- OTP attempt limits, constant-time compare, random reference codes - DB-backed rate limits (429) on sign-in, OTP, reset, register, onboarding - one generic sign-in failure message; reset request no longer reveals accounts - no password kept in the session; real status codes on failures
214 lines
7.2 KiB
PHP
214 lines
7.2 KiB
PHP
<?php
|
|
require '../session.php';
|
|
require '../config.php';
|
|
require_once '../assets/utils/otp_policy.php';
|
|
require __DIR__ . '/include_login_header.php';
|
|
// successful login — redirect based on app_access
|
|
if(!empty($_SESSION["login_status"])){
|
|
$redirect = ($_SESSION['login_app_access'] ?? 'wms') === 'accounting'
|
|
? $server_url . 'ac_dashboard/index.php'
|
|
: $server_url . 'dashboard/index.php';
|
|
header('Location: ' . $redirect);
|
|
exit;
|
|
}
|
|
|
|
?>
|
|
|
|
<body>
|
|
|
|
<div class="container d-flex align-items-center justify-content-center min-vh-100">
|
|
<div class="card " style="max-width:420px; width:100%;">
|
|
<div class="card-body p-5">
|
|
<div class="text-center mb-3">
|
|
<?php if (!empty($_SESSION['verify_error'])): ?>
|
|
<div class="alert alert-danger small py-2 mb-3">
|
|
<i class="ti ti-alert-circle me-1"></i>
|
|
<?php echo htmlspecialchars($_SESSION['verify_error']); unset($_SESSION['verify_error']); ?>
|
|
</div>
|
|
<?php endif; ?>
|
|
<a href="index.html" class="mb-5 d-inline-block">
|
|
<img src="<?php echo $server_url?>assets/images/logo.svg" alt="">
|
|
</a>
|
|
<h1 class="card-title mb-5 h5">Sign in to your account</h1>
|
|
</div>
|
|
|
|
<form class="needs-validation mt-3" novalidate id="login-form">
|
|
<!-- Whether email OTP is on is server configuration and is not shown to
|
|
anonymous visitors; password-only sign-ins are logged as OTP_BYPASSED
|
|
(assets/utils/otp_policy.php). -->
|
|
<!-- first step login [OTP] -->
|
|
<?php if(!isset($_SESSION['login_data'])){?>
|
|
<div class="mb-3">
|
|
<label for="username" class="form-label">Username</label>
|
|
<input id="username" type="username" class="form-control" placeholder="username" required autofocus>
|
|
<div class="invalid-feedback">Please enter a valid email.</div>
|
|
</div>
|
|
|
|
<div class="mb-3">
|
|
<label for="password" class="form-label d-flex justify-content-between">
|
|
<span>Password</span>
|
|
<a href="<?php echo $server_url?>login/forgot_password.php" class="small link-primary">Forgot password?</a>
|
|
</label>
|
|
<input id="password" type="password" class="form-control" placeholder="Password" required minlength="6">
|
|
<div class="invalid-feedback">Please provide a password (min 6 characters).</div>
|
|
</div>
|
|
|
|
<div class="d-flex justify-content-between align-items-center mb-3">
|
|
<!-- "Remember me" is intentionally excluded.
|
|
This login uses 2FA (OTP via email) on every session when OTP_REQUIRED=true in config.php (off by default).
|
|
A persistent login would bypass the OTP step and undermine the security model.
|
|
Do not add this back. -->
|
|
</div>
|
|
<button class="btn btn-primary w-100" onclick="login();">Sign in</button>
|
|
<p class="text-center text-muted small mt-3 mb-0">
|
|
Don't have an account?
|
|
<a href="<?php echo $server_url?>login/register.php" class="link-primary">Create one</a>
|
|
</p>
|
|
<?php }else{ ?>
|
|
<!-- second step login -->
|
|
<?php if (otp_required()): ?>
|
|
<div class="alert alert-warning small py-2 mb-3">
|
|
<i class="ti ti-mail me-1"></i>
|
|
OTP is sent via your company's SMTP setting.
|
|
If no SMTP is configured, you will be signed in directly without OTP.
|
|
<a href="<?php echo $server_url?>setting/smtp.php" class="alert-link ms-1">Configure SMTP →</a>
|
|
</div>
|
|
<div class="mb-3">
|
|
<label for="otp" class="form-label d-flex justify-content-between">
|
|
<span>One Time Password</span>
|
|
</label>
|
|
<input id="otp" type="otp" class="form-control"
|
|
placeholder="your otp for reference number <?php echo $_SESSION["reference"] ?? ''?>" required minlength="6">
|
|
<div class="invalid-feedback">Please provide a otp (min 6 characters).</div>
|
|
</div>
|
|
<?php else: ?>
|
|
<!-- OTP_REQUIRED was switched off while this session sat on the OTP step:
|
|
login_confirm.php no longer checks the code, so there is nothing to type. -->
|
|
<input id="otp" type="hidden" value="">
|
|
<?php endif; ?>
|
|
<div class="mb-3">
|
|
<label for="password" class="form-label d-flex justify-content-between">
|
|
<a href="javascript:;" class="small link-primary" onclick="back()">Back</a>
|
|
<?php if (otp_required()): ?>
|
|
<a href="javascript:;" class="small link-primary" onclick="request_new_otp();">Request New OTP</a>
|
|
<?php endif; ?>
|
|
</label>
|
|
</div>
|
|
<button class="btn btn-primary w-100" onclick="login_confirm();">Sign in</button>
|
|
<?php } ?>
|
|
</form>
|
|
|
|
|
|
</div>
|
|
</div>
|
|
</div>
|
|
|
|
|
|
<script>
|
|
|
|
|
|
// login function
|
|
function login() {
|
|
|
|
return ajax_request({
|
|
url: "<?php echo $server_url?>login/api/engine/login_otp.php",
|
|
autoPrepare: true,
|
|
checkRequired: 0,
|
|
action: 'read',
|
|
onSuccess: function(res) {
|
|
|
|
if (res.skip_otp) {
|
|
// Staff/viewer — no OTP required, confirm session directly
|
|
return ajax_request({
|
|
url: "<?php echo $server_url?>login/api/engine/login_confirm.php",
|
|
data: { json: JSON.stringify({ otp: '', action: 'read' }) },
|
|
onSuccess: function() {
|
|
window.location.href = "<?php echo $server_url?>index.php";
|
|
}
|
|
});
|
|
}
|
|
|
|
window.location.href = "<?php echo $server_url?>index.php";
|
|
|
|
}
|
|
});
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
|
|
// The server ended the pending sign-in (too many wrong OTPs, or the verified
|
|
// password is too old): show why, then return to the username/password step.
|
|
function restart_login_on(xhr) {
|
|
if (xhr?.responseJSON?.code !== 'login_restart') return;
|
|
bootbox.hideAll();
|
|
bootbox.alert(escape_html(xhr.responseJSON.message || 'Please sign in again.'), function() {
|
|
window.location.href = "<?php echo $server_url?>login/index.php";
|
|
});
|
|
}
|
|
|
|
// reqquest new otp function
|
|
function request_new_otp() {
|
|
|
|
return ajax_request({
|
|
url: "<?php echo $server_url?>login/api/engine/request_new_otp.php",
|
|
autoPrepare: true,
|
|
checkRequired: 0,
|
|
action: 'read',
|
|
onSuccess: function(res) {
|
|
|
|
window.location.href = "<?php echo $server_url?>index.php";
|
|
|
|
},
|
|
onError: restart_login_on
|
|
});
|
|
|
|
}
|
|
|
|
|
|
|
|
// log_out function
|
|
function back() {
|
|
|
|
return ajax_request({
|
|
url: "<?php echo $server_url?>login/api/engine/back.php",
|
|
autoPrepare: true,
|
|
checkRequired: 0,
|
|
action: 'read',
|
|
onSuccess: function(res) {
|
|
|
|
window.location.href = "<?php echo $server_url?>index.php";
|
|
|
|
}
|
|
});
|
|
|
|
}
|
|
|
|
|
|
|
|
// log_in confirm
|
|
function login_confirm() {
|
|
|
|
return ajax_request({
|
|
url: "<?php echo $server_url?>login/api/engine/login_confirm.php",
|
|
autoPrepare: true,
|
|
checkRequired: 0,
|
|
action: 'read',
|
|
onSuccess: function(res) {
|
|
|
|
window.location.href = "index.php";
|
|
|
|
},
|
|
onError: restart_login_on
|
|
});
|
|
|
|
}
|
|
</script>
|
|
|
|
|
|
</body>
|
|
|
|
</html>
|