implement JS password scoring, td_stock approve logicc

This commit is contained in:
Thanakorn S
2026-04-30 15:14:42 +07:00
parent db5c47b6ca
commit ac4fd9a5ad
3147 changed files with 1298 additions and 343 deletions
+7 -5
View File
@@ -116,11 +116,13 @@ $_SESSION['csrf_token'] = bin2hex(random_bytes(32));
// ── Step 5c: Write authenticated login session ────────────────────────────────
// These keys are read by db_auth.php on every subsequent request to gate access.
// login_company_id is the user's default_company — used to scope all DB queries.
$_SESSION["login_status"] = 1;
$_SESSION["login_username"] = $temp["username"];
$_SESSION["login_name"] = $temp["name"];
$_SESSION["login_surname"] = $temp["surname"];
$_SESSION["login_company_id"] = $temp["default_company"];
$_SESSION["login_status"] = 1;
$_SESSION["login_user_id"] = (int)$temp["user_id"];
$_SESSION["login_username"] = $temp["username"];
$_SESSION["login_name"] = $temp["name"];
$_SESSION["login_surname"] = $temp["surname"];
$_SESSION["login_company_id"] = $temp["default_company"];
$_SESSION["login_profile_picture"] = $temp["profile_picture"] ?? '';
// ── Step 6: Respond ───────────────────────────────────────────────────────────
$answer["success"] = 1;
+18 -28
View File
@@ -18,6 +18,9 @@
<body>
<!-- zxcvbn JS: client-side password strength scoring, no server round-trip -->
<script src="https://cdn.jsdelivr.net/npm/zxcvbn@4.4.2/dist/zxcvbn.js"></script>
<div class="container d-flex align-items-center justify-content-center min-vh-100 py-5">
<div class="card" style="max-width:520px; width:100%;">
<div class="card-body p-5">
@@ -137,9 +140,7 @@
{ label: 'Very strong', color: '#0d6efd', pct: 100 },
];
var pw_score = -1;
var pw_debounce = null;
var pw_xhr = null;
var pw_score = -1;
// ═══════════════════════════════════════════════
@@ -156,38 +157,27 @@
// ═══════════════════════════════════════════════
// Password strength
// Password strength (JS zxcvbn — no server round-trip)
// ═══════════════════════════════════════════════
function on_password_input(pw) {
clearTimeout(pw_debounce);
if (!pw) { reset_strength_ui(); check_confirm_match(); return; }
pw_debounce = setTimeout(() => check_strength(pw), 350);
check_strength(pw);
}
function check_strength(pw) {
if (pw_xhr) pw_xhr.abort();
const user_inputs = [
$('#name').val(), $('#surname').val(),
$('#username').val(), $('#email').val()
].filter(Boolean);
pw_xhr = $.ajax({
url: '<?php echo $server_url?>setting/api/engine/check_password.php',
type: 'POST',
dataType: 'json',
data: { json: JSON.stringify({
otp: '',
company_id: 0,
action: 'read',
password: pw,
})},
headers: { 'X-CSRF-TOKEN': $('meta[name="csrf-token"]').attr('content') },
success: function (res) {
pw_score = res.score ?? -1;
if (pw_score < 0) { reset_strength_ui(); return; }
const lvl = STRENGTH_LEVELS[pw_score];
$('#pw_strength_bar').css({ width: lvl.pct + '%', backgroundColor: lvl.color });
$('#pw_strength_label').text(lvl.label).css('color', lvl.color);
$('#pw_feedback').text(res.feedback || '');
check_confirm_match();
}
});
const result = zxcvbn(pw, user_inputs);
pw_score = result.score;
const lvl = STRENGTH_LEVELS[pw_score];
$('#pw_strength_bar').css({ width: lvl.pct + '%', backgroundColor: lvl.color });
$('#pw_strength_label').text(lvl.label).css('color', lvl.color);
$('#pw_feedback').text(result.feedback.warning || result.feedback.suggestions[0] || '');
check_confirm_match();
}
function reset_strength_ui() {