Fix sites freeze bug, add features and shorten README
Bug fixes: - UniFiController: add CURLOPT_TIMEOUT (10s) and CURLOPT_CONNECTTIMEOUT (5s) to login() and apiRequest() — prevents page freeze when controller unreachable - UniFiController: fix login response validation for UniFi OS API which returns a user object instead of meta.rc=ok - admin/sites.php: add JS loading state on form submit to give visual feedback - login.php: handle new 'rate_limited' return value from Auth::login() New features: - Database: in-memory settings cache eliminates redundant DB queries per request - Auth: login rate limiting (10 attempts per 10 min per IP/email) via login_attempts table - admin/vouchers.php: CSV export with UTF-8 BOM for Excel compatibility - admin/vouchers.php: client-side pagination (50 per page) - index.php: QR code display after voucher creation (qrcodejs CDN) - Mailer: sendTestEmail() method - admin/settings.php: SMTP test button with AJAX handler - database.sql: add login_attempts and audit_log tables Readme: condensed from ~420 to ~220 lines, removed duplicated sections, M365 Azure Portal walkthrough, contribution guidelines, update/migration section https://claude.ai/code/session_01UsuvFAmmeagtQa14QA4iaq
This commit is contained in:
parent
3fd9b2190a
commit
73967caefa
11 changed files with 460 additions and 450 deletions
|
|
@ -23,19 +23,62 @@ class Auth {
|
|||
|
||||
// Benutzer einloggen
|
||||
public function login($email, $password) {
|
||||
$ip = $_SERVER['REMOTE_ADDR'] ?? '0.0.0.0';
|
||||
|
||||
if ($this->isRateLimited($ip, $email)) {
|
||||
return 'rate_limited';
|
||||
}
|
||||
|
||||
$user = $this->db->fetchOne(
|
||||
"SELECT * FROM users WHERE email = ? AND is_active = 1",
|
||||
[$email]
|
||||
);
|
||||
|
||||
|
||||
if ($user && password_verify($password, $user['password_hash'])) {
|
||||
$this->clearLoginAttempts($ip, $email);
|
||||
$this->setUserSession($user);
|
||||
$this->updateLastLogin($user['id']);
|
||||
return true;
|
||||
}
|
||||
|
||||
|
||||
$this->recordLoginAttempt($ip, $email);
|
||||
return false;
|
||||
}
|
||||
|
||||
private function isRateLimited($ip, $email) {
|
||||
try {
|
||||
$count = $this->db->fetchOne(
|
||||
"SELECT COUNT(*) as cnt FROM login_attempts
|
||||
WHERE (ip_address = ? OR email = ?) AND attempted_at > DATE_SUB(NOW(), INTERVAL 10 MINUTE)",
|
||||
[$ip, $email]
|
||||
);
|
||||
return $count && (int)$count['cnt'] >= 10;
|
||||
} catch (\Exception $e) {
|
||||
return false;
|
||||
}
|
||||
}
|
||||
|
||||
private function recordLoginAttempt($ip, $email) {
|
||||
try {
|
||||
$this->db->query(
|
||||
"INSERT INTO login_attempts (ip_address, email) VALUES (?, ?)",
|
||||
[$ip, $email]
|
||||
);
|
||||
} catch (\Exception $e) {
|
||||
// Tabelle existiert noch nicht – ignorieren
|
||||
}
|
||||
}
|
||||
|
||||
private function clearLoginAttempts($ip, $email) {
|
||||
try {
|
||||
$this->db->query(
|
||||
"DELETE FROM login_attempts WHERE ip_address = ? OR email = ?",
|
||||
[$ip, $email]
|
||||
);
|
||||
} catch (\Exception $e) {
|
||||
// ignore
|
||||
}
|
||||
}
|
||||
|
||||
// Microsoft 365 Login
|
||||
public function loginWithMicrosoft($microsoftUser) {
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue