devstygian / devstygian/Simple-Auth-Template
Improve Authentication Security & Configuration
- Lingua principale
- PHP
- Stelle
- 4
- Fork
- 1
- Merge medio
- 1h 27m
- PR unite (30g)
- 1
Descrizione
## Description
The current authentication system is working as a prototype, but there are several security and configuration issues that should be addressed before treating it as production-ready.
These fixes were intentionally deferred from the current prototype PR so they can be handled separately.
## Tasks
### Authentication Security
* [ ] **Regenerate session ID after login**
* Add `session_regenerate_id(true)` after successful authentication.
* Prevent session fixation attacks.
* [ ] **Add CSRF protection**
* Add CSRF tokens to login and register forms.
* Validate tokens server-side.
* Change logout from `GET` to `POST`.
* Protect other authentication-related POST requests where necessary.
* [ ] **Validate Google's `email_verified`**
* Require Google's `email_verified` value to be `true`.
* Do not treat a missing value as verified.
* Review the Google account-linking flow while making this change.
### 🔧 Configuration & Error Handling
* [ ] **Fix `config.local.php` loading**
* Make `config.local.php` optional.
* Prevent errors when the file does not exist on a fresh clone.
* Load local configuration before defining default values.
* Allow local configuration values to override defaults.
* [ ] **Hide raw database errors**
* Stop displaying raw database connection errors to users.
* Log the actual error for debugging.
* Display a generic error message to the user.
### 🧹 Additional Cleanup
* [ ] **Review `sanitize()`**
* Separate input validation from HTML escaping.
* Validate/normalize data before storing it.
* Use HTML escaping when outputting data.
* [ ] **Fix the Forgot Password link**
* Either implement `reset-password.php`
* Or remove/disable the link until the feature exists.
## Testing Checklist
After implementing the fixes:
* [ ] Normal login still works.
* [ ] Registration still works.
* [ ] Google login still works.
* [ ] Google callback still works.
* [ ] Logout works using POST.
* [ ] Invalid/missing CSRF tokens are rejected.
* [ ] Sessions are regenerated after successful login.
* [ ] Fresh clone works without `config.local.php`.
* [ ] Database errors are not exposed to users.
* [ ] No OAuth credentials are committed to Git.
* [ ] Forgot Password link no longer leads to a missing page.
## Notes
This issue is intended as a follow-up to the prototype authentication update.
The goal is **not** to completely refactor the authentication system. Keep the existing structure where possible and focus on fixing the identified security, configuration, and obvious functionality issues.
Guida per i contributori
Nessuna guida per i contributori indicizzata per questo repository
Direzione di ricerca
Start by tracing the login and registration forms, Google callback and account-linking flow, logout endpoint, config.local.php loading, database error handling, and the forgot-password link to reset-password.php. Use the testing checklist as the first validation pass; done means the listed authentication, configuration, error-display, sanitization, and link behaviors work without exposing credentials or raw errors.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Valutazione
- Stack tecnologico
- mysql, php
- Ambito
- authentication, backend, security
- Tipo di issue
- Bug
- Difficoltà
- 5/5
- Tempo stimato
- Più di una settimana
- Stato di attività
- Attiva
- Chiarezza
- Abbastanza chiara
- Idoneità per principianti
- 35/100