Erste drei Bausteine der Haertung: - Security-Headers (X-Content-Type-Options, X-Frame-Options, Referrer- Policy, Permissions-Policy, HSTS bei HTTPS) laufen automatisch ueber app_send_security_headers() am Ende von app/bootstrap.php fuer jede dynamische Seite; landing.php war als einzige Seite ganz ohne PHP und bekam einen minimalen Bootstrap-Aufruf. Bewusst kein CSP, da die bestehenden Templates durchgaengig auf Inline-style-Attribute setzen. - DB-gestuetzte Rate-Limits (neue Tabelle rate_limit_attempts) fuer Login (10/15min je E-Mail, 20/15min je IP), Registrierung (5/h je IP) und Passwort-Reset-Anfrage (5/h je E-Mail, 10/h je IP); bei ausgereiztem Reset-Limit erscheint dieselbe generische Meldung wie im Erfolgsfall, um kein Konto-Enumeration-Signal zu geben. - Zentrales Audit-Log (neue Tabelle audit_log) fuer Mitgliederverwaltung, Zugangsvergabe/-entzug, Storno, Mandant-Einstellungen, Hinweise, CSV-Import, Jahresbonus-Verteilung und Live-Mailversand; sichtbar fuer Owner/Admin auf mandant-einstellungen.php. Live getestet: Rate-Limit greift nach 10 Fehlversuchen, Audit-Log-Eintrag mit korrekten Metadaten und Nutzernamen ueber einen isolierten Test- Mandanten geprueft. Alle Regressionstests weiterhin gruen (26/26 Smoke, 104 Golden-Master-Assertions). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
118 lines
4.7 KiB
PHP
118 lines
4.7 KiB
PHP
<?php
|
|
|
|
require_once __DIR__ . '/functions.php';
|
|
require_once __DIR__ . '/app/rate-limit.php';
|
|
|
|
$pdo = app_db_pdo();
|
|
$errors = [];
|
|
$email = trim((string)($_POST['email'] ?? ''));
|
|
$tenantSlug = trim((string)($_POST['tenant_slug'] ?? ''));
|
|
|
|
if ($_SERVER['REQUEST_METHOD'] === 'POST') {
|
|
app_require_csrf();
|
|
|
|
$emailBucketOk = app_rate_limit_check($pdo, 'login_email:' . saas_email_norm($email), 10, 900);
|
|
$ipBucketOk = app_rate_limit_check($pdo, 'login_ip:' . app_client_ip(), 20, 900);
|
|
|
|
if (!$emailBucketOk || !$ipBucketOk) {
|
|
$errors = ['Zu viele Anmeldeversuche. Bitte versuche es in einigen Minuten erneut.'];
|
|
} else {
|
|
$result = saas_authenticate(
|
|
$pdo,
|
|
$email,
|
|
(string)($_POST['password'] ?? ''),
|
|
$tenantSlug
|
|
);
|
|
|
|
if ($result['ok'] && !empty($result['needs_tenant_selection'])) {
|
|
saas_start_pending_tenant_selection((int)$result['user_id']);
|
|
header('Location: mandant-auswahl.php');
|
|
exit;
|
|
}
|
|
|
|
if ($result['ok']) {
|
|
saas_session_login($result['identity']);
|
|
header('Location: konto.php');
|
|
exit;
|
|
}
|
|
|
|
$errors = $result['errors'];
|
|
}
|
|
}
|
|
|
|
?>
|
|
|
|
<!DOCTYPE HTML>
|
|
<html lang="de">
|
|
<head>
|
|
<title>Kaffeeliste Login</title>
|
|
<meta charset="utf-8" />
|
|
<meta name="viewport" content="width=device-width, initial-scale=1, user-scalable=no" />
|
|
<link rel="stylesheet" href="assets/css/main.css" />
|
|
<link rel="stylesheet" href="assets/css/public.css" />
|
|
</head>
|
|
<body class="is-preload public-page">
|
|
<div class="public-shell">
|
|
<section class="public-auth">
|
|
<nav class="public-nav" aria-label="Hauptnavigation">
|
|
<strong><a href="landing.php">Kaffeeliste</a></strong>
|
|
<ul class="actions">
|
|
<li><a href="register.php" class="button">Registrieren</a></li>
|
|
</ul>
|
|
</nav>
|
|
|
|
<div class="public-auth-grid">
|
|
<div class="public-auth-copy">
|
|
<h1>Login</h1>
|
|
<p>Melde dich mit deinem Kundenkonto an. Wenn du mehreren Mandanten zugeordnet bist, wählst du danach den passenden Bereich aus.</p>
|
|
</div>
|
|
|
|
<div class="public-panel">
|
|
<h2>Zur App</h2>
|
|
|
|
<?php if (isset($_GET['logged_out'])): ?>
|
|
<div class="hint-box success"><p>Du wurdest abgemeldet.</p></div>
|
|
<?php endif; ?>
|
|
|
|
<?php if ($errors !== []): ?>
|
|
<div class="hint-box error">
|
|
<?php foreach ($errors as $error): ?>
|
|
<p><?php echo saas_html($error); ?></p>
|
|
<?php endforeach; ?>
|
|
</div>
|
|
<?php endif; ?>
|
|
|
|
<form method="post" action="login.php">
|
|
<?php echo app_csrf_field(); ?>
|
|
<div class="row">
|
|
<div class="col-12">
|
|
<label for="email">E-Mail</label>
|
|
<input type="email" name="email" id="email" value="<?php echo saas_html($email); ?>" required>
|
|
</div>
|
|
<div class="col-12">
|
|
<label for="password">Passwort</label>
|
|
<input type="password" name="password" id="password" required>
|
|
</div>
|
|
<div class="col-12">
|
|
<label for="tenant_slug">Kundenkürzel</label>
|
|
<input type="text" name="tenant_slug" id="tenant_slug" value="<?php echo saas_html($tenantSlug); ?>" placeholder="optional">
|
|
</div>
|
|
</div>
|
|
<ul class="actions">
|
|
<li><button type="submit" class="primary">Einloggen</button></li>
|
|
<li><a href="passwort-vergessen.php" class="button">Passwort vergessen</a></li>
|
|
</ul>
|
|
</form>
|
|
</div>
|
|
</div>
|
|
</section>
|
|
</div>
|
|
|
|
<script src="assets/js/jquery.min.js"></script>
|
|
<script src="assets/js/browser.min.js"></script>
|
|
<script src="assets/js/breakpoints.min.js"></script>
|
|
<script src="assets/js/util.js"></script>
|
|
<script src="assets/js/main.js"></script>
|
|
</body>
|
|
</html>
|