175 Commits

Author SHA1 Message Date
dillard f8addb95f1 Rebrand to QRForge (local only - do not push before domain confirmed)
Applies the approved QRForge brand kit throughout the app:
- New logo/icon SVGs, favicon set (ico/svg/png), apple-touch-icon, all
  copied from the approved brand kit into src/dist/img/brand/. Old
  Symbol_WhiteBlue.png/DynamicQRCode_Original.png removed (unused after
  the swap).
- Sidebar brand image/text, login and change-password page logos, all
  <title> tags, manifest.json name/theme-color, and the PWA icons
  (dist/img/icon-192.png/icon-512.png, same filenames so no other
  reference needed to change) updated to QRForge branding and the
  #2563EB brand blue.
- New about.php page (+ sidebar link): credits the original upstream
  fork (Giandonato Inverso) and chillerlan/php-qrcode, links to the free
  qr.ensembia.com try-out, the commercial www.qrforge.eu product page,
  and this GitHub repo for self-hosters.
- Footer now reads "QRForge" + "About / credits" + "Version 3.0"
  (replaces the inherited "PHP Qrcode Generator by Giandonato Inverso" /
  "Version 2.3.0" line - full credit moved to the About page instead).
- README.md rewritten: current feature set (all 16 static qr types,
  presets, scanner, PWA, location search, roles), qr.ensembia.com as the
  free try-out, www.qrforge.eu as the commercial product page, corrected
  Docker Compose setup steps (.env is required now, the old README still
  described the single-file demo setup from the original upstream fork).

IMPORTANT: not pushed to origin/gitea. Per user instruction, no push
until qrforge.eu domain registration is confirmed.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fo3DiRRpmz2DXjD7Uzhc8u
2026-07-11 02:48:05 +02:00
dillard bffd9a315b Fase 3 feedback round 4: group filename with owner in the qr forms
Filename now sits in the same row as Owner instead of the crowded
top row shared with format/frame text/frame font/frame font size/icon.
Freeing that column lets those fields shift left and use the space
better. Applied to both the shared static-form partial
(qrcode_options.php) and the dynamic-form's separate copy of the same
fields (form_dynamic_add.php) - the two have diverged since Fase 3 and
don't share markup. Edit forms (form_static_edit.php/form_dynamic_edit.php)
already had filename/owner side by side, no change needed there.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fo3DiRRpmz2DXjD7Uzhc8u
2026-07-11 02:40:22 +02:00
dillard 23c30db5e0 Fase 3 feedback round 3: sidebar icons, thumbnail preview, location search
- Sidebar submenu bullets (List all/Add new/Batch create) swapped from
  far fa-circle to fas fa-angle-right - the outlined circle read as an
  unchecked radio button, per feedback.
- List-page qr thumbnails now sit in a fixed 100x100 box with
  object-fit:contain instead of width/height attrs, so taller images
  (e.g. icon-above-qr) no longer get squashed into a square. Thumbnails
  are now clickable, opening a shared Bootstrap modal with the full-size
  image (same data-toggle/data-target pattern already used for the
  delete-confirmation modal).
- Location QR form gets an address search box backed by OpenStreetMap
  Nominatim (dist/js/location-search.js): free-text query, pick a result,
  it fills in latitude/longitude. No API key needed; the browser talks to
  nominatim.openstreetmap.org directly, called out in the field's help
  text since queries leave the self-hosted server.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fo3DiRRpmz2DXjD7Uzhc8u
2026-07-11 02:18:34 +02:00
dillard 175cbb91bf Fase 3 feedback round 2: live color preview, bigger top icon, dashboard links
- Style preview now updates immediately when picking a color via the
  colorpicker widget. It sets the input value through jQuery's synthetic
  trigger(), which a native addEventListener('change', ...) never sees -
  bound the listener through jQuery instead so both native and
  colorpicker-driven changes refresh the preview.
- Icon-above-QR max height raised from 25% to 62.5% of QR height (~2.5x
  bigger per feedback); the existing 60%-width cap now becomes the
  practical limit for most icons. Verified generated QR still decodes.
- Dashboard's "Dynamic Qr codes" and "Static QR codes" info-boxes now link
  to their list pages. "Total qr codes"/"Total Scans" left as-is - no
  combined-list or scan-report page exists yet to link them to.
- Random-style button now has a "Randomize" label to match its row-mates
  (Load preset/Save as preset/Style preview), instead of an empty spacer.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fo3DiRRpmz2DXjD7Uzhc8u
2026-07-11 02:09:58 +02:00
dillard 9cdfbe7a10 Fase 3 feedback round: style preview, icon upload, font choice, optional bitcoin amount, WPA3
- Default the Owner select to the creator's own account instead of "All", so
  superadmin-created codes no longer silently become visible to every admin
  (the underlying NULL-fallback sharing behavior for an explicit "All" choice
  is unchanged).
- Add a live color/precision/size preview swatch next to the preset picker.
- Let the frame text use a chosen DejaVu font + font size instead of a fixed
  GD bitmap font.
- Add an optional self-uploaded icon rendered above the qr code (not embedded
  in it, so scanability is unaffected).
- Make the Bitcoin qr amount optional; a standing wallet address is useful
  without forcing a one-off amount per code.
- Add a WPA3 option to the WiFi qr encryption select.
- Fix a real bug surfaced while testing the preview/style JS: qrcode_options.php
  was included once per static qr type (16 times on one page) and each
  inclusion re-executed <script src="qrcode-style-tools.js">, so every button
  click fired once per type - e.g. saving one preset wrote 16 duplicate rows,
  and every tab except the first ("Text") had dead random-style/preset
  buttons since only the first DOM match ever got a listener. Moved the
  script include to load once per page and rewrote the JS to scope every
  lookup to the triggering element's own tab-pane/form instead of relying on
  getElementById's first-match behavior.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0196bLhZhuxwK3MkHuKLe5WB
2026-07-09 23:11:36 +02:00
dillard be9164850a Fase 3 priority 2: presets, random style, qr scanner, PWA
Preset system: qr_presets table (migration 005) plus a presets.php AJAX
endpoint (list/save/delete, CSRF-protected, scoped to the logged-in user's
own id - presets are personal, never shared across accounts). UI/JS lives in
dist/js/qrcode-style-tools.js.

Random style button: client-side only, fills foreground/background with a
random hex color pair (playful randomize, no contrast/scannability
guarantee).

Qr scanner (scan_qrcode.php): camera or image upload, decoded entirely
client-side via html5-qrcode (CDN, pinned to 2.3.8).

PWA: manifest.json + service-worker.js, icons generated from the existing
DynamicQRCode_Original.png glyph. The service worker only caches static
assets (css/js/images) and deliberately never touches PHP pages, since those
carry CSRF tokens and session-specific content that must never be cached.

Fixes a gap found while testing: qrcode_options.php is only a shared partial
for the static qr forms - the dynamic qr form (form_dynamic_add.php) has its
own separate copy of the foreground/background/level/size/filename/format
fields (pre-existing structure, not something introduced here). That meant
frame_text and the new preset/random-style UI never showed up on the
dynamic qr page. Added the same fields there too, verified with a dynamic qr
plus frame text (150x180px, the expected +30px padding).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-09 00:49:45 +02:00
dillard f7d2de355e Fase 3 v1: new qr types, svg export, clipboard, frame text, batch CSV
New static qr types:
- App Link: Android intent:// links (with package + optional browser
  fallback) or a generic custom-scheme URI. iOS Universal Links need no
  special encoding (they're just plain https:// URLs).
- Bluetooth: device name + MAC address. Purely informational, since unlike
  WIFI:/vCard there's no OS-native "scan to pair" convention.

SVG export: already worked (format whitelist/dropdown existed since Fase 1),
verified rather than reimplemented.

Copy-to-clipboard button next to the download button on both qr list tables,
using the Clipboard API against a fetched blob.

Optional frame text label rendered below the qr code via GD after
generation (raster formats only, no-op for svg/eps).

Batch CSV upload (batch_qrcode.php): filename,link rows create dynamic qr
codes with sane defaults, downloadable as a zip. Required refactoring
Qrcode-intchil.php's generation path (previously always redirected/exited
via failure()/success(), which can't run in a loop) into a private
renderAndStore() that throws instead, shared by addQrcode() and the new
addQrcodeBatch(). Qrcode.php's addQrcodeBatch() is a separate, deliberately
duplicated implementation instead, since its generation logic is small
enough that duplication carries less risk than refactoring the working
external-API code path.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-09 00:03:01 +02:00
dillard b5ef4ac0cb Admin-scoped user accounts, secure qr code storage, PHP 8.4 upgrade
Admin-scoped users (answers: who can create a 'user' account, only super or
also an admin within their own scope?):
- New owner_admin_id column on users (migration 004). NULL means created by
  super (company-wide, previous behavior); otherwise scoped to that admin's
  own codes.
- Users::addUser/editUser/deleteUser now allow an 'admin' session, but force
  type='user' and owner_admin_id to their own id regardless of submitted
  input. user.php/users.php open up to admins with a restricted UI (no type
  picker, listing limited to their own created users).
- New qr_compute_scope_owner_id()/qr_apply_owner_scope()/qr_has_full_visibility()
  helpers in includes/security.php, replacing the ad-hoc type==='admin' checks
  in index.php, dynamic_qrcodes.php, static_qrcodes.php and bulk_action.php.
  A 'user' account created by an admin is now scoped to that admin's codes
  instead of seeing everything company-wide.

Qr code storage hardening: images were served as plain static files under the
document root with no auth check at all. Storage now lives outside the web
root; qrcode_image.php and qrcode_zip_download.php gate access with the same
permission model as the list pages, and the bulk zip download is bound to the
session that generated it.

PHP 8.4 + chillerlan/php-qrcode 6.0.1: bumped since this is a dockerized app,
so the PHP version shipped doesn't matter to end users. Note: the 6.0.1 tag
itself only requires PHP 8.2 - the earlier "needs 8.4" read was from an
unpinned clone of master, which has since moved past the tag. Fixed along the
way, surfaced by testing on 8.4:
- The hardcoded Imagick build (an old pinned master commit, workaround for
  3.7.0 being broken on PHP 8.3+) no longer compiles on 8.4. Imagick 3.8.1 is
  now a normal stable release, so the workaround is gone.
- config.php had display_errors=On + error_reporting(E_ALL), so PHP 8.4's new
  deprecation notices got dumped straight into the response before
  session_start() could run, breaking login outright. Also an info-disclosure
  risk on its own. Now logged instead of displayed.
- MysqliDb::insertMulti() had an implicit nullable parameter, now explicit.
- includes/auth_validate.php redirected unauthenticated requests but never
  called exit(), so the rest of the script kept running.
- Dockerfile.fpm was missing both git (needed to clone chillerlan/php-qrcode)
  and the imagick extension entirely.

Also removes the unused sample qr code images that shipped in the original
repo; storage now lives outside the document root so they were never going
to be served again.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-08 20:38:58 +02:00
dillard a1ab16d54c Fase 2: read-only user role with per-category view toggles
Adds a third account type 'user' alongside super/admin: no create/edit/delete
rights on qr codes, view access to dynamic/static lists gated per-account by
two admin-controlled toggles (can_view_static, can_view_dynamic), and always
full visibility into the dashboard/reports regardless of those toggles.

- New columns can_view_static/can_view_dynamic on users (migrations/003)
- Users class + form_users.php: 'user' type option with the two toggles
- Access control: dynamic_qrcode.php/static_qrcode.php/bulk_action.php reject
  all mutations for type=user; dynamic_qrcodes.php/static_qrcodes.php enforce
  the view toggle and show all codes (no owner scoping, since 'user' owns none)
- Sidebar and list tables hide add/edit/delete/bulk UI for the read-only role
- index.php dashboard stats are unscoped for both 'super' and 'user'

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-08 16:37:25 +02:00
dillard feb5380b28 Security hardening: CSRF, rate limiting, session/password policy, audit log
Fixes critical pre-existing issues found during review: bulk_action.php had no
auth check at all (unauthenticated download/delete of any qrcode) and built a
table name from unwhitelisted user input (SQL injection); the QR generator
classes wrote files from unvalidated filename/format, allowing path traversal
and arbitrary file writes. Also pins chillerlan/php-qrcode to 5.0.5 since
master now requires PHP 8.4, breaking the PHP 8.3 build.

- CSRF tokens on all POST forms and the bulk_action.php JSON endpoint
- Login rate limiting (5 attempts / 15 min) via new login_attempts table
- Hardened sessions: httponly/samesite cookies, 30 min idle timeout,
  session regeneration on login
- Forced password change for the default superadmin/superadmin account
- Server-side validation in Users/DynamicQrcode/Qrcode classes
- Audit log table for auth, user, and qrcode actions
- Checked-in db schema (db/init.sql, migrations/) instead of relying on an
  opaque prebuilt db image
- Production docker-compose with Nginx + php-fpm instead of the PHP dev server

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-08 15:00:33 +02:00
Giandonato Inverso 268a6a3f65 Remove unnecessary extra information from documentation 2025-09-02 21:56:03 +02:00
Giandonato Inverso 812db2bf9b Delete support section from index.html 2025-09-02 21:53:41 +02:00
Giandonato Inverso 48d7fefd02 Remove donation button from README 2025-09-02 21:52:03 +02:00
Giandonato Inverso 27a5dbd466 Merge pull request #144 from CLAlberto/master
fix(read.php): replace deprecated FILTER_SANITIZE_STRING for PHP 8.3 …
2025-05-08 08:56:07 +02:00
CLAlberto 2c3f2bb030 fix(read.php): replace deprecated FILTER_SANITIZE_STRING for PHP 8.3 compatibility
### Problem

The usage of `FILTER_SANITIZE_STRING` in `read.php` causes a deprecation warning in PHP 8.1 and breaks functionality entirely in PHP 8.3, as the constant was removed.

### Solution

This commit replaces:
```php
filter_input(INPUT_GET, 'id', FILTER_SANITIZE_STRING);



with a safer and future-proof alternative:

$id = filter_input(INPUT_GET, 'id', FILTER_UNSAFE_RAW);
$id = trim(strip_tags($id));


> _Thanks for maintaining this project! Happy to contribute._ 😊
2025-05-06 16:16:22 +02:00
Giandonato Inverso e4d3af69b5 Merge pull request #143 from angelosleebos/patch-1
Make environment variables compatible for other platforms
2025-04-14 12:19:34 +02:00
Giandonato Inverso 938d934b51 Merge pull request #142 from rafinou62/patch-1
Update read.php prevent SQL Injection & XSS attacks
2025-04-14 12:18:32 +02:00
Angelo Sleebos cee6f4d3d5 Make environment variables compatible for other platforms
Make environment variables compatible for other platforms
2025-04-07 01:11:17 +02:00
Raphaël Wanecque 1465ce02ad Update read.php prevent SQL Injection & XSS attacks 2025-03-26 17:04:33 +01:00
giandonato.inverso@edempg.it ba57334142 edit demo url 2025-03-22 15:51:02 +01:00
giandonato.inverso@edempg.it 615d983828 config rollback 2025-03-20 23:38:55 +01:00
giandonato.inverso@edempg.it b245694824 Merge remote-tracking branch 'origin/master' 2025-03-19 23:40:50 +01:00
giandonato.inverso@edempg.it 378968576f bug fix Class Qrcode not found 2025-03-19 23:40:36 +01:00
Giandonato Inverso 0d4368575b Merge pull request #136 from MickGe/patch-1
add cookies secure flags
2025-02-09 16:16:53 +01:00
MickGe 05e80a075a add cookies secure flags 2025-02-07 11:35:24 +01:00
giandonato.inverso@edempg.it 92a1f17dbe updated readme and docs 2025-01-21 22:41:14 +01:00
giandonato.inverso@edempg.it d1505e1e08 updated readme 2025-01-12 23:50:15 +01:00
giandonato.inverso@edempg.it f05c073ad4 Local setup eliminated and documentation updated 2025-01-12 23:48:49 +01:00
giandonato.inverso@edempg.it 79d9ac71a3 Merge remote-tracking branch 'origin/master' 2025-01-12 19:48:31 +01:00
Giandonato Inverso ffc5b64967 Merge pull request #130 from Shineson1001/feature/129-QRCodeGeneratorSwitch
🐛 Global switch for the QR code generator (#129)
2025-01-02 12:04:55 +01:00
Shine 869dd2c799 🐛 Global switch for the QR code generator (#129) 2024-12-31 20:48:56 +01:00
giandonato.inverso@edempg.it 531820e2a8 Revert "Revert "Instead using external API (api.qrserver.com) .. use chillerlan/php-qrcode""
This reverts commit 630bbf3aea.
2024-12-23 18:52:11 +01:00
giandonato.inverso@edempg.it 630bbf3aea Revert "Instead using external API (api.qrserver.com) .. use chillerlan/php-qrcode"
This reverts commit 9b65bb8020.
2024-12-23 18:49:05 +01:00
Giandonato Inverso 8238a81494 Merge pull request #128 from Shineson1001/feature/116-EventIncorrectTimeZone
🐛 Event: Incorrect Time Zone
2024-12-20 20:02:32 +01:00
Shine cc45f0659c 🐛 Event: Incorrect Time Zone
- Add "Time zone" input field.
- 24-Hour time format.
- Set Min-Year and Max-Year dynamically
2024-12-19 22:34:42 +01:00
Giandonato Inverso ad37224890 Merge pull request #127 from Shineson1001/feature/88-SelfHostedQRCodeGenerator
Instead using external API (api.qrserver.com) .. use chillerlan/php-qrcode
2024-12-15 16:35:29 +01:00
Shine 9b65bb8020 Instead using external API (api.qrserver.com) .. use chillerlan/php-qrcode 2024-12-15 14:36:39 +01:00
Giandonato Inverso 97481c2444 Merge pull request #126 from Shineson1001/feature/2FA-QRCodes
Add 2FA QR Code
2024-12-14 09:17:50 +01:00
Shine 8151de4b9a Add 2FA QR Code
Save your 2FA secrets to QR-Code.
2024-12-13 23:42:57 +01:00
Giandonato Inverso 477d7803f0 available plugins 2024-10-20 16:32:58 +02:00
Giandonato Inverso 8cc5294a84 Update README.md 2024-10-20 11:07:12 +02:00
giandonato.inverso@edempg.it e6aac416d9 bug fix in helpers.php 2024-04-21 12:55:03 +02:00
giandonato.inverso@edempg.it e84f853d80 edit readme 2024-04-21 12:38:35 +02:00
giandonato.inverso@edempg.it 7d5a4b889c bug fix 2024-04-18 20:54:04 +02:00
giandonato.inverso@edempg.it c157815ca8 fix in bulk action 2024-04-18 20:44:22 +02:00
giandonato.inverso@edempg.it 2d9b6162e1 readme 2024-04-18 20:35:04 +02:00
giandonato.inverso@edempg.it 096c239715 bug fix in read.php, bump version in footer, NEW: bulk delete 2024-04-18 20:33:20 +02:00
giandonato.inverso@edempg.it 5bdcb8e2bf bug fix database prefix in Qrcode class 2024-03-11 15:43:16 +01:00
giandonato.inverso@edempg.it 98ae82a040 bug fix bulk download 2024-03-04 14:36:18 +01:00
Giandonato Inverso 15b5ece4f9 Merge pull request #94 from tranmh/xss_static_qrcode
Fix Security: Stored Cross Site Scripting for static QR code
2024-03-01 09:58:29 +01:00
Minh Cuong Tran b03238b4c3 Fix Security: Stored Cross Site Scripting for static QR code, see https://github.com/giandonatoinverso/PHP-Dynamic-Qr-code/issues/93 2024-03-01 08:03:31 +01:00
Giandonato Inverso 2287d98455 Merge pull request #92 from tranmh/fix_remove_DATABASE_PREFIX_for_getOne
Inconsistency of using DATABASE_PREFIX with getOne()
2024-02-29 00:25:17 +01:00
Minh Cuong Tran 3e43b72eec Inconsistency of using DATABASE_PREFIX with getOne() 2024-02-28 16:56:39 +01:00
Giandonato Inverso 5488ad0a84 Merge pull request #91 from tranmh/mixed_content_blocked
fix: mixed content blocked for http and https
2024-02-28 14:16:21 +01:00
Minh Cuong Tran 9710ae0673 fix mixed content blocked for http and https: Mixed Content: The page at 'https://localhost/qrcode/dynamic_qrcodes.php' was loaded over HTTPS, but requested an insecure stylesheet 'http://code.ionicframework.com/ionicons/2.0.1/css/ionicons.min.css'. This request has been blocked; the content must be served over HTTPS. 2024-02-28 13:55:44 +01:00
Giandonato Inverso 893b883dbf Merge pull request #90 from tranmh/fix_case_sensitive_filename
Fix case sensitive filename
2024-02-27 13:25:17 +01:00
Minh Cuong Tran 60620e15dd fix: case sensitive for filename 2024-02-27 13:18:52 +01:00
Minh Cuong Tran ec786d2956 fix: case sensitive for filename 2024-02-27 13:18:01 +01:00
Giandonato Inverso a4d8455e5a increased size of column link - dynamic qrcode
increased size of column link - dynamic qrcode
2024-02-14 23:58:00 +01:00
Giandonato Inverso 5ac338945d Update README.md
updated php version requirement
2024-01-03 00:43:50 +01:00
Giandonato Inverso 6e213483a4 Update README.md 2023-10-30 17:02:13 +01:00
Giandonato Inverso 8a926ac0f3 bug fix redirect url with docker installation 2023-10-17 23:24:34 +02:00
Giandonato Inverso 0360176490 bug fix 2023-10-17 00:41:15 +02:00
Giandonato Inverso 57930cf9db bug fix and documentation 2023-10-16 22:57:16 +02:00
Giandonato Inverso 6682a207b2 updated documentation 2023-10-16 22:24:15 +02:00
Giandonato Inverso c326a30afc updated documentation 2023-10-16 20:56:06 +02:00
Giandonato Inverso 28545c2245 Refactoring docker image building, NEW: added docker compose support
Signed-off-by: giandonato.inverso@edempg.it <giandonato.inverso@studenti.unimi.it>
2023-10-16 19:49:29 +02:00
Giandonato Inverso 1085a13d38 readme updated
Signed-off-by: giandonato.inverso@edempg.it <giandonato.inverso@studenti.unimi.it>
2023-10-16 13:15:53 +02:00
giandonato.inverso@edempg.it 13a807ac85 readme updated
Signed-off-by: giandonato.inverso@edempg.it <giandonato.inverso@studenti.unimi.it>
2023-10-16 13:15:07 +02:00
Giandonato Inverso 876b6736b6 refactoring of table database, added script for upgrading to versions >= 2.0, added multi-user support
Signed-off-by: giandonato.inverso@edempg.it <giandonato.inverso@studenti.unimi.it>
2023-10-16 13:10:57 +02:00
Giandonato Inverso e36c26a37a readme updated
Signed-off-by: giandonato.inverso@edempg.it <giandonato.inverso@studenti.unimi.it>
2023-10-16 01:43:56 +02:00
Giandonato Inverso a2ce4b38b6 eliminazione file superflui, spostamento file read.php all'interno del progetto, aggiunta astrazione classe Qrcode, miglioramento download bulk, refactoring generale
Signed-off-by: giandonato.inverso@edempg.it <giandonato.inverso@studenti.unimi.it>
2023-10-16 01:41:27 +02:00
Giandonato Inverso 12e358b87c Bug fix login.php
removed .min extension adminlte js file
2023-09-16 14:51:04 +02:00
Giandonato Inverso 617d08c13d paypal donations 2023-09-05 23:31:38 +02:00
Giandonato Inverso 5612558ad1 Update README.md 2023-09-05 23:29:51 +02:00
giandonato.inverso@edempg.it e827b55f6b Merge remote-tracking branch 'origin/master' 2023-08-22 17:15:09 +02:00
giandonato.inverso@edempg.it 3ea78d6a84 doc update
Signed-off-by: giandonato.inverso@edempg.it <Zannabianca20>
2023-08-22 17:14:52 +02:00
Giandonato Inverso e947153e74 Update Dockerfile 2023-01-25 18:51:10 +01:00
Giandonato Inverso 4e3cfeeaa3 Merge pull request #52 from AyhamAl-Ali/fix/db_prefix
🚀 Fix DB Prefix in `read.php`
2023-01-25 18:50:15 +01:00
Ayham Al-Ali f750d7aaca Fix DB Prefix 2023-01-25 20:47:52 +03:00
Giandonato Inverso c6cb83638a Merge pull request #45 from chilluniverse/patch-1
DATABASE_HOST
2022-10-14 10:36:59 +02:00
Pascal 7e70ca94d8 DATABASE_HOST
In the docker-compose.yml is the Database_Host defined as "mariadb". If Host is not changed in the environment.php to "mariadb" as well the setup will fail
2022-10-14 01:26:06 +02:00
giandonato.inverso@edempg.it 7d7c326795 new version dockerfile 2022-09-28 16:23:44 +02:00
giandonato.inverso@edempg.it 16327a0e0a new version dockerfile 2022-09-28 16:22:18 +02:00
Giandonato Inverso 53955af19c Merge pull request #37 from 0xRenegade/feature/download-multiple-qr-img-at-once
Error Message for no qrcodes selected.
2022-09-24 22:43:16 +02:00
0xRenegade 4aab7d637a Error Message for no qrcodes selected. 2022-09-24 15:40:56 -05:00
Giandonato Inverso a6b2b29352 Merge pull request #36 from 0xRenegade/feature/download-multiple-qr-img-at-once
Feature/download multiple qr img at once
2022-09-24 22:26:36 +02:00
0xRenegade dac89ba0b2 download multiple qrcodes at once feature 2022-09-24 15:14:20 -05:00
0xRenegade f064d8f1ef add base_url() function in helpers, works with https and port number 2022-09-24 14:32:04 -05:00
0xRenegade cccf3ada43 adds in custom.css for, well, custom styles. 2022-09-24 13:09:17 -05:00
Giandonato Inverso b5aec38e45 Merge pull request #35 from 0xRenegade/issue-30/update-docker-yml-for-db-prefix
Issue 30/update docker yml for db prefix
2022-09-24 19:44:31 +02:00
Giandonato Inverso 654d395369 Merge pull request #33 from 0xRenegade/QOL/ignore-env-and-use-example-instead
QOL/ignore env and use example instead
2022-09-24 19:44:23 +02:00
0xRenegade f410322119 update docker-compose.yml for database prefix option 2022-09-24 12:19:40 -05:00
0xRenegade cbc5246163 update docs for this change 2022-09-24 11:52:34 -05:00
0xRenegade d99e8132c9 update main gitignore to add in environment.php 2022-09-24 11:44:02 -05:00
0xRenegade 99a361c0be move env to example, so we don't run into merge conflicts constantly 2022-09-24 11:42:17 -05:00
0xRenegade 64974c6c51 Merge pull request #1 from giandonatoinverso/master
sync master branch with remote
2022-09-24 11:28:55 -05:00
Giandonato Inverso 52e2347644 Merge pull request #31 from 0xRenegade/renegade/general-fixes
general fixes, fixed database prefix during install
2022-09-24 11:53:34 +02:00
0xRenegade 304b808bb6 set static attribute of class rather than non-DRY code 2022-09-24 00:24:03 -05:00
0xRenegade 9f376bd3c9 remove error_log debugging 2022-09-24 00:05:50 -05:00
0xRenegade fca443b6cc updated MysqliDb class functions to handle prefix properly. 2022-09-23 23:44:01 -05:00
0xRenegade 1f64d4cad7 if this feature is accepted in Pull Request, will need to add this back 2022-09-23 23:02:05 -05:00
0xRenegade b7b090f6c5 Merge branch 'renegade/general-fixes' of github.com:0xRenegade/PHP-Dynamic-Qr-code into renegade/general-fixes 2022-09-23 23:01:05 -05:00
0xRenegade 52d890597d some queries are manually entered, which aren't picked up by 'prefix' class attribute in database class 2022-09-23 22:59:53 -05:00
0xRenegade 40ab7b256d Merge branch 'master' into renegade/general-fixes 2022-09-23 21:05:16 -05:00
0xRenegade bbf115c2ae added in prefix by default, oops. 2022-09-23 21:00:41 -05:00
0xRenegade b433a83578 Issue #30: Fixes database_prefix option during install 2022-09-23 20:55:55 -05:00
Giandonato Inverso c005b52211 Update config.php 2022-09-24 03:24:15 +02:00
Giandonato Inverso e61c38473c Update docker-compose.yml 2022-09-24 03:23:41 +02:00
Giandonato Inverso 1243b32de1 Update environment.php 2022-09-24 03:23:20 +02:00
0xRenegade a20810d650 missing scroll bar on documentation page sidebar 2022-09-23 20:09:22 -05:00
Giandonato Inverso c4d5440453 Update add_dynamic_form.php
added support for http url
2022-09-10 11:50:19 +02:00
Giandonato Inverso 975fde9c35 Update MysqliDb.php
fix deprecated implode()
2022-09-05 20:40:26 +02:00
Giandonato Inverso af363723b2 Merge pull request #25 from nirpt/master
docker build now supports app release version code.
2022-08-29 14:09:34 +02:00
nirpt e2ff6e585b Docker build with app version added. 2022-08-29 12:32:20 +02:00
nirpt 389123fe15 Merge remote-tracking branch 'origin/master'
# Conflicts:
#	docker/README.md
2022-08-28 13:22:12 +02:00
Giandonato Inverso a519d7bfe6 Update README.md 2022-08-28 12:33:14 +02:00
Giandonato Inverso a98c89075d doc update
Signed-off-by: giandonato.inverso@edempg.it <Zannabianca20>
2022-08-28 12:04:48 +02:00
Giandonato Inverso 00d7dfdb0b new installation process via script, elimination of data entry form for installation
Signed-off-by: giandonato.inverso@edempg.it <Zannabianca20>
2022-08-28 11:57:31 +02:00
nirpt 08ac31210c Minor refactor and cleanup 2022-08-28 11:29:20 +02:00
Giandonato Inverso fef45c401a configuration file modification, docker environment variable support 2022-08-28 11:24:32 +02:00
Giandonato Inverso 21b779c581 Merge pull request #23 from nirpt/master
docker support added
2022-08-28 10:47:05 +02:00
nirpt 618030e9d3 docker support added 2022-08-28 10:24:07 +02:00
Giandonato Inverso 59cee36c3a Update README.md 2022-06-17 11:49:06 +02:00
Giandonato Inverso 88028393cd Update README.md 2022-06-17 11:48:44 +02:00
Giandonato Inverso de377902be Merge pull request #16 from neoteknic/patch-1
Fix php 8.1 warning in form field
2022-02-22 16:55:19 +01:00
neoteknic ee711a5796 Update filters.php
Fix php 8.1 warning in form field
2022-02-22 16:22:13 +01:00
Giandonato Inverso e599aed16f Add files via upload 2020-09-08 18:43:51 +02:00
Giandonato Inverso 0d77e8f3a4 Add files via upload 2020-09-08 18:42:29 +02:00
Giandonato Inverso 6ed9018086 Add files via upload 2020-09-08 18:41:51 +02:00
Giandonato Inverso 8cee68e091 Add files via upload 2020-09-08 18:30:32 +02:00
Giandonato Inverso 4615be4280 Add files via upload 2020-09-08 18:28:26 +02:00
Giandonato Inverso 6e7b7cfa77 Add files via upload 2020-09-08 18:22:57 +02:00
Giandonato Inverso 74f92ca2fa Add files via upload 2020-09-08 18:20:38 +02:00
Giandonato Inverso 2dc2e2fe16 Add files via upload 2020-09-08 18:17:08 +02:00
Giandonato Inverso 37dc9baa97 Add files via upload 2020-09-08 18:15:54 +02:00
Giandonato Inverso 0337838319 Add files via upload 2020-09-08 18:13:36 +02:00
Giandonato Inverso c544e0c7b5 Add files via upload 2020-09-08 18:11:37 +02:00
Giandonato Inverso 087e3e83b5 Add files via upload 2020-09-08 18:09:19 +02:00
Giandonato Inverso 2ae9f32cb8 Add files via upload 2020-09-08 18:06:28 +02:00
Giandonato Inverso 5924afa3dc Add files via upload 2020-09-08 17:59:49 +02:00
Giandonato Inverso b302e0cce1 Add files via upload 2020-09-08 17:59:21 +02:00
Giandonato Inverso 1f9fa672c6 Update README.md 2020-09-08 17:31:01 +02:00
Giandonato Inverso bd610dc68f Update README.md 2020-09-08 17:29:26 +02:00
Giandonato Inverso dd9d5ae2fb Update README.md 2020-09-08 17:26:41 +02:00
Giandonato Inverso 0e62c29f11 Update README.md 2020-09-08 17:25:38 +02:00
Giandonato Inverso 14610fe212 Update README.md 2020-09-08 17:24:07 +02:00
Giandonato Inverso 8bcb852ea9 Update README.md 2020-09-08 17:23:38 +02:00
Giandonato Inverso 0bfe40eafe Update README.md 2020-09-08 17:23:17 +02:00
Giandonato Inverso 1e6bc3af4e Update README.md 2020-09-08 17:23:02 +02:00
Giandonato Inverso fa9e6730cc Update README.md 2020-09-08 17:22:41 +02:00
Giandonato Inverso 6709776cc5 Update README.md 2020-09-08 17:22:25 +02:00
Giandonato Inverso df04139a05 Update README.md 2020-09-08 17:21:33 +02:00
Giandonato Inverso 4a377b635c Update README.md 2020-09-08 17:21:07 +02:00
Giandonato Inverso 8262550a10 Update README.md 2020-09-08 17:20:39 +02:00
Giandonato Inverso 31ab8efc05 Update README.md 2020-09-08 17:20:20 +02:00
Giandonato Inverso 3ee55c9b17 Update README.md 2020-09-08 17:20:05 +02:00
Giandonato Inverso 93cd20c49d Update README.md 2020-09-08 17:18:41 +02:00
Giandonato Inverso eff10b3ee6 Update README.md 2020-09-08 17:17:36 +02:00
Giandonato Inverso 6de33ea45c Update README.md 2020-09-08 17:14:57 +02:00
Giandonato Inverso 34bfee494e Update README.md 2020-09-08 17:13:33 +02:00
Giandonato Inverso 3f8209a6a6 Update README.md 2020-09-08 17:13:06 +02:00
Giandonato Inverso 2b93634d3a Update README.md 2020-09-08 17:12:50 +02:00
Giandonato Inverso c698fc34f1 Update README.md 2020-09-08 17:12:34 +02:00
Giandonato Inverso 93d362aba2 Update README.md 2020-09-08 17:12:01 +02:00
Giandonato Inverso 8fe055a5b1 Update README.md 2020-09-08 17:11:45 +02:00
Giandonato Inverso 8a64294455 Update README.md 2020-09-08 17:11:27 +02:00
Giandonato Inverso 854b0ca77d Update README.md 2020-09-08 17:10:01 +02:00
Giandonato Inverso 7c707f865c Update README.md 2020-09-08 17:09:36 +02:00
Giandonato Inverso 439d136f54 Update README.md 2020-09-08 17:09:15 +02:00
Giandonato Inverso d0f2d526f1 Update README.md 2020-09-08 17:08:42 +02:00
Giandonato Inverso 9c855a19bb Update README.md 2020-09-08 17:07:06 +02:00
Giandonato Inverso a7e532867a Update README.md 2020-09-08 17:06:25 +02:00
Giandonato Inverso 67e6d85da9 Update README.md 2020-09-08 17:05:43 +02:00
Giandonato Inverso 35c72f6199 Initial commit 2020-09-08 16:56:05 +02:00
55 changed files with 117 additions and 943 deletions
+1 -17
View File
@@ -4,7 +4,7 @@ TYPE=docker
QRCODE_GENERATOR=internal-chillerlan.qrcode
BASE_URL=http://localhost
DATABASE_HOST=qrforge-db
DATABASE_HOST=php-dynamic-qrcode-db
DATABASE_PORT=3306
DATABASE_NAME=qrcode
DATABASE_USER=qrcode
@@ -13,19 +13,3 @@ DATABASE_PREFIX=
DATABASE_CHARSET=utf8
MYSQL_ROOT_PASSWORD=change-me-to-a-strong-root-password
# Self-registration: lets visitors create their own free 'admin' account
# (email + CAPTCHA -> mailed password -> forced reset on first login).
ALLOW_SELF_REGISTRATION=false
# Only needed when ALLOW_SELF_REGISTRATION=true.
MAIL_HOST=
MAIL_PORT=587
MAIL_ENCRYPTION=tls
# Set to false to relay unauthenticated through an internal mail server (no
# MAIL_USERNAME/MAIL_PASSWORD needed in that case).
MAIL_SMTP_AUTH=true
MAIL_USERNAME=
MAIL_PASSWORD=
MAIL_FROM_ADDRESS=noreply@example.com
MAIL_FROM_NAME=QRForge
+1 -2
View File
@@ -2,5 +2,4 @@
.project
.idea
.DS_Store
.env
/data/
.env
-11
View File
@@ -75,7 +75,6 @@ RUN cd /opt \
&& rm /opt/composer-setup.php /opt/composer-setup.sha384sum
RUN docker-php-source extract
RUN docker-php-ext-configure gd --with-freetype --with-jpeg
RUN docker-php-ext-install pdo_mysql zip exif pcntl gd
RUN docker-php-ext-install mysqli && docker-php-ext-enable mysqli
RUN docker-php-ext-install gettext && docker-php-ext-enable gettext
@@ -95,22 +94,12 @@ RUN cp -R ./php-qrcode/src /var/www/html/
WORKDIR /var/www/html
RUN composer update
RUN composer require phpmailer/phpmailer:^6.9
COPY ./src ./
COPY ./db/migrations ./db/migrations
RUN chmod 755 *;
# Qr code storage lives outside the document root so files can only be reached through
# the authenticated qrcode_image.php / qrcode_zip_download.php endpoints.
RUN mkdir -p /var/www/qrcode-storage/zip && chmod -R 777 /var/www/qrcode-storage
# Applies any not-yet-applied db/migrations/*.sql on every container start (see
# src/scripts/migrate.php) - docker-entrypoint-initdb.d only runs db/init.sql, and only
# on a brand new volume, so without this an existing install's schema silently falls
# behind the code on every `git pull` + restart.
COPY docker/entrypoint.sh /usr/local/bin/entrypoint.sh
RUN chmod +x /usr/local/bin/entrypoint.sh
ENTRYPOINT ["/usr/local/bin/entrypoint.sh"]
EXPOSE 80
CMD ["php", "-S", "0.0.0.0:80"]
-10
View File
@@ -51,9 +51,7 @@ RUN cp -R ./php-qrcode/src /var/www/html/
WORKDIR /var/www/html
RUN composer update
RUN composer require phpmailer/phpmailer:^6.9
COPY ./src ./
COPY ./db/migrations ./db/migrations
RUN chown -R www-data:www-data /var/www/html \
&& find /var/www/html -type f -exec chmod 644 {} \; \
&& find /var/www/html -type d -exec chmod 755 {} \;
@@ -64,13 +62,5 @@ RUN mkdir -p /var/www/qrcode-storage/zip \
&& chown -R www-data:www-data /var/www/qrcode-storage \
&& chmod -R 775 /var/www/qrcode-storage
# Applies any not-yet-applied db/migrations/*.sql on every container start (see
# src/scripts/migrate.php) - docker-entrypoint-initdb.d only runs db/init.sql, and only
# on a brand new volume, so without this an existing install's schema silently falls
# behind the code on every `git pull` + restart.
COPY docker/entrypoint.sh /usr/local/bin/entrypoint.sh
RUN chmod +x /usr/local/bin/entrypoint.sh
ENTRYPOINT ["/usr/local/bin/entrypoint.sh"]
EXPOSE 9000
CMD ["php-fpm"]
-14
View File
@@ -1,14 +0,0 @@
FROM nginx:1.27-alpine
# The php-dynamic-qrcode container builds the full app (incl. composer/vendor) into its
# own image at /var/www/html. nginx runs as a separate container and has no access to
# that filesystem, so it needs its own copy of just the static assets it serves directly
# via try_files - everything else (*.php) is proxied to php-fpm regardless. Without this,
# every static asset request (CSS/JS/manifest) falls through nginx's try_files to
# index.php, which requires a login and silently redirects there instead of serving the
# file.
COPY src/dist /var/www/html/dist
COPY src/plugins /var/www/html/plugins
COPY src/manifest.json /var/www/html/manifest.json
COPY src/service-worker.js /var/www/html/service-worker.js
COPY src/favicon.ico /var/www/html/favicon.ico
-1
View File
@@ -1,7 +1,6 @@
MIT License
Copyright (c) 2020 Giandonato Inverso
Copyright (c) 2026 Dillard Blom
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
+5 -11
View File
@@ -8,13 +8,9 @@ of the original [PHP Dynamic Qr code](https://github.com/giandonatoinverso/PHP-D
project by Giandonato Inverso, built on [AdminLTE](https://adminlte.io/).
- **Try it free:** [qr.ensembia.com](https://qr.ensembia.com) - fully functional OSS test
instance. [Register your own free account](https://qr.ensembia.com/register.php)
(email + a self-hosted CAPTCHA, no third-party service) - no shared demo login needed.
- **Commercial VIP edition:** the ability to give sub-users the ability to create
QR codes as well, from their own (sub)account. If you have a bigger organisation,
having more users being able to create new QR codes delegates your workload. To
fund our open-source project, a small fee (€49/year subscription per organisation
("tenant")) is requested for this. [www.qrforge.eu](https://www.qrforge.eu).
instance, register your own account any time.
- **Commercial VIP edition** (self-service create-rights, logo-embedded QR codes):
[www.qrforge.eu](https://www.qrforge.eu).
- **Self-host it yourself:** this repository, MIT-licensed.
# Features
@@ -34,8 +30,7 @@ project by Giandonato Inverso, built on [AdminLTE](https://adminlte.io/).
- Installable as a PWA
- Role-based access: `super` (full access + user management), `admin`
(scoped to their own codes and sub-users), `user` (read-only, with
optional view toggles set by an admin; per-account create rights are
a VIP-edition feature, not available in this OSS version)
optional per-account create rights and view toggles set by an admin)
- Dashboard with QR/scan statistics and a 7-day activity chart
- CSRF protection, login rate limiting, session hardening, audit log
- Docker Compose setup, both a dev image and a production Nginx + PHP-FPM image
@@ -43,8 +38,7 @@ project by Giandonato Inverso, built on [AdminLTE](https://adminlte.io/).
# What is included
- PHP 8.4 application source
- Database schema + migrations (applied automatically on every container start,
so `git pull` + restart is enough to bring an existing install up to date)
- Database schema + migrations
- Docker Compose files (dev and production)
- CSS/JS assets
+3 -9
View File
@@ -19,20 +19,14 @@ CREATE TABLE IF NOT EXISTS `users` (
`can_view_static` tinyint(1) NOT NULL DEFAULT 0,
`can_view_dynamic` tinyint(1) NOT NULL DEFAULT 0,
`owner_admin_id` int(25) DEFAULT NULL,
`email` varchar(255) DEFAULT NULL,
`must_set_email` tinyint(1) NOT NULL DEFAULT 0,
`self_registered_at` datetime DEFAULT NULL,
PRIMARY KEY (`id`),
UNIQUE KEY `username` (`username`),
UNIQUE KEY `email` (`email`)
UNIQUE KEY `username` (`username`)
) ENGINE=InnoDB DEFAULT CHARSET=utf8 AUTO_INCREMENT=0 ;
-- Default super admin account. Credentials: superadmin / superadmin
-- must_change_password=1 forces a password change on first login (see Fase 1 hardening).
-- must_set_email=1: no email yet, so login falls back to username until it's set (same
-- one-time interstitial pre-migration accounts get - see set_email.php).
INSERT INTO `users` (`id`, `username`, `password`, `series_id`, `remember_token`, `expires`, `type`, `must_change_password`, `password_changed_at`, `must_set_email`) VALUES
(1, 'superadmin', '$2y$10$xpZc5KC.aU2XHkcqhuZGFuAnqmtL4Unt8MysOyylceq.19XIyoZpG', NULL, NULL, NULL, 'super', 1, NULL, 1);
INSERT INTO `users` (`id`, `username`, `password`, `series_id`, `remember_token`, `expires`, `type`, `must_change_password`, `password_changed_at`) VALUES
(1, 'superadmin', '$2y$10$xpZc5KC.aU2XHkcqhuZGFuAnqmtL4Unt8MysOyylceq.19XIyoZpG', NULL, NULL, NULL, 'super', 1, NULL);
CREATE TABLE IF NOT EXISTS `dynamic_qrcodes` (
`id` int(10) NOT NULL AUTO_INCREMENT,
-51
View File
@@ -1,51 +0,0 @@
-- Self-registration: adds email as the login identifier (mirrors qr-vip's
-- 006_vip_and_create_rights.sql email migration) plus a marker for
-- self-registered accounts.
SET @db := DATABASE();
-- 1. email: becomes the login identifier going forward. Nullable so existing accounts (which
-- have no email) don't violate a NOT NULL constraint; a unique index still allows unlimited
-- NULLs in InnoDB, so pre-existing NULL-email rows never collide with each other.
SET @col_exists := (
SELECT COUNT(*) FROM information_schema.COLUMNS
WHERE TABLE_SCHEMA = @db AND TABLE_NAME = 'users' AND COLUMN_NAME = 'email'
);
SET @sql := IF(@col_exists = 0,
'ALTER TABLE `users` ADD COLUMN `email` VARCHAR(255) DEFAULT NULL',
'SELECT 1');
PREPARE stmt FROM @sql; EXECUTE stmt; DEALLOCATE PREPARE stmt;
SET @idx_exists := (
SELECT COUNT(*) FROM information_schema.STATISTICS
WHERE TABLE_SCHEMA = @db AND TABLE_NAME = 'users' AND INDEX_NAME = 'email'
);
SET @sql := IF(@idx_exists = 0,
'ALTER TABLE `users` ADD UNIQUE KEY `email` (`email`)',
'SELECT 1');
PREPARE stmt FROM @sql; EXECUTE stmt; DEALLOCATE PREPARE stmt;
-- 2. must_set_email: forces existing (pre-migration) accounts through a one-time "set your
-- email" interstitial on next login, mirroring must_change_password. New accounts created
-- after this migration always have an email from creation, so they never get this flag.
SET @col_exists := (
SELECT COUNT(*) FROM information_schema.COLUMNS
WHERE TABLE_SCHEMA = @db AND TABLE_NAME = 'users' AND COLUMN_NAME = 'must_set_email'
);
SET @sql := IF(@col_exists = 0,
'ALTER TABLE `users` ADD COLUMN `must_set_email` TINYINT(1) NOT NULL DEFAULT 0',
'SELECT 1');
PREPARE stmt FROM @sql; EXECUTE stmt; DEALLOCATE PREPARE stmt;
UPDATE `users` SET `must_set_email` = 1 WHERE `email` IS NULL;
-- 3. self_registered_at: NULL for accounts created by an admin/super, set for accounts created
-- through register.php. Purely informational/reporting for now.
SET @col_exists := (
SELECT COUNT(*) FROM information_schema.COLUMNS
WHERE TABLE_SCHEMA = @db AND TABLE_NAME = 'users' AND COLUMN_NAME = 'self_registered_at'
);
SET @sql := IF(@col_exists = 0,
'ALTER TABLE `users` ADD COLUMN `self_registered_at` DATETIME DEFAULT NULL',
'SELECT 1');
PREPARE stmt FROM @sql; EXECUTE stmt; DEALLOCATE PREPARE stmt;
+16 -23
View File
@@ -1,8 +1,6 @@
services:
nginx:
build:
context: .
dockerfile: Dockerfile.nginx
image: "nginx:1.27-alpine"
restart: "unless-stopped"
ports:
- "80:80"
@@ -11,11 +9,11 @@ services:
volumes:
- ./nginx.conf:/etc/nginx/conf.d/default.conf:ro
depends_on:
- qrforge-app
- php-dynamic-qrcode
networks:
- qrforge-network
- php-dynamic-qrcode-network
qrforge-app:
php-dynamic-qrcode:
build:
context: .
dockerfile: Dockerfile.fpm
@@ -24,35 +22,26 @@ services:
TYPE: "docker"
QRCODE_GENERATOR: "${QRCODE_GENERATOR:-internal-chillerlan.qrcode}"
BASE_URL: "${BASE_URL:?set BASE_URL in .env, e.g. https://qr.ensembia.com}"
DATABASE_HOST: "qrforge-db"
DATABASE_HOST: "php-dynamic-qrcode-db"
DATABASE_PORT: "3306"
DATABASE_NAME: "${DATABASE_NAME:-qrcode}"
DATABASE_USER: "${DATABASE_USER:-qrcode}"
DATABASE_PASSWORD: "${DATABASE_PASSWORD:?set DATABASE_PASSWORD in .env}"
DATABASE_PREFIX: "${DATABASE_PREFIX:-}"
DATABASE_CHARSET: "${DATABASE_CHARSET:-utf8}"
ALLOW_SELF_REGISTRATION: "${ALLOW_SELF_REGISTRATION:-false}"
MAIL_HOST: "${MAIL_HOST:-}"
MAIL_PORT: "${MAIL_PORT:-587}"
MAIL_ENCRYPTION: "${MAIL_ENCRYPTION:-tls}"
MAIL_SMTP_AUTH: "${MAIL_SMTP_AUTH:-true}"
MAIL_USERNAME: "${MAIL_USERNAME:-}"
MAIL_PASSWORD: "${MAIL_PASSWORD:-}"
MAIL_FROM_ADDRESS: "${MAIL_FROM_ADDRESS:-noreply@example.com}"
MAIL_FROM_NAME: "${MAIL_FROM_NAME:-QRForge}"
depends_on:
qrforge-db:
php-dynamic-qrcode-db:
condition: service_healthy
volumes:
- ./data/qrcode-storage:/var/www/qrcode-storage
- php_dynamic_qrcode_saved_qrcode_data:/var/www/qrcode-storage
networks:
- qrforge-network
- php-dynamic-qrcode-network
qrforge-db:
php-dynamic-qrcode-db:
image: "mysql:8.0"
restart: "unless-stopped"
volumes:
- ./data/mysql:/var/lib/mysql
- php_dynamic_qrcode_db_data:/var/lib/mysql
- ./db/init.sql:/docker-entrypoint-initdb.d/init.sql:ro
environment:
MYSQL_ROOT_PASSWORD: "${MYSQL_ROOT_PASSWORD:?set MYSQL_ROOT_PASSWORD in .env}"
@@ -65,8 +54,12 @@ services:
timeout: 5s
retries: 10
networks:
- qrforge-network
- php-dynamic-qrcode-network
volumes:
php_dynamic_qrcode_db_data:
php_dynamic_qrcode_saved_qrcode_data:
networks:
qrforge-network:
php-dynamic-qrcode-network:
driver: bridge
+13 -29
View File
@@ -1,5 +1,5 @@
services:
qrforge-app:
php-dynamic-qrcode:
build:
context: .
dockerfile: Dockerfile
@@ -8,48 +8,28 @@ services:
TYPE: "${TYPE:-docker}"
QRCODE_GENERATOR: "${QRCODE_GENERATOR:-internal-chillerlan.qrcode}"
BASE_URL: "${BASE_URL:-http://localhost}"
DATABASE_HOST: "qrforge-db"
DATABASE_HOST: "php-dynamic-qrcode-db"
DATABASE_PORT: "3306"
DATABASE_NAME: "${DATABASE_NAME:-qrcode}"
DATABASE_USER: "${DATABASE_USER:-qrcode}"
DATABASE_PASSWORD: "${DATABASE_PASSWORD:?zet DATABASE_PASSWORD in .env}"
DATABASE_PREFIX: "${DATABASE_PREFIX:-}"
DATABASE_CHARSET: "${DATABASE_CHARSET:-utf8}"
ALLOW_SELF_REGISTRATION: "${ALLOW_SELF_REGISTRATION:-false}"
# Defaults here are dev-convenience only (mailhog, no auth) - a real deployment's
# .env must override MAIL_HOST/MAIL_SMTP_AUTH/MAIL_USERNAME/MAIL_PASSWORD
# explicitly, same as DATABASE_PASSWORD above already requires.
MAIL_HOST: "${MAIL_HOST:-mailhog}"
MAIL_PORT: "${MAIL_PORT:-1025}"
MAIL_ENCRYPTION: "${MAIL_ENCRYPTION:-}"
MAIL_SMTP_AUTH: "${MAIL_SMTP_AUTH:-false}"
MAIL_USERNAME: "${MAIL_USERNAME:-}"
MAIL_PASSWORD: "${MAIL_PASSWORD:-}"
MAIL_FROM_ADDRESS: "${MAIL_FROM_ADDRESS:-noreply@example.com}"
MAIL_FROM_NAME: "${MAIL_FROM_NAME:-QRForge}"
ports:
- "80:80"
depends_on:
qrforge-db:
php-dynamic-qrcode-db:
condition: service_healthy
volumes:
- ./data/qrcode-storage:/var/www/qrcode-storage
- php_dynamic_qrcode_saved_qrcode_data:/var/www/html/saved_qrcode
networks:
- qrforge-network
- php-dynamic-qrcode-network
mailhog:
image: "mailhog/mailhog:v1.0.1"
restart: "unless-stopped"
ports:
- "8025:8025" # web UI: http://localhost:8025
networks:
- qrforge-network
qrforge-db:
php-dynamic-qrcode-db:
image: "mysql:8.0"
restart: "unless-stopped"
volumes:
- ./data/mysql:/var/lib/mysql
- php_dynamic_qrcode_db_data:/var/lib/mysql
- ./db/init.sql:/docker-entrypoint-initdb.d/init.sql:ro
environment:
MYSQL_ROOT_PASSWORD: "${MYSQL_ROOT_PASSWORD:?zet MYSQL_ROOT_PASSWORD in .env}"
@@ -62,8 +42,12 @@ services:
timeout: 5s
retries: 10
networks:
- qrforge-network
- php-dynamic-qrcode-network
volumes:
php_dynamic_qrcode_db_data:
php_dynamic_qrcode_saved_qrcode_data:
networks:
qrforge-network:
php-dynamic-qrcode-network:
driver: bridge
-6
View File
@@ -1,6 +0,0 @@
#!/bin/sh
set -e
php /var/www/html/scripts/migrate.php
exec docker-php-entrypoint "$@"
+2 -2
View File
@@ -11,11 +11,11 @@ server {
add_header Referrer-Policy "same-origin" always;
location / {
try_files $uri /index.php$is_args$args;
try_files $uri $uri/ /index.php$is_args$args;
}
location ~ \.php$ {
fastcgi_pass qrforge-app:9000;
fastcgi_pass php-dynamic-qrcode:9000;
fastcgi_index index.php;
include fastcgi_params;
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
+2 -4
View File
@@ -51,9 +51,7 @@ require_once BASE_PATH . '/includes/auth_validate.php';
This is the free, open-source (MIT) edition of QRForge. It runs unmodified
as a live, fully functional try-out at
<a href="https://qr.ensembia.com" target="_blank">qr.ensembia.com</a> -
<a href="https://qr.ensembia.com/register.php" target="_blank">register your
own free account</a> there (email + a self-hosted CAPTCHA, no third-party
service).
register a free account there any time.
</p>
<p>
The commercial VIP edition (paid create-rights and logo-embedded QR codes)
@@ -72,7 +70,7 @@ require_once BASE_PATH . '/includes/auth_validate.php';
<p>
Prefer to run your own instance? QRForge is MIT-licensed and available on
GitHub:
<a href="https://github.com/dillardblom/QRForge-selfhosted" target="_blank">github.com/dillardblom/QRForge-selfhosted</a>.
<a href="https://github.com/dillardblom/QR-app-selfhosted" target="_blank">github.com/dillardblom/QR-app-selfhosted</a>.
</p>
</div>
</div>
+8 -19
View File
@@ -6,20 +6,17 @@ if ($_SERVER['REQUEST_METHOD'] === 'POST')
{
csrf_verify_or_die();
// Login moves from username to email. Accept either during the transition -
// existing pre-migration accounts have no email yet (see must_set_email/set_email.php),
// so a plain username must keep working until they've set one.
$identifier = filter_input(INPUT_POST, 'email');
$username = filter_input(INPUT_POST, 'username');
$password = filter_input(INPUT_POST, 'password');
$remember = filter_input(INPUT_POST, 'remember');
if (!$identifier || !$password) {
$_SESSION['login_failure'] = 'Invalid email or password';
if (!$username || !$password) {
$_SESSION['login_failure'] = 'Invalid username or password';
header('Location: login.php');
exit;
}
if (qr_is_login_locked_out($identifier)) {
if (qr_is_login_locked_out($username)) {
$_SESSION['login_failure'] = 'Too many failed login attempts. Try again in 15 minutes.';
header('Location: login.php');
exit;
@@ -28,19 +25,12 @@ if ($_SERVER['REQUEST_METHOD'] === 'POST')
// Get DB instance.
$db = getDbInstance();
$db->where('email', $identifier);
$db->where('username', $username);
$row = $db->getOne('users');
if ($db->count < 1) {
// Compatibility fallback for accounts that haven't set an email yet.
$db = getDbInstance();
$db->where('username', $identifier);
$row = $db->getOne('users');
}
if ($db->count >= 1 && password_verify($password, $row['password']))
{
qr_record_login_attempt($identifier, true);
qr_record_login_attempt($username, true);
// Voorkom session fixation: nieuwe sessie-id na een geslaagde login.
session_regenerate_id(true);
@@ -50,7 +40,6 @@ if ($_SERVER['REQUEST_METHOD'] === 'POST')
$_SESSION['user_id'] = $row['id'];
$_SESSION['username'] = $row['username'];
$_SESSION['must_change_password'] = !empty($row['must_change_password']);
$_SESSION['must_set_email'] = !empty($row['must_set_email']);
$_SESSION['can_view_static'] = !empty($row['can_view_static']);
$_SESSION['can_view_dynamic'] = !empty($row['can_view_dynamic']);
$_SESSION['scope_owner_id'] = qr_compute_scope_owner_id($row);
@@ -97,8 +86,8 @@ if ($_SERVER['REQUEST_METHOD'] === 'POST')
}
else
{
qr_record_login_attempt($identifier, false);
$_SESSION['login_failure'] = 'Invalid email or password';
qr_record_login_attempt($username, false);
$_SESSION['login_failure'] = 'Invalid username or password';
header('Location: login.php');
exit;
}
-41
View File
@@ -1,41 +0,0 @@
<?php
// Public endpoint (no auth): renders a self-hosted CAPTCHA image for register.php.
// No third-party service (reCAPTCHA/Turnstile/etc) - a simple math challenge drawn
// with GD onto a noisy background, expected answer kept server-side in the session.
require_once 'includes/bootstrap.php';
$a = random_int(1, 9);
$b = random_int(1, 9);
$_SESSION['captcha_answer'] = (string) ($a + $b);
$text = "{$a} + {$b} =";
$width = 160;
$height = 60;
$image = imagecreatetruecolor($width, $height);
$bg = imagecolorallocate($image, 245, 245, 245);
$fg = imagecolorallocate($image, 30, 30, 30);
imagefill($image, 0, 0, $bg);
// Noise: random lines behind the text, purely cosmetic distortion.
for ($i = 0; $i < 8; $i++) {
$lineColor = imagecolorallocate($image, random_int(180, 220), random_int(180, 220), random_int(180, 220));
imageline($image, random_int(0, $width), random_int(0, $height), random_int(0, $width), random_int(0, $height), $lineColor);
}
$fontFile = '/usr/share/fonts/truetype/dejavu/DejaVuSans-Bold.ttf';
if (is_file($fontFile) && function_exists('imagettftext')) {
$fontSize = 22;
$bbox = imagettfbbox($fontSize, 0, $fontFile, $text);
$textWidth = abs($bbox[2] - $bbox[0]);
$textHeight = abs($bbox[1] - $bbox[7]);
$x = (int) (($width - $textWidth) / 2);
$y = (int) (($height + $textHeight) / 2);
imagettftext($image, $fontSize, 0, $x, $y, $fg, $fontFile, $text);
} else {
imagestring($image, 5, 10, 20, $text, $fg);
}
header('Content-Type: image/png');
header('Cache-Control: no-store, no-cache, must-revalidate');
imagepng($image);
imagedestroy($image);
-11
View File
@@ -16,14 +16,3 @@ define('DATABASE_CHARSET', getenv('DATABASE_CHARSET') ?: 'utf8');
define('TYPE', getenv('TYPE') ?: 'local');
define('BASE_URL', getenv('BASE_URL') ?: 'http://localhost');
define('QRCODE_GENERATOR', getenv('QRCODE_GENERATOR') ?: 'external-api.qrserver.com'); // opties: external-api.qrserver.com of internal-chillerlan.qrcode
define('ALLOW_SELF_REGISTRATION', filter_var(getenv('ALLOW_SELF_REGISTRATION'), FILTER_VALIDATE_BOOLEAN));
define('MAIL_HOST', getenv('MAIL_HOST') ?: '');
define('MAIL_PORT', filter_var(getenv('MAIL_PORT'), FILTER_VALIDATE_INT) ?: 587);
define('MAIL_ENCRYPTION', getenv('MAIL_ENCRYPTION') !== false ? getenv('MAIL_ENCRYPTION') : 'tls'); // opties: tls, ssl, '' (geen)
define('MAIL_SMTP_AUTH', getenv('MAIL_SMTP_AUTH') !== false ? filter_var(getenv('MAIL_SMTP_AUTH'), FILTER_VALIDATE_BOOLEAN) : true);
define('MAIL_USERNAME', getenv('MAIL_USERNAME') ?: '');
define('MAIL_PASSWORD', getenv('MAIL_PASSWORD') ?: '');
define('MAIL_FROM_ADDRESS', getenv('MAIL_FROM_ADDRESS') ?: 'noreply@example.com');
define('MAIL_FROM_NAME', getenv('MAIL_FROM_NAME') ?: 'QRForge');
BIN
View File
Binary file not shown.

Before

Width:  |  Height:  |  Size: 1.9 KiB

After

Width:  |  Height:  |  Size: 2.8 KiB

BIN
View File
Binary file not shown.

Before

Width:  |  Height:  |  Size: 7.9 KiB

After

Width:  |  Height:  |  Size: 7.4 KiB

+12 -12
View File
@@ -118,6 +118,18 @@
<div class="col-sm-12 mb-2">
<div class="row">
<div class="col-6 col-md-1">
<label for="format">Format *</label>
<select name="format" class="form-control" required="required">
<option value="png" selected>PNG</option>
<option value="gif">GIF</option>
<option value="jpeg">JPEG</option>
<option value="jpg">JPG</option>
<option value="svg">SVG</option>
<option value="eps">EPS</option>
</select>
</div>
<div class="col-sm-4">
<div class="form-group">
<label for="frame_text">Frame text</label>
@@ -166,18 +178,6 @@
</div>
</div>
<div class="col-6 col-md-1">
<label for="format">Format *</label>
<select name="format" class="form-control" required="required">
<option value="png" selected>PNG</option>
<option value="gif">GIF</option>
<option value="jpeg">JPEG</option>
<option value="jpg">JPG</option>
<option value="svg">SVG</option>
<option value="eps">EPS</option>
</select>
</div>
<?php if ($_SESSION['type'] === 'super') { ?>
<div class="col-sm-4">
<div class="form-group">
+3 -21
View File
@@ -12,20 +12,6 @@
</div>
</div>
<div class="col-sm-4">
<div class="form-group">
<label for="email">Email</label>
<div class="input-group">
<div class="input-group-prepend">
<span class="input-group-text"><i class="fa fa-envelope"></i></span>
</div>
<input type="email" name="email" placeholder="Email" class="form-control" value="<?php echo ($edit) ? htmlspecialchars($user['email'] ?? '', ENT_QUOTES, 'UTF-8') : ''; ?>" autocomplete="off">
</div>
<small class="form-text text-muted">Used to log in once set. Leave blank to prompt for it on next login.</small>
</div>
</div>
<div class="col-sm-4">
<div class="form-group">
<label for="password">Password *</label>
@@ -40,29 +26,25 @@
</div>
<?php if ($_SESSION['type'] === 'super'): ?>
<?php $editing_self = $edit && (int) $user['id'] === (int) $_SESSION['user_id']; ?>
<div class="col-sm-4">
<label for="user-type">User type *</label>
<div class="form-group">
<div class="radio">
<label class="radio">
<input type="radio" name="type" value="super" required="required" <?php echo ($edit && $user['type'] =='super') ? "checked": "" ; ?> <?php echo $editing_self ? "disabled" : ""; ?>/> Super admin</label>
<input type="radio" name="type" value="super" required="required" <?php echo ($edit && $user['type'] =='super') ? "checked": "" ; ?>/> Super admin</label>
</div>
<div class="radio">
<label class="radio">
<input type="radio" name="type" value="admin" required="required" <?php echo ($edit && $user['type'] =='admin') ? "checked": "" ; ?> <?php echo $editing_self ? "disabled" : ""; ?>/> Admin</label>
<input type="radio" name="type" value="admin" required="required" <?php echo ($edit && $user['type'] =='admin') ? "checked": "" ; ?>/> Admin</label>
</div>
<div class="radio">
<label class="radio">
<input type="radio" name="type" value="user" required="required" id="type-user" <?php echo ($edit && $user['type'] =='user') ? "checked": "" ; ?> <?php echo $editing_self ? "disabled" : ""; ?>/> User (read-only)</label>
<input type="radio" name="type" value="user" required="required" id="type-user" <?php echo ($edit && $user['type'] =='user') ? "checked": "" ; ?>/> User (read-only)</label>
</div>
</div>
<?php if ($editing_self): ?>
<small class="form-text text-muted">You can't change your own access level.</small>
<?php endif; ?>
</div>
<div class="col-sm-12 mt-2" id="user-view-toggles">
+17 -17
View File
@@ -114,6 +114,23 @@ if (QRCODE_GENERATOR === "internal-chillerlan.qrcode") {
<div class="col-sm-12 mb-2">
<div class="row">
<div class="col-6 col-md-1">
<label for="format">Format</label>
<select name="format" class="form-control">
<option value="png">PNG</option>
<option value="gif">GIF</option>
<option value="jpeg">JPEG</option>
<option value="jpg">JPG</option>
<option value="svg">SVG</option>
<?php
if (QRCODE_GENERATOR === "internal-chillerlan.qrcode") {
echo ' <option value="svgbw">SVG (BW)</option>';
}
?>
<option value="eps">EPS</option>
</select>
</div>
<div class="col-sm-4">
<div class="form-group">
<label for="frame_text">Frame text</label>
@@ -162,23 +179,6 @@ if (QRCODE_GENERATOR === "internal-chillerlan.qrcode") {
</div>
</div>
<div class="col-6 col-md-1">
<label for="format">Format</label>
<select name="format" class="form-control">
<option value="png">PNG</option>
<option value="gif">GIF</option>
<option value="jpeg">JPEG</option>
<option value="jpg">JPG</option>
<option value="svg">SVG</option>
<?php
if (QRCODE_GENERATOR === "internal-chillerlan.qrcode") {
echo ' <option value="svgbw">SVG (BW)</option>';
}
?>
<option value="eps">EPS</option>
</select>
</div>
<?php if ($_SESSION['type'] === 'super') { ?>
<div class="col-sm-4">
<div class="form-group">
+1 -1
View File
@@ -1,5 +1,6 @@
<form class="form" action="static_qrcode.php?type=2fa" method="post" id="static_form" enctype="multipart/form-data">
<?php echo csrf_field(); ?>
<?php include BASE_PATH.'/forms/qrcode_options.php'; ?>
<!-- Input forms -->
<div class="col-sm-12 mb-2">
<div class="row">
@@ -37,7 +38,6 @@
</div>
</div>
<?php include BASE_PATH.'/forms/qrcode_options.php'; ?>
<div class="col-sm-12 mb-2">
<div class="row">
<div class="col-6 col-md-3">
+1 -1
View File
@@ -1,5 +1,6 @@
<form class="form" action="static_qrcode.php?type=applink" method="post" id="static_form" enctype="multipart/form-data">
<?php echo csrf_field(); ?>
<?php include BASE_PATH.'/forms/qrcode_options.php'; ?>
<!-- Input forms -->
<div class="col-sm-12 mb-2">
<div class="row">
@@ -61,7 +62,6 @@
})();
</script>
<?php include BASE_PATH.'/forms/qrcode_options.php'; ?>
<div class="col-sm-12 mb-2">
<div class="row">
<div class="col-6 col-md-3">
+1 -1
View File
@@ -1,5 +1,6 @@
<form class="form" action="static_qrcode.php?type=bitcoin" method="post" id="static_form" enctype="multipart/form-data">
<?php echo csrf_field(); ?>
<?php include BASE_PATH.'/forms/qrcode_options.php'; ?>
<!-- Input forms -->
<div class="col-sm-12 mb-2">
<div class="row">
@@ -46,7 +47,6 @@
</div>
</div>
<?php include BASE_PATH.'/forms/qrcode_options.php'; ?>
<div class="col-sm-12 mb-2">
<div class="row">
<div class="col-6 col-md-3">
+1 -1
View File
@@ -1,5 +1,6 @@
<form class="form" action="static_qrcode.php?type=bluetooth" method="post" id="static_form" enctype="multipart/form-data">
<?php echo csrf_field(); ?>
<?php include BASE_PATH.'/forms/qrcode_options.php'; ?>
<!-- Input forms -->
<div class="col-sm-12 mb-2">
<small class="form-text text-muted mb-2">
@@ -25,7 +26,6 @@
</div>
</div>
<?php include BASE_PATH.'/forms/qrcode_options.php'; ?>
<div class="col-sm-12 mb-2">
<div class="row">
<div class="col-6 col-md-3">
+1 -1
View File
@@ -1,5 +1,6 @@
<form class="form" action="static_qrcode.php?type=bookmark" method="post" id="static_form" enctype="multipart/form-data">
<?php echo csrf_field(); ?>
<?php include BASE_PATH.'/forms/qrcode_options.php'; ?>
<!-- Input forms -->
<div class="col-sm-12 mb-2">
<div class="row">
@@ -19,7 +20,6 @@
</div>
</div>
<?php include BASE_PATH.'/forms/qrcode_options.php'; ?>
<div class="col-sm-12 mb-2">
<div class="row">
<div class="col-6 col-md-3">
+1 -1
View File
@@ -1,5 +1,6 @@
<form class="form" action="static_qrcode.php?type=email" method="post" id="static_form" enctype="multipart/form-data">
<?php echo csrf_field(); ?>
<?php include BASE_PATH.'/forms/qrcode_options.php'; ?>
<!-- Input forms -->
<div class="col-sm-12 mb-2">
<div class="row">
@@ -27,7 +28,6 @@
</div>
</div>
<?php include BASE_PATH.'/forms/qrcode_options.php'; ?>
<div class="col-sm-12 mb-2">
<div class="row">
<div class="col-6 col-md-3">
+1 -1
View File
@@ -1,5 +1,6 @@
<form class="form" action="static_qrcode.php?type=event" method="post" id="static_form" enctype="multipart/form-data">
<?php echo csrf_field(); ?>
<?php include BASE_PATH.'/forms/qrcode_options.php'; ?>
<!-- Input forms -->
<div class="col-sm-4">
<div class="form-group">
@@ -71,7 +72,6 @@
</div>
</div>
<?php include BASE_PATH.'/forms/qrcode_options.php'; ?>
<div class="col-sm-12 mb-2">
<div class="row">
<div class="col-6 col-md-3">
+1 -1
View File
@@ -1,5 +1,6 @@
<form class="form" action="static_qrcode.php?type=location" method="post" id="static_form" enctype="multipart/form-data">
<?php echo csrf_field(); ?>
<?php include BASE_PATH.'/forms/qrcode_options.php'; ?>
<!-- Input forms -->
<div class="col-sm-8">
<div class="form-group" style="position: relative;">
@@ -29,7 +30,6 @@
</div>
</div>
<?php include BASE_PATH.'/forms/qrcode_options.php'; ?>
<div class="col-sm-12 mb-2">
<div class="row">
<div class="col-6 col-md-3">
+1 -1
View File
@@ -1,5 +1,6 @@
<form class="form" action="static_qrcode.php?type=paypal" method="post" id="static_form" enctype="multipart/form-data">
<?php echo csrf_field(); ?>
<?php include BASE_PATH.'/forms/qrcode_options.php'; ?>
<!-- Input forms -->
<div class="col-sm-12 mb-2">
<div class="row">
@@ -99,7 +100,6 @@
</div>
</div>
<?php include BASE_PATH.'/forms/qrcode_options.php'; ?>
<div class="col-sm-12 mb-2">
<div class="row">
<div class="col-6 col-md-3">
+1 -1
View File
@@ -1,5 +1,6 @@
<form class="form" action="static_qrcode.php?type=phone" method="post" id="static_form" enctype="multipart/form-data">
<?php echo csrf_field(); ?>
<?php include BASE_PATH.'/forms/qrcode_options.php'; ?>
<!-- Input forms -->
<div class="col-sm-12 mb-2">
<div class="row">
@@ -22,7 +23,6 @@
</div>
</div>
<?php include BASE_PATH.'/forms/qrcode_options.php'; ?>
<div class="col-sm-12 mb-2">
<div class="row">
<div class="col-6 col-md-3">
+1 -1
View File
@@ -1,5 +1,6 @@
<form class="form" action="static_qrcode.php?type=skype" method="post" id="static_form" enctype="multipart/form-data">
<?php echo csrf_field(); ?>
<?php include BASE_PATH.'/forms/qrcode_options.php'; ?>
<!-- Input forms -->
<div class="col-sm-4">
<div class="form-group">
@@ -8,7 +9,6 @@
</div>
</div>
<?php include BASE_PATH.'/forms/qrcode_options.php'; ?>
<div class="col-sm-12 mb-2">
<div class="row">
<div class="col-6 col-md-3">
+1 -1
View File
@@ -1,5 +1,6 @@
<form class="form" action="static_qrcode.php?type=sms" method="post" id="static_form" enctype="multipart/form-data">
<?php echo csrf_field(); ?>
<?php include BASE_PATH.'/forms/qrcode_options.php'; ?>
<!-- Input forms -->
<div class="col-sm-12 mb-2">
<div class="row">
@@ -29,7 +30,6 @@
</div>
</div>
<?php include BASE_PATH.'/forms/qrcode_options.php'; ?>
<div class="col-sm-12 mb-2">
<div class="row">
<div class="col-6 col-md-3">
+1 -1
View File
@@ -1,5 +1,6 @@
<form class="form" action="static_qrcode.php?type=text" method="post" id="static_form" enctype="multipart/form-data">
<?php echo csrf_field(); ?>
<?php include BASE_PATH.'/forms/qrcode_options.php'; ?>
<!-- Input forms -->
<div class="col-sm-6">
<div class="form-group">
@@ -8,7 +9,6 @@
</div>
</div>
<?php include BASE_PATH.'/forms/qrcode_options.php'; ?>
<div class="col-sm-12 mb-2">
<div class="row">
<div class="col-6 col-md-3">
+2 -9
View File
@@ -1,5 +1,6 @@
<form class="form" action="static_qrcode.php?type=vcard" method="post" id="static_form" enctype="multipart/form-data">
<?php echo csrf_field(); ?>
<?php include BASE_PATH.'/forms/qrcode_options.php'; ?>
<!-- Input forms -->
<!-- First row -->
<div class="col-sm-12 mb-2">
@@ -137,18 +138,10 @@
<input type="text" name="state" value="" placeholder="" class="form-control">
</div>
</div>
<div class="col-6 col-md-3">
<div class="form-group">
<label>Country</label>
<input type="text" name="country" value="" placeholder="" class="form-control">
</div>
</div>
</div>
</div>
<?php include BASE_PATH.'/forms/qrcode_options.php'; ?>
<div class="col-sm-12 mb-2">
<div class="row">
<div class="col-6 col-md-3">
+1 -1
View File
@@ -1,5 +1,6 @@
<form class="form" action="static_qrcode.php?type=whatsapp" method="post" id="static_form" enctype="multipart/form-data">
<?php echo csrf_field(); ?>
<?php include BASE_PATH.'/forms/qrcode_options.php'; ?>
<!-- Input forms -->
<div class="col-sm-12 mb-2">
<div class="row">
@@ -29,7 +30,6 @@
</div>
</div>
<?php include BASE_PATH.'/forms/qrcode_options.php'; ?>
<div class="col-sm-12 mb-2">
<div class="row">
<div class="col-6 col-md-3">
+1 -1
View File
@@ -1,5 +1,6 @@
<form class="form" action="static_qrcode.php?type=wifi" method="post" id="static_form" enctype="multipart/form-data">
<?php echo csrf_field(); ?>
<?php include BASE_PATH.'/forms/qrcode_options.php'; ?>
<!-- Input forms -->
<div class="col-sm-12 mb-2">
<div class="row">
@@ -32,7 +33,6 @@
</div>
</div>
<?php include BASE_PATH.'/forms/qrcode_options.php'; ?>
<div class="col-sm-12 mb-2">
<div class="row">
<div class="col-6 col-md-3">
+2 -4
View File
@@ -6,9 +6,8 @@
<thead>
<tr>
<th width="5%">ID</th>
<th width="25%">Username</th>
<th width="30%">Email</th>
<th width="30%">Type</th>
<th width="45%">Username</th>
<th width="40%">Type</th>
<th width="10%">Actions</th>
</tr>
</thead>
@@ -17,7 +16,6 @@
<tr>
<td><?php echo $row['id']; ?></td>
<td><?php echo htmlspecialchars($row['username']); ?></td>
<td><?php echo htmlspecialchars($row['email'] ?? ''); ?></td>
<td><?php echo htmlspecialchars($row['type']); ?></td>
<td>
<!-- EDIT -->
-1
View File
@@ -12,4 +12,3 @@ require_once __DIR__ . '/security.php';
qr_session_start();
qr_enforce_session_timeout();
qr_enforce_password_change();
qr_enforce_email_set();
-60
View File
@@ -35,64 +35,4 @@
if ('serviceWorker' in navigator) {
navigator.serviceWorker.register('service-worker.js');
}
</script>
<!--
Idle-timeout warning: the session dies silently after
<?php echo SESSION_IDLE_TIMEOUT; ?> seconds of inactivity (no PHP page
load), which loses whatever form the user is filling in. This warns a
couple of minutes before that happens and offers a "stay logged in"
button that pings the server without navigating away.
-->
<div id="session-timeout-toast" class="toast" role="alert" aria-live="assertive" aria-atomic="true"
style="position:fixed;bottom:20px;right:20px;z-index:2000;min-width:320px;display:none;">
<div class="toast-header bg-warning">
<i class="fa fa-clock mr-2"></i>
<strong class="mr-auto">Session expiring soon</strong>
</div>
<div class="toast-body bg-white">
<span id="session-timeout-message">You'll be logged out in a couple of minutes due to inactivity.</span>
<div class="mt-2">
<button type="button" id="session-timeout-extend" class="btn btn-sm btn-primary">Stay logged in</button>
</div>
</div>
</div>
<script>
(function () {
var SESSION_IDLE_TIMEOUT = <?php echo (int) SESSION_IDLE_TIMEOUT; ?>;
var WARNING_LEAD_TIME = 120; // show the warning this many seconds before expiry
var toast = document.getElementById('session-timeout-toast');
var message = document.getElementById('session-timeout-message');
var extendBtn = document.getElementById('session-timeout-extend');
var warnTimer = null;
function showWarning() {
toast.style.display = 'block';
}
function scheduleWarning() {
clearTimeout(warnTimer);
var delayMs = Math.max(0, (SESSION_IDLE_TIMEOUT - WARNING_LEAD_TIME) * 1000);
warnTimer = setTimeout(showWarning, delayMs);
}
extendBtn.addEventListener('click', function () {
fetch('session_ping.php', { method: 'GET', redirect: 'manual', credentials: 'same-origin' })
.then(function (response) {
// redirect: 'manual' turns a server-side redirect (session already
// dead) into an opaque response instead of silently following it.
if (response.type === 'opaqueredirect' || !response.ok) {
throw new Error('expired');
}
toast.style.display = 'none';
scheduleWarning();
})
.catch(function () {
message.textContent = 'Your session already expired - please copy any unsaved work before reloading.';
extendBtn.style.display = 'none';
});
});
scheduleWarning();
})();
</script>
+3 -44
View File
@@ -66,11 +66,8 @@ function qr_enforce_password_change() {
return;
}
// Also exempt set_email.php - an account can need both flows at once (e.g. a fresh
// self-registered row, or a pre-migration account that never set a password either),
// and each enforcer redirecting to its own page while blocking the other's would loop forever.
$current_script = basename(parse_url($_SERVER['SCRIPT_NAME'], PHP_URL_PATH));
$exempt = ['change_password.php', 'set_email.php', 'logout.php'];
$exempt = ['change_password.php', 'logout.php'];
if (in_array($current_script, $exempt, true)) {
return;
@@ -80,26 +77,6 @@ function qr_enforce_password_change() {
exit;
}
/**
* Stuurt ingelogde gebruikers zonder e-mailadres naar set_email.php, behalve op de
* wijzigingspagina's zelf en logout.
*/
function qr_enforce_email_set() {
if (empty($_SESSION['user_logged_in']) || empty($_SESSION['must_set_email'])) {
return;
}
$current_script = basename(parse_url($_SERVER['SCRIPT_NAME'], PHP_URL_PATH));
$exempt = ['set_email.php', 'change_password.php', 'logout.php'];
if (in_array($current_script, $exempt, true)) {
return;
}
header('Location: set_email.php');
exit;
}
/**
* CSRF-bescherming
*/
@@ -141,18 +118,6 @@ function csrf_verify_header_or_die() {
}
}
/**
* Verifieert het antwoord op de zelf-gehoste CAPTCHA (captcha.php). Verbruikt het
* verwachte antwoord uit de sessie na de eerste check, zodat elke afbeelding maar
* eenmaal te gebruiken is (voorkomt hergebruik van hetzelfde plaatje/antwoord).
*/
function captcha_is_valid($submittedAnswer) {
$expected = $_SESSION['captcha_answer'] ?? null;
unset($_SESSION['captcha_answer']);
return $expected !== null && is_string($submittedAnswer) && hash_equals($expected, trim($submittedAnswer));
}
/**
* Rate limiting op login
*/
@@ -212,18 +177,12 @@ function qr_has_full_visibility() {
/**
* Apply the current session's owner scope to a MysqliDb query builder in place.
* No-op when the session has full visibility.
*
* Uses a single raw, parenthesized condition rather than where()+orWhere() -
* the previous two-call form produced "WHERE id = ? AND id_owner = ? OR id_owner
* IS NULL" whenever a caller had already added its own where('id', ...) (e.g.
* qrcode_image.php, bulk_action.php), and AND binds tighter than OR in SQL, so
* the OR silently detached from the id filter and matched *any* id_owner-NULL
* row instead of the one actually requested.
*/
function qr_apply_owner_scope($db) {
$scope_owner_id = qr_scope_owner_id();
if ($scope_owner_id !== null) {
$db->where('(id_owner = ' . (int) $scope_owner_id . ' OR id_owner IS NULL)');
$db->where('id_owner', $scope_owner_id);
$db->orWhere('id_owner', NULL, 'IS');
}
}
-56
View File
@@ -1,56 +0,0 @@
<?php
require_once __DIR__.'/../../vendor/autoload.php';
use PHPMailer\PHPMailer\PHPMailer;
use PHPMailer\PHPMailer\Exception as PHPMailerException;
class Mailer
{
/**
* Sends a temporary/initial password to a newly created or provisioned account.
* Returns true on success, false on failure (never throws - callers decide how to
* surface a mail failure without blocking the account creation itself).
*/
public function sendInitialPassword($toEmail, $tempPassword) {
$subject = 'Your ' . MAIL_FROM_NAME . ' account';
$body = "An account was created for you.\n\n"
. "Email: {$toEmail}\n"
. "Temporary password: {$tempPassword}\n\n"
. "You'll be asked to set a new password the first time you log in.\n\n"
. rtrim(BASE_URL, '/') . "/login.php";
return $this->send($toEmail, $subject, $body);
}
private function send($toEmail, $subject, $body) {
$mail = new PHPMailer(true);
try {
$mail->isSMTP();
$mail->Host = MAIL_HOST;
$mail->Port = MAIL_PORT;
$mail->SMTPAuth = MAIL_SMTP_AUTH;
if (MAIL_SMTP_AUTH) {
$mail->Username = MAIL_USERNAME;
$mail->Password = MAIL_PASSWORD;
}
if (MAIL_ENCRYPTION !== '') {
$mail->SMTPSecure = MAIL_ENCRYPTION;
}
$mail->setFrom(MAIL_FROM_ADDRESS, MAIL_FROM_NAME);
$mail->addAddress($toEmail);
$mail->Subject = $subject;
$mail->Body = $body;
$mail->isHTML(false);
$mail->send();
return true;
} catch (PHPMailerException $e) {
error_log('Mailer: failed to send to ' . $toEmail . ': ' . $mail->ErrorInfo);
return false;
}
}
}
-5
View File
@@ -207,12 +207,9 @@ class Qrcode {
}
public function getQrcode($id) {
require_once BASE_PATH . '/includes/security.php';
$db = getDbInstance();
$db->where('id', $id);
qr_apply_owner_scope($db);
$result = $db->getOne($this->table);
if($result !== NULL)
@@ -534,7 +531,6 @@ class Qrcode {
if(!file_exists(SAVED_QRCODE_DIRECTORY.$data_to_db['filename'].'.'.$old_qrcode["format"]) || $data_to_db['filename'] == $input_data["old_filename"]){
$db->where('id', $input_data["id"]);
qr_apply_owner_scope($db);
$stat = $db->update($this->table, $data_to_db);
try{
@@ -567,7 +563,6 @@ class Qrcode {
$qrcode = $this->getQrcode($id);
$db->where('id', $id);
qr_apply_owner_scope($db);
$status = $db->delete($this->table);
if ($status) {
-5
View File
@@ -192,12 +192,9 @@ class Qrcode {
}
public function getQrcode($id) {
require_once BASE_PATH . '/includes/security.php';
$db = getDbInstance();
$db->where('id', $id);
qr_apply_owner_scope($db);
$result = $db->getOne($this->table);
if($result !== NULL)
@@ -379,7 +376,6 @@ class Qrcode {
if(!file_exists(SAVED_QRCODE_DIRECTORY.$data_to_db['filename'].'.'.$old_qrcode["format"]) || $data_to_db['filename'] == $input_data["old_filename"]){
$db->where('id', $input_data["id"]);
qr_apply_owner_scope($db);
$stat = $db->update($this->table, $data_to_db);
try{
@@ -412,7 +408,6 @@ class Qrcode {
$qrcode = $this->getQrcode($id);
$db->where('id', $id);
qr_apply_owner_scope($db);
$status = $db->delete($this->table);
if ($status) {
+3 -3
View File
@@ -171,7 +171,7 @@ class StaticQrcode {
* create a qr code of type "vcard"
*
*/
public function vcardQrcode($fullname, $nickname, $email, $website, $phone, $home_phone, $work_phone, $company, $role, $categories, $note, $photo, $address, $city, $postcode, $state, $country)
public function vcardQrcode($fullname, $nickname, $email, $website, $phone, $home_phone, $work_phone, $company, $role, $categories, $note, $photo, $address, $city, $postcode, $state)
{
if($fullname != NULL && $phone != NULL){
@@ -188,7 +188,7 @@ class StaticQrcode {
$vcard->categories($categories);
$vcard->note($note);
$vcard->photo($photo);
$vcard->address($address, $city, $state, $postcode, $country);
$vcard->address($address, $city, $postcode, $state);
$vcard->create();
$this->sData = $vcard->get();
@@ -202,7 +202,7 @@ class StaticQrcode {
$this->sContent .= '<div class="col-sm-4">';
$this->sContent .= '<strong>Phone:</strong> '.$phone.'<br>'.'<strong>Home Phone:</strong> '.$home_phone.'<br>'.'<strong>Work phone:</strong> '.$work_phone.'<br>'.'<strong>Address:</strong> '.$address.'&nbsp;'.$city.'&nbsp;'.$postcode.'&nbsp;'.$state.'&nbsp;'.$country.'</div>';
$this->sContent .= '<strong>Phone:</strong> '.$phone.'<br>'.'<strong>Home Phone:</strong> '.$home_phone.'<br>'.'<strong>Work phone:</strong> '.$work_phone.'<br>'.'<strong>Address:</strong> '.$address.'&nbsp;'.$city.'&nbsp;'.$postcode.'&nbsp;'.$state.'</div>';
$this->sContent .= '</div>';
+2 -151
View File
@@ -1,6 +1,5 @@
<?php
require_once 'config/config.php';
require_once BASE_PATH . '/lib/Mailer/Mailer.php';
class Users
{
@@ -32,23 +31,6 @@ class Users
return null;
}
/**
* Server-side validation of the (optional, for admin-created accounts) email address.
* Empty is allowed here - an account without one gets must_set_email=1, same as a
* pre-migration legacy account (see the callers below).
*/
private function validateEmail($email) {
if ($email === '' || $email === null) {
return null;
}
if (!is_string($email) || strlen($email) > 255 || !filter_var($email, FILTER_VALIDATE_EMAIL)) {
return 'Please enter a valid email address.';
}
return null;
}
/**
*
*/
@@ -131,19 +113,11 @@ class Users
$this->failure($validation_error, 'Location: user.php');
}
$email = trim($input_data['email'] ?? '');
$email_error = $this->validateEmail($email);
if ($email_error !== null) {
$this->failure($email_error, 'Location: user.php');
}
if (!isset($input_data['password']) || strlen($input_data['password']) < 10) {
$this->failure('Password must be at least 10 characters long.', 'Location: user.php');
}
$data_to_db["username"] = $input_data["username"];
$data_to_db["email"] = $email !== '' ? $email : null;
$data_to_db['must_set_email'] = $email === '' ? 1 : 0;
$data_to_db['password'] = password_hash($input_data['password'], PASSWORD_DEFAULT);
$data_to_db["type"] = $requested_type;
$data_to_db['owner_admin_id'] = $owner_admin_id;
@@ -156,16 +130,6 @@ class Users
if ($db->count >= 1)
$this->failure('Username already exists');
if ($email !== '') {
$db = getDbInstance();
$db->where('email', $email);
$db->get('users');
if ($db->count >= 1)
$this->failure('An account with this email already exists', 'Location: user.php');
}
$db = getDbInstance();
$last_id = $db->insert('users', $data_to_db);
if ($last_id) {
@@ -173,90 +137,7 @@ class Users
$this->success('User added successfully');
}
}
/**
* Public self-registration (register.php). No session/permission checks - this is
* the one path where an unauthenticated visitor creates their own account. Always
* creates a free-forever 'admin' (self-scoped, no tenant), matching what a manually
* created OSS admin gets. Returns ['ok' => true] on success or
* ['ok' => false, 'error' => string] - callers are responsible for flash/redirect,
* unlike addUser()/editUser() which redirect themselves (this runs pre-login, on a
* page with its own layout).
*/
public function registerSelfUser($email) {
if (!ALLOW_SELF_REGISTRATION) {
return ['ok' => false, 'error' => 'Self-registration is not enabled.'];
}
if (!filter_var($email, FILTER_VALIDATE_EMAIL)) {
return ['ok' => false, 'error' => 'Please enter a valid email address.'];
}
$db = getDbInstance();
$db->where('email', $email);
$existing = $db->getOne('users');
if (!empty($existing)) {
return ['ok' => false, 'error' => 'An account with this email already exists.'];
}
$username = $this->deriveUniqueUsername($email);
$tempPassword = bin2hex(random_bytes(8));
$data_to_db = [
'username' => $username,
'password' => password_hash($tempPassword, PASSWORD_DEFAULT),
'type' => 'admin',
'owner_admin_id' => null,
'email' => $email,
'must_change_password' => 1,
'self_registered_at' => date('Y-m-d H:i:s'),
];
$db = getDbInstance();
$last_id = $db->insert('users', $data_to_db);
if (!$last_id) {
return ['ok' => false, 'error' => 'Could not create the account: ' . $db->getLastError()];
}
audit_log('user_self_registered', 'user', $last_id);
$mailer = new Mailer();
$mailer->sendInitialPassword($email, $tempPassword);
return ['ok' => true];
}
/**
* Derives a username candidate from the email's local part (letters/digits/dot/
* underscore/hyphen only, matching validateUsernameAndType()'s rules), appending a
* numeric suffix if it's already taken.
*/
private function deriveUniqueUsername($email) {
$localPart = strtolower(strstr($email, '@', true) ?: $email);
$base = preg_replace('/[^a-z0-9._-]/', '', $localPart);
$base = substr($base, 0, 45) ?: 'user';
if (strlen($base) < 3) {
$base = str_pad($base, 3, '0');
}
$candidate = $base;
$suffix = 1;
$db = getDbInstance();
$db->where('username', $candidate);
while ($db->getOne('users') !== null) {
$candidate = $base . $suffix;
$suffix++;
$db = getDbInstance();
$db->where('username', $candidate);
}
return $candidate;
}
/**
* Edit user.
*
@@ -279,26 +160,13 @@ class Users
'edit' => "true",
));
$is_self_edit = (int) $input_data['id'] === (int) $_SESSION['user_id'];
// A user editing their own account keeps their current type, even if a
// different value was submitted - prevents accidentally (or deliberately)
// locking yourself out by downgrading your own access level.
$requested_type = $_SESSION['type'] === 'admin'
? 'user'
: ($is_self_edit ? $target['type'] : ($input_data['type'] ?? ''));
$requested_type = $_SESSION['type'] === 'admin' ? 'user' : ($input_data['type'] ?? '');
$validation_error = $this->validateUsernameAndType($input_data['username'] ?? '', $requested_type);
if ($validation_error !== null) {
$this->failure($validation_error, 'Location: user.php?'.$query_string);
}
$email = trim($input_data['email'] ?? '');
$email_error = $this->validateEmail($email);
if ($email_error !== null) {
$this->failure($email_error, 'Location: user.php?'.$query_string);
}
if (isset($input_data['password']) && strlen($input_data['password']) > 0 && strlen($input_data['password']) < 10) {
$this->failure('Password must be at least 10 characters long.', 'Location: user.php?'.$query_string);
}
@@ -312,25 +180,8 @@ class Users
$this->failure('Username already exists', 'Location: user.php?'.$query_string);
}
if ($email !== '') {
$db = getDbInstance();
$db->where('email', $email);
$db->where('id', $input_data["id"], '!=');
$row = $db->getOne('users');
if (!empty($row['email'])) {
$this->failure('An account with this email already exists', 'Location: user.php?'.$query_string);
}
}
$data_to_db["username"] = $input_data["username"];
$data_to_db["type"] = $requested_type;
// Only touch email/must_set_email if an email was actually submitted - an admin
// leaving the field blank on an already-set account shouldn't wipe it back out.
if ($email !== '') {
$data_to_db['email'] = $email;
$data_to_db['must_set_email'] = 0;
}
$data_to_db['can_view_static'] = !empty($input_data['can_view_static']) ? 1 : 0;
$data_to_db['can_view_dynamic'] = !empty($input_data['can_view_dynamic']) ? 1 : 0;
+2 -3
View File
@@ -43,11 +43,10 @@ class vCard
*
* @return self
*/
public function address($sAddress, $sCity, $sState, $sPostcode, $sCountry)
public function address($sAddress, $sCity, $sPostcode, $sState)
{
// Component order per vCard 4.0 ADR: pobox;ext;street;locality;region;code;country
$this->sData .= 'ADR:;;'.$sAddress.';';
$this->sData .= $sCity.';'.$sState.';'.$sPostcode.';'.$sCountry."\n";
$this->sData .= $sCity.';'.$sPostcode.';'.$sState."\n";
return $this;
}
+3 -9
View File
@@ -40,7 +40,6 @@ if (isset($_COOKIE['series_id']) && isset($_COOKIE['remember_token']))
$_SESSION['type'] = $row['type'];
$_SESSION['username'] = $row['username'];
$_SESSION['must_change_password'] = !empty($row['must_change_password']);
$_SESSION['must_set_email'] = !empty($row['must_set_email']);
$_SESSION['can_view_static'] = !empty($row['can_view_static']);
$_SESSION['can_view_dynamic'] = !empty($row['can_view_dynamic']);
$_SESSION['scope_owner_id'] = qr_compute_scope_owner_id($row);
@@ -82,12 +81,10 @@ if (isset($_COOKIE['series_id']) && isset($_COOKIE['remember_token']))
<div class="card-body login-card-body">
<p class="login-box-msg">Sign in to start your session</p>
<?php include './includes/flash_messages.php'; ?>
<form method="POST" action="authenticate.php">
<?php echo csrf_field(); ?>
<div class="input-group mb-3">
<input type="text" name="email" class="form-control" placeholder="Email" required="required">
<input type="text" name="username" class="form-control" placeholder="Username" required="required">
<div class="input-group-append">
<div class="input-group-text">
<span class="fa fa-user"></span>
@@ -135,11 +132,8 @@ if (isset($_COOKIE['series_id']) && isset($_COOKIE['remember_token']))
</div>
</div>
<?php endif; ?>
<?php if (ALLOW_SELF_REGISTRATION): ?>
<p class="mt-3 text-center"><a href="register.php">Register for free</a></p>
<?php endif; ?>
</div>
<!-- /.login-card-body -->
</div>
-86
View File
@@ -1,86 +0,0 @@
<?php
require_once 'includes/bootstrap.php';
require_once 'lib/Users/Users.php';
if (!ALLOW_SELF_REGISTRATION) {
header('Location: login.php');
exit;
}
if (isset($_SESSION['user_logged_in']) && $_SESSION['user_logged_in'] === TRUE) {
header('Location: index.php');
exit;
}
if ($_SERVER['REQUEST_METHOD'] === 'POST') {
csrf_verify_or_die();
$email = trim($_POST['email'] ?? '');
if (!captcha_is_valid($_POST['captcha'] ?? '')) {
$_SESSION['failure'] = 'Incorrect CAPTCHA answer, please try again.';
} else {
$users = new Users();
$result = $users->registerSelfUser($email);
if ($result['ok']) {
$_SESSION['success'] = 'Account created! Check your inbox for a temporary password.';
header('Location: login.php');
exit;
}
$_SESSION['failure'] = $result['error'];
}
}
?>
<!DOCTYPE html>
<html lang="en">
<title>Register - QRForge</title>
<?php include './includes/head.php'; ?>
<body class="login-page" style="min-height: 512.391px;">
<div class="login-box">
<div class="login-logo">
<img src="dist/img/brand/logo.svg" alt="QRForge" style="max-width: 260px;">
</div>
<div class="card">
<div class="card-body login-card-body">
<p class="login-box-msg">Create your free account</p>
<?php include './includes/flash_messages.php'; ?>
<form method="POST" action="register.php">
<?php echo csrf_field(); ?>
<div class="input-group mb-3">
<input type="email" name="email" class="form-control" placeholder="Email address" required="required">
</div>
<div class="mb-3 text-center">
<img src="captcha.php" alt="CAPTCHA" id="captcha-image" style="cursor:pointer;" title="Click to refresh">
</div>
<div class="input-group mb-3">
<input type="text" name="captcha" class="form-control" placeholder="Answer the sum above" required="required" autocomplete="off">
</div>
<div class="row">
<div class="col-12">
<button type="submit" class="btn btn-primary btn-block">Create account</button>
</div>
</div>
</form>
<p class="mt-3 text-center"><a href="login.php">Back to login</a></p>
</div>
</div>
</div>
<script src="../../plugins/jquery/jquery.min.js"></script>
<script src="../../plugins/bootstrap/js/bootstrap.bundle.min.js"></script>
<script src="../../dist/js/adminlte.js"></script>
<script>
document.getElementById('captcha-image').addEventListener('click', function () {
this.src = 'captcha.php?' + Date.now();
});
</script>
</body>
</html>
-72
View File
@@ -1,72 +0,0 @@
<?php
// Lightweight migration runner: applies any db/migrations/*.sql file not yet recorded
// in schema_migrations, in filename order. Every migration file is itself idempotent
// (checks information_schema before altering), so re-running an already-applied file
// is a safe no-op - this script leans on that instead of needing transactional rollback.
// Run automatically by the container entrypoint on every start (see docker/entrypoint.sh),
// so a `git pull` + restart is enough to bring an existing install's schema up to date -
// docker-entrypoint-initdb.d only ever runs db/init.sql, and only on a brand new volume.
require_once __DIR__ . '/../config/environment.php';
mysqli_report(MYSQLI_REPORT_OFF);
$mysqli = new mysqli(DATABASE_HOST, DATABASE_USER, DATABASE_PASSWORD, DATABASE_NAME, DATABASE_PORT);
if ($mysqli->connect_errno) {
fwrite(STDERR, "migrate.php: could not connect to database: {$mysqli->connect_error}\n");
exit(1);
}
$mysqli->set_charset(DATABASE_CHARSET);
$mysqli->query(
'CREATE TABLE IF NOT EXISTS schema_migrations (
filename VARCHAR(255) NOT NULL PRIMARY KEY,
applied_at DATETIME NOT NULL
) ENGINE=InnoDB DEFAULT CHARSET=utf8'
);
$files = glob(__DIR__ . '/../db/migrations/*.sql');
sort($files, SORT_STRING);
$applied = [];
$result = $mysqli->query('SELECT filename FROM schema_migrations');
while ($row = $result->fetch_assoc()) {
$applied[$row['filename']] = true;
}
$ran = 0;
foreach ($files as $file) {
$filename = basename($file);
if (isset($applied[$filename])) {
continue;
}
echo "Applying migration: $filename\n";
if (!$mysqli->multi_query(file_get_contents($file))) {
fwrite(STDERR, "migrate.php: failed to apply $filename: {$mysqli->error}\n");
exit(1);
}
// multi_query queues result sets asynchronously - drain them all before the next
// query, and check for a mid-batch error on each one.
do {
if ($res = $mysqli->store_result()) {
$res->free();
}
if ($mysqli->errno) {
fwrite(STDERR, "migrate.php: error while applying $filename: {$mysqli->error}\n");
exit(1);
}
} while ($mysqli->more_results() && $mysqli->next_result());
$stmt = $mysqli->prepare('INSERT INTO schema_migrations (filename, applied_at) VALUES (?, NOW())');
$stmt->bind_param('s', $filename);
$stmt->execute();
$stmt->close();
$ran++;
}
echo $ran === 0 ? "No pending migrations.\n" : "Applied $ran migration(s).\n";
$mysqli->close();
-18
View File
@@ -1,18 +0,0 @@
<?php
// Lightweight keep-alive endpoint: including bootstrap.php refreshes
// $_SESSION['last_activity'], extending the idle timeout without navigating
// away from (and losing) whatever form the user is currently filling in.
// Deliberately doesn't use auth_validate.php's redirect-to-login-on-failure
// behavior: this is called from JS, and a 401 lets the caller show "your
// session already expired" instead of silently following a redirect.
require_once 'includes/bootstrap.php';
header('Content-Type: application/json');
if (empty($_SESSION['user_logged_in'])) {
http_response_code(401);
echo json_encode(['ok' => false]);
exit;
}
echo json_encode(['ok' => true]);
-89
View File
@@ -1,89 +0,0 @@
<?php
require_once 'includes/bootstrap.php';
if (empty($_SESSION['user_logged_in'])) {
header('Location: login.php');
exit;
}
$forced = !empty($_SESSION['must_set_email']);
if ($_SERVER['REQUEST_METHOD'] === 'POST') {
csrf_verify_or_die();
$email = trim($_POST['email'] ?? '');
if (!filter_var($email, FILTER_VALIDATE_EMAIL)) {
$_SESSION['failure'] = 'Please enter a valid email address.';
} else {
$db = getDbInstance();
$db->where('email', $email);
$db->where('id', $_SESSION['user_id'], '!=');
$existing = $db->getOne('users');
if (!empty($existing['email'])) {
$_SESSION['failure'] = 'An account with this email already exists.';
} else {
$db = getDbInstance();
$db->where('id', $_SESSION['user_id']);
$db->update('users', [
'email' => $email,
'must_set_email' => 0,
]);
$_SESSION['must_set_email'] = false;
audit_log('email_set');
$_SESSION['success'] = 'Email address saved.';
header('Location: index.php');
exit;
}
}
}
?>
<!DOCTYPE html>
<html lang="en">
<title>Set email - QRForge</title>
<?php include './includes/head.php'; ?>
<body class="login-page" style="min-height: 512.391px;">
<div class="login-box">
<div class="login-logo">
<img src="dist/img/brand/logo.svg" alt="QRForge" style="max-width: 260px;">
</div>
<div class="card">
<div class="card-body login-card-body">
<p class="login-box-msg">
<?php echo $forced
? 'Please set an email address for your account before continuing. This will become your login.'
: 'Set your email address'; ?>
</p>
<?php include './includes/flash_messages.php'; ?>
<form method="POST" action="set_email.php">
<?php echo csrf_field(); ?>
<div class="input-group mb-3">
<input type="email" name="email" class="form-control" placeholder="Email address" required="required">
</div>
<div class="row">
<div class="col-12">
<button type="submit" class="btn btn-primary btn-block">Save email</button>
</div>
</div>
</form>
<?php if (!$forced): ?>
<p class="mt-3 text-center"><a href="index.php">Back to dashboard</a></p>
<?php endif; ?>
</div>
</div>
</div>
<script src="../../plugins/jquery/jquery.min.js"></script>
<script src="../../plugins/bootstrap/js/bootstrap.bundle.min.js"></script>
<script src="../../dist/js/adminlte.js"></script>
</body>
</html>
+1 -1
View File
@@ -65,7 +65,7 @@ if($_SERVER["REQUEST_METHOD"] === "POST" && !isset($_POST["edit"]) && !isset($_P
case 'location': $static_qrcode_instance->locationQrcode($_POST['latitude'], $_POST['longitude']);
break;
case 'vcard': $static_qrcode_instance->vcardQrcode($_POST['full_name'], $_POST['nickname'], $_POST['email'], $_POST['website'], $_POST['phone'], $_POST['home_phone'], $_POST['work_phone'], $_POST['company'], $_POST['role'], $_POST['categories'], $_POST['note'], $_POST['photo'], $_POST['address'], $_POST['city'], $_POST['post_code'], $_POST['state'], $_POST['country']);
case 'vcard': $static_qrcode_instance->vcardQrcode($_POST['full_name'], $_POST['nickname'], $_POST['email'], $_POST['website'], $_POST['phone'], $_POST['home_phone'], $_POST['work_phone'], $_POST['company'], $_POST['role'], $_POST['categories'], $_POST['note'], $_POST['photo'], $_POST['address'], $_POST['city'], $_POST['post_code'], $_POST['state']);
break;
case 'event': $static_qrcode_instance->eventQrcode($_POST['title'], $_POST['start'], $_POST['end'], $_POST['timezone'], $_POST['location'], $_POST['description'], $_POST['url']);
+1 -1
View File
@@ -9,7 +9,7 @@ $users = new Users();
if (!in_array($_SESSION['type'], ['super', 'admin'], true))
$users->failure('Only "super admin" and "admin" accounts can access the user management page', 'Location: index.php');
$select = array('id', 'username', 'email', 'type');
$select = array('id', 'username', 'type');
$search_fields = array('username');
require_once BASE_PATH . '/includes/search_order.php';
$page = filter_input(INPUT_GET, 'page', FILTER_SANITIZE_FULL_SPECIAL_CHARS) ?? 1;