Update besar apk finance
This commit is contained in:
@@ -17,26 +17,50 @@ class Auth extends CI_Controller {
|
||||
$this->load->view('auth/login');
|
||||
}
|
||||
|
||||
public function process_login()
|
||||
{
|
||||
$username = $this->input->post('username');
|
||||
$password = $this->input->post('password');
|
||||
public function process_login()
|
||||
{
|
||||
if (strtoupper($this->input->method()) !== 'POST') {
|
||||
show_error('Metode request tidak diizinkan.', 405);
|
||||
}
|
||||
|
||||
$lockedUntil = (int) $this->session->userdata('login_locked_until');
|
||||
if ($lockedUntil > time()) {
|
||||
$remaining = max(1, (int) ceil(($lockedUntil - time()) / 60));
|
||||
$this->session->set_flashdata('error', 'Terlalu banyak percobaan login. Coba kembali dalam ' . $remaining . ' menit.');
|
||||
redirect('auth');
|
||||
return;
|
||||
}
|
||||
|
||||
$username = trim((string) $this->input->post('username', true));
|
||||
$password = (string) $this->input->post('password');
|
||||
|
||||
if ($username === '' || $password === '') {
|
||||
$this->session->set_flashdata('error', 'Username dan password wajib diisi.');
|
||||
redirect('auth');
|
||||
return;
|
||||
}
|
||||
|
||||
$user = $this->db->get_where('v_users', ['username' => $username])->row();
|
||||
|
||||
if ($user && password_verify($password, $user->password)) {
|
||||
if ($user && (int)$user->role_is_active === 1 && password_verify($password, $user->password)) {
|
||||
|
||||
$this->session->sess_regenerate(true);
|
||||
$this->session->unset_userdata(array('login_attempts', 'login_locked_until'));
|
||||
|
||||
// Decode permissions
|
||||
$permissions = json_decode($user->permissions, true);
|
||||
if (!is_array($permissions)) {
|
||||
$permissions = [];
|
||||
}
|
||||
$permissions = json_decode($user->permissions, true);
|
||||
if (!is_array($permissions)) {
|
||||
$permissions = [];
|
||||
}
|
||||
$role = $this->db->select('is_super_admin')->get_where('roles', array('id' => (int)$user->role_id))->row();
|
||||
|
||||
$session_data = [
|
||||
'user_id' => $user->id,
|
||||
'nama' => $user->nama,
|
||||
'username' => $user->username,
|
||||
'role' => $user->nama_role,
|
||||
'role' => $user->nama_role,
|
||||
'role_id' => (int) $user->role_id,
|
||||
'is_super_admin'=> $role && (int)$role->is_super_admin === 1,
|
||||
'permissions' => $permissions,
|
||||
'logged_in' => TRUE
|
||||
];
|
||||
@@ -53,7 +77,17 @@ class Auth extends CI_Controller {
|
||||
|
||||
redirect('dashboard');
|
||||
|
||||
} else {
|
||||
} else {
|
||||
|
||||
$attempts = (int) $this->session->userdata('login_attempts') + 1;
|
||||
$this->session->set_userdata('login_attempts', $attempts);
|
||||
|
||||
if ($attempts >= 5) {
|
||||
$this->session->set_userdata(array(
|
||||
'login_attempts' => 0,
|
||||
'login_locked_until' => time() + 300
|
||||
));
|
||||
}
|
||||
|
||||
// 🔥 LOG LOGIN GAGAL
|
||||
log_activity(
|
||||
@@ -63,7 +97,7 @@ class Auth extends CI_Controller {
|
||||
'failed'
|
||||
);
|
||||
|
||||
$this->session->set_flashdata('error', 'Username atau Password salah!');
|
||||
$this->session->set_flashdata('error', 'Username atau password salah.');
|
||||
redirect('auth');
|
||||
}
|
||||
}
|
||||
@@ -84,4 +118,4 @@ class Auth extends CI_Controller {
|
||||
redirect('auth');
|
||||
}
|
||||
}
|
||||
?>
|
||||
?>
|
||||
|
||||
Reference in New Issue
Block a user