implement JS password scoring, td_stock approve logicc
This commit is contained in:
@@ -11,7 +11,7 @@
|
||||
*
|
||||
* Method order:
|
||||
* Core public API → checkStrength, change, forceSet
|
||||
* HTTP handlers → handleCheck, handleChange (thin wrappers for AJAX endpoints)
|
||||
* HTTP handler → handleChange (thin wrapper for AJAX endpoint)
|
||||
* Private helpers → loadZxcvbn, fetchUser, enforceStrength, persist
|
||||
*
|
||||
* Usage:
|
||||
@@ -49,7 +49,7 @@ class PasswordManager {
|
||||
*/
|
||||
public function __construct($pdo, string $include_url) {
|
||||
$this->pdo = $pdo;
|
||||
$this->zxcvbn_path = rtrim($include_url, '/') . '/assets/zxcvbn-php-master/vendor/autoload.php';
|
||||
$this->zxcvbn_path = rtrim($include_url, '/') . '/../lib/zxcvbn-php-master/vendor/autoload.php';
|
||||
}
|
||||
|
||||
// ─────────────────────────────────────────────────────────────
|
||||
@@ -166,44 +166,9 @@ class PasswordManager {
|
||||
}
|
||||
|
||||
// ─────────────────────────────────────────────────────────────
|
||||
// HTTP handlers (thin AJAX endpoint wrappers)
|
||||
// HTTP handler (thin AJAX endpoint wrapper)
|
||||
// ─────────────────────────────────────────────────────────────
|
||||
|
||||
/**
|
||||
* Handle an AJAX strength-check request and echo a JSON response.
|
||||
*
|
||||
* Called by: setting/api/engine/check_password.php
|
||||
*
|
||||
* Expected $data keys:
|
||||
* password (string) — the password string to analyse
|
||||
*
|
||||
* Response JSON keys:
|
||||
* success (int 1), score (int -1 if empty, else 0–4), feedback (string)
|
||||
*
|
||||
* Outputs JSON and calls exit. Safe against XSS — all output via json_encode.
|
||||
*
|
||||
* @param array $data Request data array (typically from $_POST or decoded JSON body).
|
||||
*/
|
||||
public function handleCheck(array $data): void {
|
||||
|
||||
$password = $data['password'] ?? '';
|
||||
|
||||
if (empty($password)) {
|
||||
echo json_encode(['success' => 1, 'score' => -1, 'feedback' => '']);
|
||||
exit;
|
||||
}
|
||||
|
||||
$result = $this->checkStrength($password);
|
||||
$feedback = $result['warning'] ?: ($result['suggestions'][0] ?? '');
|
||||
|
||||
echo json_encode([
|
||||
'success' => 1,
|
||||
'score' => $result['score'],
|
||||
'feedback' => $feedback,
|
||||
]);
|
||||
exit;
|
||||
}
|
||||
|
||||
/**
|
||||
* Handle an AJAX change-password request and echo a JSON response.
|
||||
*
|
||||
|
||||
Reference in New Issue
Block a user