED_ROUTE', true);
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
|
||||
// Intentional 1-second delay — prevents timing attacks on session enumeration
|
||||
|
||||
@@ -51,6 +51,7 @@
|
||||
require '../../../session.php';
|
||||
require '../../../config.php';
|
||||
require '../../../preset.php';
|
||||
define('UNAUTHENTICATED_ROUTE', true);
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
|
||||
// ── Step 1: Load session state written by login_otp.php ───────────────────────
|
||||
|
||||
@@ -60,6 +60,7 @@
|
||||
require '../../../session.php';
|
||||
require '../../../config.php';
|
||||
require '../../../preset.php';
|
||||
define('UNAUTHENTICATED_ROUTE', true);
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
|
||||
// ── Step 1: Resolve user_id from username or email (case-insensitive) ────────
|
||||
|
||||
@@ -45,6 +45,7 @@
|
||||
require '../../../session.php';
|
||||
require '../../../config.php';
|
||||
require '../../../preset.php';
|
||||
define('UNAUTHENTICATED_ROUTE', true);
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
|
||||
// ── Step 1: Reload credentials from session ───────────────────────────────────
|
||||
|
||||
@@ -1,6 +1,10 @@
|
||||
<?php
|
||||
// app/session.php
|
||||
if (session_status() === PHP_SESSION_NONE) {
|
||||
// Reject client-supplied session IDs — prevents session fixation.
|
||||
ini_set('session.use_strict_mode', 1);
|
||||
// Server-side session file lifetime: 1 hour.
|
||||
ini_set('session.gc_maxlifetime', 3600);
|
||||
session_set_cookie_params([
|
||||
'lifetime' => 0,
|
||||
'path' => '/wms/',
|
||||
|
||||
@@ -5,8 +5,9 @@
|
||||
|
||||
require_role($user_role, ['owner', 'admin']);
|
||||
|
||||
// ─── Allowed upload MIME types ────────────────────────────────────────────
|
||||
// ─── Allowed upload types ─────────────────────────────────────────────────
|
||||
const ALLOWED_MIME = ['image/jpeg', 'image/png', 'image/gif', 'image/webp'];
|
||||
const ALLOWED_EXT = ['jpg', 'jpeg', 'png', 'gif', 'webp'];
|
||||
const MAX_SIZE = 2 * 1024 * 1024; // 2 MB
|
||||
|
||||
// ─── Helper: handle one image slot ────────────────────────────────────────
|
||||
@@ -48,13 +49,17 @@
|
||||
throw new RuntimeException('Invalid file type. Only JPEG, PNG, GIF, WEBP allowed.');
|
||||
}
|
||||
|
||||
$ext = strtolower(pathinfo($file['name'], PATHINFO_EXTENSION));
|
||||
if (!in_array($ext, ALLOWED_EXT, true)) {
|
||||
throw new RuntimeException('Invalid file extension. Only jpg, png, gif, webp allowed.');
|
||||
}
|
||||
|
||||
// Delete old file first
|
||||
if ($current && file_exists($upload_dir . $current)) {
|
||||
unlink($upload_dir . $current);
|
||||
}
|
||||
|
||||
$ext = pathinfo($file['name'], PATHINFO_EXTENSION);
|
||||
$filename = $prefix . uniqid() . '.' . strtolower($ext);
|
||||
$filename = $prefix . uniqid() . '.' . $ext;
|
||||
|
||||
if (!move_uploaded_file($file['tmp_name'], $upload_dir . $filename)) {
|
||||
throw new RuntimeException("Failed to save {$slot}.");
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
<?php
|
||||
session_start();
|
||||
define('UNAUTHENTICATED_ROUTE', true);
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
require '../../../assets/utils/classes/PasswordResetManager.php';
|
||||
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
<?php
|
||||
session_start();
|
||||
define('UNAUTHENTICATED_ROUTE', true);
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
require '../../../assets/utils/classes/PasswordResetManager.php';
|
||||
|
||||
|
||||
Reference in New Issue
Block a user