3afe3b7698
Fixes critical pre-existing issues found during review: bulk_action.php had no auth check at all (unauthenticated download/delete of any qrcode) and built a table name from unwhitelisted user input (SQL injection); the QR generator classes wrote files from unvalidated filename/format, allowing path traversal and arbitrary file writes. Also pins chillerlan/php-qrcode to 5.0.5 since master now requires PHP 8.4, breaking the PHP 8.3 build. - CSRF tokens on all POST forms and the bulk_action.php JSON endpoint - Login rate limiting (5 attempts / 15 min) via new login_attempts table - Hardened sessions: httponly/samesite cookies, 30 min idle timeout, session regeneration on login - Forced password change for the default superadmin/superadmin account - Server-side validation in Users/DynamicQrcode/Qrcode classes - Audit log table for auth, user, and qrcode actions - Checked-in db schema (db/init.sql, migrations/) instead of relying on an opaque prebuilt db image - Production docker-compose with Nginx + php-fpm instead of the PHP dev server
16 lines
412 B
Bash
16 lines
412 B
Bash
# Kopieer naar .env en pas de waarden aan. .env wordt niet gecommit (zie .gitignore).
|
|
|
|
TYPE=docker
|
|
QRCODE_GENERATOR=internal-chillerlan.qrcode
|
|
BASE_URL=http://localhost
|
|
|
|
DATABASE_HOST=php-dynamic-qrcode-db
|
|
DATABASE_PORT=3306
|
|
DATABASE_NAME=qrcode
|
|
DATABASE_USER=qrcode
|
|
DATABASE_PASSWORD=change-me-to-a-strong-password
|
|
DATABASE_PREFIX=
|
|
DATABASE_CHARSET=utf8
|
|
|
|
MYSQL_ROOT_PASSWORD=change-me-to-a-strong-root-password
|