auth.php 6.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232
  1. <?php
  2. /**
  3. * lib/auth.php
  4. *
  5. * Authentication and authorisation functions.
  6. * Requires config/database.php to be included before use.
  7. */
  8. if (session_status() === PHP_SESSION_NONE) {
  9. session_start();
  10. }
  11. // ---------------------------------------------------------------------------
  12. // Session helpers
  13. // ---------------------------------------------------------------------------
  14. function isLoggedIn(): bool
  15. {
  16. return isset($_SESSION['user_id']) && !empty($_SESSION['user_id']);
  17. }
  18. function getCurrentUserId(): ?int
  19. {
  20. return isset($_SESSION['user_id']) ? (int) $_SESSION['user_id'] : null;
  21. }
  22. function getCurrentUser(): ?array
  23. {
  24. if (!isLoggedIn()) {
  25. return null;
  26. }
  27. return [
  28. 'id' => (int) $_SESSION['user_id'],
  29. 'fullname' => $_SESSION['user_name'] ?? '',
  30. 'email' => $_SESSION['user_email'] ?? '',
  31. ];
  32. }
  33. function requireLogin(): void
  34. {
  35. if (!isLoggedIn()) {
  36. header('Location: /login/login.php');
  37. exit;
  38. }
  39. }
  40. function hasPermission(string $permission): bool
  41. {
  42. // Stub — extend with role checks when roles are introduced
  43. return isLoggedIn();
  44. }
  45. // ---------------------------------------------------------------------------
  46. // Login / Logout
  47. // ---------------------------------------------------------------------------
  48. /**
  49. * Attempt login with email + plain-text password.
  50. * Returns user row array on success, null on failure.
  51. */
  52. function loginUser(string $email, string $password): ?array
  53. {
  54. $pdo = getDBConnection();
  55. $stmt = $pdo->prepare(
  56. 'SELECT id, fullname, email, password FROM users WHERE email = ? AND active = 1 LIMIT 1'
  57. );
  58. $stmt->execute([strtolower(trim($email))]);
  59. $user = $stmt->fetch();
  60. if (!$user || !password_verify($password, $user['password'])) {
  61. return null;
  62. }
  63. // Rehash on cost/algorithm upgrade
  64. if (password_needs_rehash($user['password'], PASSWORD_DEFAULT)) {
  65. $pdo->prepare('UPDATE users SET password = ? WHERE id = ?')
  66. ->execute([password_hash($password, PASSWORD_DEFAULT), $user['id']]);
  67. }
  68. session_regenerate_id(true);
  69. $_SESSION['user_id'] = $user['id'];
  70. $_SESSION['user_name'] = $user['fullname'];
  71. $_SESSION['user_email'] = $user['email'];
  72. return $user;
  73. }
  74. /**
  75. * Destroy session completely and clear the session cookie.
  76. */
  77. function logoutUser(): void
  78. {
  79. $_SESSION = [];
  80. if (ini_get('session.use_cookies')) {
  81. $p = session_get_cookie_params();
  82. setcookie(
  83. session_name(), '', time() - 42000,
  84. $p['path'], $p['domain'], $p['secure'], $p['httponly']
  85. );
  86. }
  87. session_destroy();
  88. }
  89. // ---------------------------------------------------------------------------
  90. // Registration
  91. // ---------------------------------------------------------------------------
  92. /**
  93. * Register a new user.
  94. * Returns ['success' => true, 'user_id' => int]
  95. * or ['success' => false, 'error' => string]
  96. */
  97. function registerUser(array $data): array
  98. {
  99. $pdo = getDBConnection();
  100. $email = strtolower(trim($data['email'] ?? ''));
  101. // Duplicate email check
  102. $stmt = $pdo->prepare('SELECT id FROM users WHERE email = ? LIMIT 1');
  103. $stmt->execute([$email]);
  104. if ($stmt->fetch()) {
  105. return ['success' => false, 'error' => 'An account with that email already exists.'];
  106. }
  107. $stmt = $pdo->prepare('
  108. INSERT INTO users
  109. (fullname, email, password, company, mobilephone, industry, role, city, state, postcode, country, active, created_at)
  110. VALUES
  111. (?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, 1, NOW())
  112. ');
  113. $stmt->execute([
  114. trim($data['fullname'] ?? ''),
  115. $email,
  116. password_hash($data['password'], PASSWORD_DEFAULT),
  117. trim($data['company'] ?? ''),
  118. trim($data['mobilephone'] ?? ''),
  119. $data['industry'] ?? '',
  120. $data['role'] ?? '',
  121. trim($data['city'] ?? ''),
  122. $data['state'] ?? '',
  123. trim($data['postcode'] ?? ''),
  124. $data['country'] ?? 'Australia',
  125. ]);
  126. return ['success' => true, 'user_id' => (int) $pdo->lastInsertId()];
  127. }
  128. // ---------------------------------------------------------------------------
  129. // Password reset
  130. // ---------------------------------------------------------------------------
  131. /**
  132. * Create a password-reset token for $email (1-hour expiry).
  133. * Returns the raw token string, or null if the email doesn't exist.
  134. */
  135. function createPasswordResetToken(string $email): ?string
  136. {
  137. $pdo = getDBConnection();
  138. $email = strtolower(trim($email));
  139. $stmt = $pdo->prepare('SELECT id FROM users WHERE email = ? AND active = 1 LIMIT 1');
  140. $stmt->execute([$email]);
  141. if (!$stmt->fetch()) {
  142. return null;
  143. }
  144. // Remove any previous tokens for this email
  145. $pdo->prepare('DELETE FROM password_resets WHERE email = ?')->execute([$email]);
  146. $token = bin2hex(random_bytes(32));
  147. $pdo->prepare(
  148. 'INSERT INTO password_resets (email, token, created_at, expires_at)
  149. VALUES (?, ?, NOW(), DATE_ADD(NOW(), INTERVAL 1 HOUR))'
  150. )->execute([$email, $token]);
  151. return $token;
  152. }
  153. /**
  154. * Validate a reset token. Returns the associated email on success, null if invalid/expired.
  155. */
  156. function validatePasswordResetToken(string $token): ?string
  157. {
  158. $pdo = getDBConnection();
  159. $stmt = $pdo->prepare(
  160. 'SELECT email FROM password_resets WHERE token = ? AND expires_at > NOW() LIMIT 1'
  161. );
  162. $stmt->execute([$token]);
  163. $row = $stmt->fetch();
  164. return $row ? $row['email'] : null;
  165. }
  166. /**
  167. * Update the user's password and delete the reset token.
  168. */
  169. function resetPassword(string $token, string $newPassword): bool
  170. {
  171. $pdo = getDBConnection();
  172. $email = validatePasswordResetToken($token);
  173. if (!$email) {
  174. return false;
  175. }
  176. $pdo->prepare('UPDATE users SET password = ? WHERE email = ?')
  177. ->execute([password_hash($newPassword, PASSWORD_DEFAULT), $email]);
  178. $pdo->prepare('DELETE FROM password_resets WHERE email = ?')->execute([$email]);
  179. return true;
  180. }
  181. /**
  182. * Change password for currently logged-in user after verifying old password.
  183. * Returns true on success, false if old password is wrong.
  184. */
  185. function changePassword(int $userId, string $oldPassword, string $newPassword): bool
  186. {
  187. $pdo = getDBConnection();
  188. $stmt = $pdo->prepare('SELECT password FROM users WHERE id = ? LIMIT 1');
  189. $stmt->execute([$userId]);
  190. $user = $stmt->fetch();
  191. if (!$user || !password_verify($oldPassword, $user['password'])) {
  192. return false;
  193. }
  194. $pdo->prepare('UPDATE users SET password = ? WHERE id = ?')
  195. ->execute([password_hash($newPassword, PASSWORD_DEFAULT), $userId]);
  196. return true;
  197. }