implement JS password scoring, td_stock approve logicc
This commit is contained in:
@@ -116,11 +116,13 @@ $_SESSION['csrf_token'] = bin2hex(random_bytes(32));
|
||||
// ── Step 5c: Write authenticated login session ────────────────────────────────
|
||||
// These keys are read by db_auth.php on every subsequent request to gate access.
|
||||
// login_company_id is the user's default_company — used to scope all DB queries.
|
||||
$_SESSION["login_status"] = 1;
|
||||
$_SESSION["login_username"] = $temp["username"];
|
||||
$_SESSION["login_name"] = $temp["name"];
|
||||
$_SESSION["login_surname"] = $temp["surname"];
|
||||
$_SESSION["login_company_id"] = $temp["default_company"];
|
||||
$_SESSION["login_status"] = 1;
|
||||
$_SESSION["login_user_id"] = (int)$temp["user_id"];
|
||||
$_SESSION["login_username"] = $temp["username"];
|
||||
$_SESSION["login_name"] = $temp["name"];
|
||||
$_SESSION["login_surname"] = $temp["surname"];
|
||||
$_SESSION["login_company_id"] = $temp["default_company"];
|
||||
$_SESSION["login_profile_picture"] = $temp["profile_picture"] ?? '';
|
||||
|
||||
// ── Step 6: Respond ───────────────────────────────────────────────────────────
|
||||
$answer["success"] = 1;
|
||||
|
||||
+18
-28
@@ -18,6 +18,9 @@
|
||||
|
||||
<body>
|
||||
|
||||
<!-- zxcvbn JS: client-side password strength scoring, no server round-trip -->
|
||||
<script src="https://cdn.jsdelivr.net/npm/zxcvbn@4.4.2/dist/zxcvbn.js"></script>
|
||||
|
||||
<div class="container d-flex align-items-center justify-content-center min-vh-100 py-5">
|
||||
<div class="card" style="max-width:520px; width:100%;">
|
||||
<div class="card-body p-5">
|
||||
@@ -137,9 +140,7 @@
|
||||
{ label: 'Very strong', color: '#0d6efd', pct: 100 },
|
||||
];
|
||||
|
||||
var pw_score = -1;
|
||||
var pw_debounce = null;
|
||||
var pw_xhr = null;
|
||||
var pw_score = -1;
|
||||
|
||||
|
||||
// ═══════════════════════════════════════════════
|
||||
@@ -156,38 +157,27 @@
|
||||
|
||||
|
||||
// ═══════════════════════════════════════════════
|
||||
// Password strength
|
||||
// Password strength (JS zxcvbn — no server round-trip)
|
||||
// ═══════════════════════════════════════════════
|
||||
function on_password_input(pw) {
|
||||
clearTimeout(pw_debounce);
|
||||
if (!pw) { reset_strength_ui(); check_confirm_match(); return; }
|
||||
pw_debounce = setTimeout(() => check_strength(pw), 350);
|
||||
check_strength(pw);
|
||||
}
|
||||
|
||||
function check_strength(pw) {
|
||||
if (pw_xhr) pw_xhr.abort();
|
||||
const user_inputs = [
|
||||
$('#name').val(), $('#surname').val(),
|
||||
$('#username').val(), $('#email').val()
|
||||
].filter(Boolean);
|
||||
|
||||
pw_xhr = $.ajax({
|
||||
url: '<?php echo $server_url?>setting/api/engine/check_password.php',
|
||||
type: 'POST',
|
||||
dataType: 'json',
|
||||
data: { json: JSON.stringify({
|
||||
otp: '',
|
||||
company_id: 0,
|
||||
action: 'read',
|
||||
password: pw,
|
||||
})},
|
||||
headers: { 'X-CSRF-TOKEN': $('meta[name="csrf-token"]').attr('content') },
|
||||
success: function (res) {
|
||||
pw_score = res.score ?? -1;
|
||||
if (pw_score < 0) { reset_strength_ui(); return; }
|
||||
const lvl = STRENGTH_LEVELS[pw_score];
|
||||
$('#pw_strength_bar').css({ width: lvl.pct + '%', backgroundColor: lvl.color });
|
||||
$('#pw_strength_label').text(lvl.label).css('color', lvl.color);
|
||||
$('#pw_feedback').text(res.feedback || '');
|
||||
check_confirm_match();
|
||||
}
|
||||
});
|
||||
const result = zxcvbn(pw, user_inputs);
|
||||
pw_score = result.score;
|
||||
|
||||
const lvl = STRENGTH_LEVELS[pw_score];
|
||||
$('#pw_strength_bar').css({ width: lvl.pct + '%', backgroundColor: lvl.color });
|
||||
$('#pw_strength_label').text(lvl.label).css('color', lvl.color);
|
||||
$('#pw_feedback').text(result.feedback.warning || result.feedback.suggestions[0] || '');
|
||||
check_confirm_match();
|
||||
}
|
||||
|
||||
function reset_strength_ui() {
|
||||
|
||||
Reference in New Issue
Block a user