23e8d9b765
Applies the approved QRForge brand kit throughout the app: - New logo/icon SVGs, favicon set (ico/svg/png), apple-touch-icon, all copied from the approved brand kit into src/dist/img/brand/. Old Symbol_WhiteBlue.png/DynamicQRCode_Original.png removed (unused after the swap). - Sidebar brand image/text, login and change-password page logos, all <title> tags, manifest.json name/theme-color, and the PWA icons (dist/img/icon-192.png/icon-512.png, same filenames so no other reference needed to change) updated to QRForge branding and the #2563EB brand blue. - New about.php page (+ sidebar link): credits the original upstream fork (Giandonato Inverso) and chillerlan/php-qrcode, links to the free qr.ensembia.com try-out, the commercial www.qrforge.eu product page, and this GitHub repo for self-hosters. - Footer now reads "QRForge" + "About / credits" + "Version 3.0" (replaces the inherited "PHP Qrcode Generator by Giandonato Inverso" / "Version 2.3.0" line - full credit moved to the About page instead). - README.md rewritten: current feature set (all 16 static qr types, presets, scanner, PWA, location search, roles), qr.ensembia.com as the free try-out, www.qrforge.eu as the commercial product page, corrected Docker Compose setup steps (.env is required now, the old README still described the single-file demo setup from the original upstream fork). IMPORTANT: not pushed to origin/gitea. Per user instruction, no push until qrforge.eu domain registration is confirmed.
100 lines
3.5 KiB
PHP
100 lines
3.5 KiB
PHP
<?php
|
|
require_once 'includes/bootstrap.php';
|
|
|
|
if (empty($_SESSION['user_logged_in'])) {
|
|
header('Location: login.php');
|
|
exit;
|
|
}
|
|
|
|
$forced = !empty($_SESSION['must_change_password']);
|
|
|
|
if ($_SERVER['REQUEST_METHOD'] === 'POST') {
|
|
csrf_verify_or_die();
|
|
|
|
$current_password = $_POST['current_password'] ?? '';
|
|
$new_password = $_POST['new_password'] ?? '';
|
|
$confirm_password = $_POST['confirm_password'] ?? '';
|
|
|
|
$db = getDbInstance();
|
|
$db->where('id', $_SESSION['user_id']);
|
|
$user = $db->getOne('users');
|
|
|
|
if ($user === NULL || !password_verify($current_password, $user['password'])) {
|
|
$_SESSION['failure'] = 'Current password is incorrect.';
|
|
} elseif (strlen($new_password) < 10) {
|
|
$_SESSION['failure'] = 'New password must be at least 10 characters long.';
|
|
} elseif ($new_password !== $confirm_password) {
|
|
$_SESSION['failure'] = 'New password and confirmation do not match.';
|
|
} elseif ($new_password === $current_password) {
|
|
$_SESSION['failure'] = 'New password must be different from the current password.';
|
|
} else {
|
|
$db = getDbInstance();
|
|
$db->where('id', $_SESSION['user_id']);
|
|
$db->update('users', [
|
|
'password' => password_hash($new_password, PASSWORD_DEFAULT),
|
|
'must_change_password' => 0,
|
|
'password_changed_at' => date('Y-m-d H:i:s'),
|
|
]);
|
|
|
|
$_SESSION['must_change_password'] = false;
|
|
audit_log('password_changed');
|
|
|
|
$_SESSION['success'] = 'Password updated successfully.';
|
|
header('Location: index.php');
|
|
exit;
|
|
}
|
|
}
|
|
?>
|
|
<!DOCTYPE html>
|
|
<html lang="en">
|
|
<title>Change password - QRForge</title>
|
|
<?php include './includes/head.php'; ?>
|
|
|
|
<body class="login-page" style="min-height: 512.391px;">
|
|
<div class="login-box">
|
|
<div class="login-logo">
|
|
<img src="dist/img/brand/logo.svg" alt="QRForge" style="max-width: 260px;">
|
|
</div>
|
|
|
|
<div class="card">
|
|
<div class="card-body login-card-body">
|
|
<p class="login-box-msg">
|
|
<?php echo $forced
|
|
? 'You must change your password before continuing.'
|
|
: 'Change your password'; ?>
|
|
</p>
|
|
|
|
<?php include './includes/flash_messages.php'; ?>
|
|
|
|
<form method="POST" action="change_password.php">
|
|
<?php echo csrf_field(); ?>
|
|
<div class="input-group mb-3">
|
|
<input type="password" name="current_password" class="form-control" placeholder="Current password" required="required" autocomplete="current-password">
|
|
</div>
|
|
<div class="input-group mb-3">
|
|
<input type="password" name="new_password" class="form-control" placeholder="New password (min. 10 characters)" required="required" minlength="10" autocomplete="new-password">
|
|
</div>
|
|
<div class="input-group mb-3">
|
|
<input type="password" name="confirm_password" class="form-control" placeholder="Confirm new password" required="required" minlength="10" autocomplete="new-password">
|
|
</div>
|
|
<div class="row">
|
|
<div class="col-12">
|
|
<button type="submit" class="btn btn-primary btn-block">Update password</button>
|
|
</div>
|
|
</div>
|
|
</form>
|
|
|
|
<?php if (!$forced): ?>
|
|
<p class="mt-3 text-center"><a href="index.php">Back to dashboard</a></p>
|
|
<?php endif; ?>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
|
|
<script src="../../plugins/jquery/jquery.min.js"></script>
|
|
<script src="../../plugins/bootstrap/js/bootstrap.bundle.min.js"></script>
|
|
<script src="../../dist/js/adminlte.js"></script>
|
|
|
|
</body>
|
|
</html>
|