M3 Passwort-Reset und E-Mail-Verifikation ergänzen

- Auth-Token-Tabelle mit gehashten Single-Use-Tokens einführen
- Passwort-Reset und E-Mail-Verifikation als Dev-Flow bauen
- Token-Flow-Test, Smoke-Abdeckung und M3-Dokumentation aktualisieren
This commit is contained in:
2026-07-13 19:26:58 +02:00
parent 19ff11c21a
commit 8ab4a8a9bb
15 changed files with 740 additions and 9 deletions
+23
View File
@@ -3,6 +3,11 @@
require_once __DIR__ . '/functions.php';
$user = saas_require_login();
$devVerificationToken = null;
if (saas_should_show_auth_links() && !empty($_SESSION['saas_dev_email_verification_token'])) {
$devVerificationToken = (string)$_SESSION['saas_dev_email_verification_token'];
unset($_SESSION['saas_dev_email_verification_token']);
}
include 'header.php';
include 'headerline.php';
@@ -17,6 +22,13 @@ include 'nav.php';
<div class="hint-box success"><p>Das Kundenkonto wurde angelegt.</p></div>
<?php endif; ?>
<?php if ($devVerificationToken !== null): ?>
<div class="hint-box success">
<p>Der Verifizierungslink wurde vorbereitet.</p>
<p><a href="email-verifizieren.php?token=<?php echo saas_html($devVerificationToken); ?>">Dev-Link zur E-Mail-Verifizierung</a></p>
</div>
<?php endif; ?>
<table>
<tr>
<th>Name</th>
@@ -38,8 +50,19 @@ include 'nav.php';
<th>Rolle</th>
<td><?php echo saas_html($user['role']); ?></td>
</tr>
<tr>
<th>E-Mail bestaetigt</th>
<td><?php echo $user['email_verified_at'] !== null ? 'ja' : 'nein'; ?></td>
</tr>
</table>
<?php if ($user['email_verified_at'] === null): ?>
<form method="post" action="email-verifikation-senden.php">
<?php echo app_csrf_field(); ?>
<button type="submit">E-Mail-Verifizierung vorbereiten</button>
</form>
<?php endif; ?>
<?php if (saas_can_manage_tenant_settings($user)): ?>
<ul class="actions">
<li><a href="mandant-einstellungen.php" class="button">Mandant-Einstellungen</a></li>