stock aggregate table
This commit is contained in:
@@ -99,21 +99,21 @@ $_SESSION["diff"] = $otp_diff_minutes;
|
||||
// If session_token is non-NULL AND was set within the last 8 hours, another
|
||||
// session is active — reject. Tokens older than 8 hours are treated as
|
||||
// abandoned (browser crash, PHP GC expiry, etc.) and cleared automatically.
|
||||
$sth_token = $pdo1->prepare("SELECT session_token, session_token_at FROM user WHERE user_id = :uid LIMIT 1");
|
||||
$sth_token = $pdo1->prepare("SELECT session_token, session_last_seen FROM user WHERE user_id = :uid LIMIT 1");
|
||||
$sth_token->execute([':uid' => $user_id]);
|
||||
$token_row = $sth_token->fetch(PDO::FETCH_ASSOC);
|
||||
$token_row = $sth_token->fetch(PDO::FETCH_ASSOC);
|
||||
$existing_token = $token_row['session_token'] ?? null;
|
||||
if (!empty($existing_token)) {
|
||||
$token_age_hours = PHP_INT_MAX;
|
||||
if (!empty($token_row['session_token_at'])) {
|
||||
$token_age_hours = (time() - strtotime($token_row['session_token_at'])) / 3600;
|
||||
$idle_seconds = PHP_INT_MAX;
|
||||
if (!empty($token_row['session_last_seen'])) {
|
||||
$idle_seconds = time() - strtotime($token_row['session_last_seen']);
|
||||
}
|
||||
if ($token_age_hours < 8) {
|
||||
if ($idle_seconds < (int)ini_get('session.gc_maxlifetime')) {
|
||||
$answer["message"] = "This account is currently logged in on another device. Please wait for the other session to end.";
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
// Stale token — clear it and proceed with login
|
||||
$pdo1->prepare("UPDATE user SET session_token = NULL, session_token_at = NULL WHERE user_id = :uid")
|
||||
// PHP GC has expired this session — clear token and allow login
|
||||
$pdo1->prepare("UPDATE user SET session_token = NULL, session_token_at = NULL, session_last_seen = NULL WHERE user_id = :uid")
|
||||
->execute([':uid' => $user_id]);
|
||||
}
|
||||
|
||||
|
||||
@@ -361,6 +361,9 @@ if (password_verify(trim($data["password"]), $temp["password"])) {
|
||||
$_SESSION["user_email"] = $user_email; // shown masked on OTP screen
|
||||
$_SESSION["login_user_id"] = $user_id; // used by login_confirm.php to build the login session
|
||||
$_SESSION["no_smtp"] = empty($smtp_config); // true = skip OTP step on login page
|
||||
if (empty($smtp_config)) {
|
||||
$_SESSION['skip_otp'] = true;
|
||||
}
|
||||
|
||||
// ── Step 10: Respond ──────────────────────────────────────────────────────
|
||||
$answer["success"] = 1;
|
||||
|
||||
Reference in New Issue
Block a user