Files
wms-app/app/login/api/engine/accept_invite.php
T
Thanakorn 73c680e844 Harden sign-in and password reset
- OTP attempt limits, constant-time compare, random reference codes
- DB-backed rate limits (429) on sign-in, OTP, reset, register, onboarding
- one generic sign-in failure message; reset request no longer reveals accounts
- no password kept in the session; real status codes on failures
2026-09-24 14:53:40 +07:00

91 lines
3.4 KiB
PHP
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
<?php
/**
* accept_invite.php — Accept a company invitation for an existing user.
*
* Called by accept_invite.php page AJAX after the user clicks Accept.
* The user already has an active account; this just clears the invite_token
* on their company_map_user row, making them a full member.
*
* Full flow:
* 1. Session guard — rejects if accept_invite_token is missing.
* 2. CSRF check.
* 3. Re-validate token against DB (not expired, invite_token still set).
* 4. Clear invite_token and invite_expires_at from company_map_user.
* 5. Verify exactly one row was updated.
* 6. Clear session keys.
* 7. Return { success: 1 }.
*/
require_once '../../../session.php';
require_once '../../../config.php';
require_once '../../../preset.php';
define('UNAUTHENTICATED_ROUTE', true);
require_once '../../../assets/utils/db_auth.php';
header('Content-Type: application/json; charset=utf-8');
$answer = ['success' => 0, 'message' => ''];
// ── Step 1: Session guard ─────────────────────────────────────────────────────
if (empty($_SESSION['accept_invite_token'])) {
$answer['message'] = 'Invalid session. Please use your invitation link.';
http_response_code(403);
exit(json_encode($answer));
}
$token = $_SESSION['accept_invite_token'];
// ── Step 2: CSRF check ────────────────────────────────────────────────────────
if ($_SERVER['REQUEST_METHOD'] === 'POST') {
$csrf = $_SERVER['HTTP_X_CSRF_TOKEN'] ?? '';
if (empty($csrf) || !hash_equals((string)($_SESSION['csrf_token'] ?? ''), $csrf)) {
http_response_code(403);
$answer['message'] = 'Invalid request.';
exit(json_encode($answer));
}
}
try {
// ── Step 3: Re-validate token ─────────────────────────────────────────────
$sth = $pdo1->prepare(
"SELECT map_id FROM company_map_user
WHERE invite_token = :token
AND invite_expires_at > NOW()
LIMIT 1"
);
$sth->execute([':token' => $token]);
if (!$sth->fetchColumn()) {
$answer['message'] = 'Invitation has expired or already been used.';
http_response_code(403);
exit(json_encode($answer));
}
// ── Step 4–5: Activate membership ────────────────────────────────────────
$stmt = $pdo1->prepare(
"UPDATE company_map_user
SET invite_token = NULL,
invite_expires_at = NULL
WHERE invite_token = :token"
);
$stmt->execute([':token' => $token]);
if ($stmt->rowCount() !== 1) {
$answer['message'] = 'Invitation is no longer valid.';
http_response_code(403);
exit(json_encode($answer));
}
// ── Step 6: Clear session keys ────────────────────────────────────────────
unset($_SESSION['accept_invite_token']);
$answer['success'] = 1;
$answer['message'] = 'Invitation accepted.';
} catch (Exception $e) {
$answer['message'] = $e->getMessage();
http_response_code(400);
}
exit(json_encode($answer));