|
|
@@ -6,12 +6,19 @@ class admin_login_model extends Model {
|
|
|
public function logmein() {
|
|
|
$data = $this->escapeArray($_REQUEST);
|
|
|
if ($_REQUEST['email']!='' && $_REQUEST['pass']!='') {
|
|
|
+ // Look the user up by identity only; the password is verified in PHP
|
|
|
+ // so we can support hashed passwords (and legacy plaintext during migration).
|
|
|
$result = $this->query("select * from azonics_admin_users where "
|
|
|
. "admin_status='1' and "
|
|
|
- . "(admin_email='".$data['email']."' or admin_name='".$data['email']."') and "
|
|
|
- . "admin_pass='".$data['pass']."';");
|
|
|
-
|
|
|
- if (sizeof($result)>0) {
|
|
|
+ . "(admin_email='".$data['email']."' or admin_name='".$data['email']."');");
|
|
|
+
|
|
|
+ if (sizeof($result)>0 && admin_utils::verifyPassword($_REQUEST['pass'], $result[0]->admin_pass)) {
|
|
|
+ // Upgrade legacy plaintext passwords to a proper hash on first valid login.
|
|
|
+ if (admin_utils::passwordNeedsRehash($result[0]->admin_pass)) {
|
|
|
+ $newHash = admin_utils::hashPassword($_REQUEST['pass']);
|
|
|
+ $this->execute("update azonics_admin_users set admin_pass='".$this->escapeString($newHash)."' where admin_id='".$result[0]->admin_id."';");
|
|
|
+ $result[0]->admin_pass = $newHash;
|
|
|
+ }
|
|
|
$this->execute("update azonics_admin_users set admin_last_ip='".$_SERVER['REMOTE_ADDR']."' where admin_id='".$result[0]->admin_id."';");
|
|
|
$_SESSION['admin_user'] = $result[0];
|
|
|
$_SESSION['access_level'] = $result[0]->admin_access_level;
|
|
|
@@ -37,6 +44,13 @@ class admin_login_model extends Model {
|
|
|
$data = $this->escapeArray($_REQUEST);
|
|
|
$result = $this->query("select * from azonics_admin_users where admin_email='".$data['email']."' and admin_status='1';");
|
|
|
if (sizeof($result)>0) {
|
|
|
+ // Passwords are stored hashed and can no longer be recovered, so we
|
|
|
+ // generate a new temporary password, store it hashed, and return the
|
|
|
+ // plaintext value so the caller can e-mail it to the user.
|
|
|
+ $tempPass = bin2hex(random_bytes(6));
|
|
|
+ $hash = admin_utils::hashPassword($tempPass);
|
|
|
+ $this->execute("update azonics_admin_users set admin_pass='".$this->escapeString($hash)."' where admin_id='".$result[0]->admin_id."';");
|
|
|
+ $result[0]->admin_pass = $tempPass;
|
|
|
return $result[0];
|
|
|
}
|
|
|
else {
|