Files
wms-app/app/login/index.php
T
Thanakorn c957280aa5 Add Asset Management app
Assets from purchase invoice lines, straight-line depreciation/amortization with salvage value, disposals, and [Asset Mgmt] sources in Batch GL Entries. Green third workspace with an app access guard.
2026-09-15 09:50:55 +07:00

206 lines
6.9 KiB
PHP

<?php
require '../session.php';
require '../config.php';
require_once '../assets/utils/otp_policy.php';
require '../include_header.php';
require_once '../assets/utils/app_registry.php';
// successful login — redirect based on app_access
if(!empty($_SESSION["login_status"])){
$login_app = app_default_for_access($app_registry, $_SESSION['login_app_access'] ?? 'wms');
$redirect = $server_url . app_home_path($app_registry, $login_app);
header('Location: ' . $redirect);
exit;
}
?>
<body>
<div class="container d-flex align-items-center justify-content-center min-vh-100">
<div class="card " style="max-width:420px; width:100%;">
<div class="card-body p-5">
<div class="text-center mb-3">
<?php if (!empty($_SESSION['verify_error'])): ?>
<div class="alert alert-danger small py-2 mb-3">
<i class="ti ti-alert-circle me-1"></i>
<?php echo htmlspecialchars($_SESSION['verify_error']); unset($_SESSION['verify_error']); ?>
</div>
<?php endif; ?>
<a href="index.html" class="mb-5 d-inline-block">
<img src="<?php echo $server_url?>assets/images/logo.svg" alt="">
</a>
<h1 class="card-title mb-5 h5">Sign in to your account</h1>
</div>
<form class="needs-validation mt-3" novalidate id="login-form">
<?php if (!otp_required()): ?>
<!-- OTP_REQUIRED is not true in config.php (the default): a password-only sign-in must never be invisible -->
<div class="alert alert-warning small py-2 mb-3" title="OTP_REQUIRED is not true in config.php">
<i class="ti ti-alert-triangle me-1"></i>
Email OTP is off — sign-in is password only.
</div>
<?php endif; ?>
<!-- first step login [OTP] -->
<?php if(!isset($_SESSION['login_data'])){?>
<div class="mb-3">
<label for="username" class="form-label">Username</label>
<input id="username" type="username" class="form-control" placeholder="username" required autofocus>
<div class="invalid-feedback">Please enter a valid email.</div>
</div>
<div class="mb-3">
<label for="password" class="form-label d-flex justify-content-between">
<span>Password</span>
<a href="<?php echo $server_url?>login/forgot_password.php" class="small link-primary">Forgot password?</a>
</label>
<input id="password" type="password" class="form-control" placeholder="Password" required minlength="6">
<div class="invalid-feedback">Please provide a password (min 6 characters).</div>
</div>
<div class="d-flex justify-content-between align-items-center mb-3">
<!-- "Remember me" is intentionally excluded.
This login uses 2FA (OTP via email) on every session when OTP_REQUIRED=true in config.php (off by default).
A persistent login would bypass the OTP step and undermine the security model.
Do not add this back. -->
</div>
<button class="btn btn-primary w-100" onclick="login();">Sign in</button>
<p class="text-center text-muted small mt-3 mb-0">
Don't have an account?
<a href="<?php echo $server_url?>login/register.php" class="link-primary">Create one</a>
</p>
<?php }else{ ?>
<!-- second step login -->
<?php if (otp_required()): ?>
<div class="alert alert-warning small py-2 mb-3">
<i class="ti ti-mail me-1"></i>
OTP is sent via your company's SMTP setting.
If no SMTP is configured, you will be signed in directly without OTP.
<a href="<?php echo $server_url?>setting/smtp.php" class="alert-link ms-1">Configure SMTP →</a>
</div>
<div class="mb-3">
<label for="otp" class="form-label d-flex justify-content-between">
<span>One Time Password</span>
</label>
<input id="otp" type="otp" class="form-control"
placeholder="your otp for reference number <?php echo $_SESSION["reference"] ?? ''?>" required minlength="6">
<div class="invalid-feedback">Please provide a otp (min 6 characters).</div>
</div>
<?php else: ?>
<!-- OTP_REQUIRED was switched off while this session sat on the OTP step:
login_confirm.php no longer checks the code, so there is nothing to type. -->
<input id="otp" type="hidden" value="">
<?php endif; ?>
<div class="mb-3">
<label for="password" class="form-label d-flex justify-content-between">
<a href="javascript:;" class="small link-primary" onclick="back()">Back</a>
<?php if (otp_required()): ?>
<a href="javascript:;" class="small link-primary" onclick="request_new_otp();">Request New OTP</a>
<?php endif; ?>
</label>
</div>
<button class="btn btn-primary w-100" onclick="login_confirm();">Sign in</button>
<?php } ?>
</form>
</div>
</div>
</div>
<script>
// login function
function login() {
return ajax_request({
url: "<?php echo $server_url?>login/api/engine/login_otp.php",
autoPrepare: true,
checkRequired: 0,
action: 'read',
onSuccess: function(res) {
if (res.skip_otp) {
// Staff/viewer — no OTP required, confirm session directly
return ajax_request({
url: "<?php echo $server_url?>login/api/engine/login_confirm.php",
data: { json: JSON.stringify({ otp: '', action: 'read' }) },
onSuccess: function() {
window.location.href = "<?php echo $server_url?>index.php";
}
});
}
window.location.href = "<?php echo $server_url?>index.php";
}
});
}
// reqquest new otp function
function request_new_otp() {
return ajax_request({
url: "<?php echo $server_url?>login/api/engine/request_new_otp.php",
autoPrepare: true,
checkRequired: 0,
action: 'read',
onSuccess: function(res) {
window.location.href = "<?php echo $server_url?>index.php";
}
});
}
// log_out function
function back() {
return ajax_request({
url: "<?php echo $server_url?>login/api/engine/back.php",
autoPrepare: true,
checkRequired: 0,
action: 'read',
onSuccess: function(res) {
window.location.href = "<?php echo $server_url?>index.php";
}
});
}
// log_in confirm
function login_confirm() {
return ajax_request({
url: "<?php echo $server_url?>login/api/engine/login_confirm.php",
autoPrepare: true,
checkRequired: 0,
action: 'read',
onSuccess: function(res) {
window.location.href = "index.php";
}
});
}
</script>
</body>
</html>