Files
wms-app/app/login/verify.php
T

74 lines
3.0 KiB
PHP

<?php
require '../session.php';
require '../config.php';
require '../dbconn.php';
require '../assets/utils/db_helpers.php';
$answer = ['success' => 0, 'message' => ''];
$token = trim($_GET['token'] ?? '');
if (!$token) {
header('Location: ' . $server_url . 'login/index.php');
exit;
}
// ── Look up token ─────────────────────────────────────────────
// license='owner' guard: invited users also have verify_token set, but they
// must use invited_onboarding.php — never this flow.
$sth = $pdo1->prepare("
SELECT user_id, name, status, verify_expires_at
FROM user
WHERE verify_token = :token
AND license = 'owner'
LIMIT 1
");
$sth->execute([':token' => $token]);
$user = $sth->fetch(PDO::FETCH_ASSOC);
// ── Invalid token ─────────────────────────────────────────────
if (!$user) {
$_SESSION['verify_error'] = 'This verification link is invalid or has already been used.';
header('Location: ' . $server_url . 'login/index.php');
exit;
}
// ── Already verified — check if onboarding still needed ───────
if ($user['status'] === 'active') {
$sth = $pdo1->prepare("
SELECT default_company FROM user WHERE user_id = :id LIMIT 1
");
$sth->execute([':id' => $user['user_id']]);
$default_company = $sth->fetchColumn();
if (empty($default_company)) {
// Verified but never completed onboarding — resume it
$_SESSION['onboarding_user_id'] = (int)$user['user_id'];
$_SESSION['onboarding_name'] = $user['name'];
session_write_close();
header('Location: ' . $server_url . 'login/onboarding.php');
} else {
// Fully set up — just go to login
header('Location: ' . $server_url . 'login/index.php');
}
exit;
}
// ── Expired ───────────────────────────────────────────────────
if (strtotime($user['verify_expires_at']) < time()) {
// Delete the expired pending account
$sth = $pdo1->prepare("DELETE FROM user WHERE user_id = :id AND status = 'pending'");
$sth->execute([':id' => $user['user_id']]);
$_SESSION['verify_error'] = 'This verification link has expired. Please register again.';
header('Location: ' . $server_url . 'login/index.php');
exit;
}
// ── Store user_id in session for onboarding ───────────────────
$_SESSION['onboarding_user_id'] = (int)$user['user_id'];
$_SESSION['onboarding_name'] = $user['name'];
session_write_close();
header('Location: ' . $server_url . 'login/onboarding.php');
exit;?>