dillard feb5380b28 Security hardening: CSRF, rate limiting, session/password policy, audit log
Fixes critical pre-existing issues found during review: bulk_action.php had no
auth check at all (unauthenticated download/delete of any qrcode) and built a
table name from unwhitelisted user input (SQL injection); the QR generator
classes wrote files from unvalidated filename/format, allowing path traversal
and arbitrary file writes. Also pins chillerlan/php-qrcode to 5.0.5 since
master now requires PHP 8.4, breaking the PHP 8.3 build.

- CSRF tokens on all POST forms and the bulk_action.php JSON endpoint
- Login rate limiting (5 attempts / 15 min) via new login_attempts table
- Hardened sessions: httponly/samesite cookies, 30 min idle timeout,
  session regeneration on login
- Forced password change for the default superadmin/superadmin account
- Server-side validation in Users/DynamicQrcode/Qrcode classes
- Audit log table for auth, user, and qrcode actions
- Checked-in db schema (db/init.sql, migrations/) instead of relying on an
  opaque prebuilt db image
- Production docker-compose with Nginx + php-fpm instead of the PHP dev server

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-08 15:00:33 +02:00
2020-09-08 16:56:05 +02:00
2025-09-02 21:52:03 +02:00

PHP Dynamic Qr code is a script that allows the generation and saving of dynamic and static QR codes. It has a clean, responsive, and user-friendly design. It is based on AdminLte, the "Best open source admin dashboard & control panel theme. Built on top of Bootstrap" and Core PHP Admin Panel, a simple Admin Panel written in core PHP that contains an implementation of general features you might need in your website admin panel like: record management (CRUD), secure authentication, pagination, filters.

LIVE DEMO

username: admin

password: admin

DOCUMENTATION

Features

  • #1 Dynamic Qr code generator on GitHub with a database to store Qr codes
  • Create unlimited Qr codes
  • Docker compose support
  • Control panel with 2 access levels
  • Multi-account
  • Dashboard with advanced statistics on Qr codes created and on scans
  • Bulk download, bulk delete
  • Dynamic Qr code
    • Create, modify, and delete Qr codes
    • You can download your Qr codes when you want
    • URL shortener with redirect
    • Enable or disable the link redirect
  • Static Qr code
    • Text QR Code
    • Email QR Code
    • Phone QR Code
    • Sms QR Code
    • Whatsapp QR Code
    • Skype QR Code
    • Location QR Code
    • Vcard QR Code
    • Event/calendar QR Code
    • Bookmark QR Code
    • Wifi QR Code
    • Paypal QR Code
    • Bitcoin QR Code
  • Customization of Qr codes
    • 6 formats for images
    • Foreground color
    • Background color
    • 4 levels of precision
    • 10 sizes
  • Responsive bootstrap-based design
  • Easy to understand and expand code
  • Full OOP with classes and well-documented

What is included

  • PHP files
  • .sql file with sample data
  • JS files
  • CSS files
  • Docker compose file

Setup with docker compose

  1. download docker-compose.yml file
  2. Start docker stack
docker compose build --no-cache && docker compose up -d
  1. Open your browser at http://localhost:80 and login with (username: superadmin, password: superadmin)
S
Description
Self-hosted QR-generator (MIT fork), publieke OSS-variant voor qr.ensembia.com
Readme MIT 15 MiB
Languages
JavaScript 79.3%
PHP 12.3%
CSS 5.1%
HTML 3.2%
Dockerfile 0.1%