devstygian / devstygian/Simple-Auth-Template

Improve Authentication Security & Configuration

オープン
#7 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
help wanted high risk
主要言語
PHP
スター
4
フォーク
1
平均マージ
1時間 27分
マージ済み PR(30日)
1

説明

## Description

The current authentication system is working as a prototype, but there are several security and configuration issues that should be addressed before treating it as production-ready.

These fixes were intentionally deferred from the current prototype PR so they can be handled separately.

## Tasks

### Authentication Security

* [ ] **Regenerate session ID after login**

* Add `session_regenerate_id(true)` after successful authentication.
* Prevent session fixation attacks.

* [ ] **Add CSRF protection**

* Add CSRF tokens to login and register forms.
* Validate tokens server-side.
* Change logout from `GET` to `POST`.
* Protect other authentication-related POST requests where necessary.

* [ ] **Validate Google's `email_verified`**

* Require Google's `email_verified` value to be `true`.
* Do not treat a missing value as verified.
* Review the Google account-linking flow while making this change.

### 🔧 Configuration & Error Handling

* [ ] **Fix `config.local.php` loading**

* Make `config.local.php` optional.
* Prevent errors when the file does not exist on a fresh clone.
* Load local configuration before defining default values.
* Allow local configuration values to override defaults.

* [ ] **Hide raw database errors**

* Stop displaying raw database connection errors to users.
* Log the actual error for debugging.
* Display a generic error message to the user.

### 🧹 Additional Cleanup

* [ ] **Review `sanitize()`**

* Separate input validation from HTML escaping.
* Validate/normalize data before storing it.
* Use HTML escaping when outputting data.

* [ ] **Fix the Forgot Password link**

* Either implement `reset-password.php`
* Or remove/disable the link until the feature exists.

## Testing Checklist

After implementing the fixes:

* [ ] Normal login still works.
* [ ] Registration still works.
* [ ] Google login still works.
* [ ] Google callback still works.
* [ ] Logout works using POST.
* [ ] Invalid/missing CSRF tokens are rejected.
* [ ] Sessions are regenerated after successful login.
* [ ] Fresh clone works without `config.local.php`.
* [ ] Database errors are not exposed to users.
* [ ] No OAuth credentials are committed to Git.
* [ ] Forgot Password link no longer leads to a missing page.

## Notes

This issue is intended as a follow-up to the prototype authentication update.

The goal is **not** to completely refactor the authentication system. Keep the existing structure where possible and focus on fixing the identified security, configuration, and obvious functionality issues.

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

調査の方向性

まず、ログインフォームと登録フォーム、Google callback とアカウント連携フロー、ログアウトエンドポイント、config.local.php の読み込み、データベースエラー処理、およびパスワード忘れのリンクから reset-password.php への遷移を追跡します。最初の検証パスとしてテストチェックリストを使用してください。完了とは、一覧にある認証、設定、エラー表示、サニタイズ、リンクの動作が、認証情報や生のエラーを露出させずに機能することを意味します。

索引モデルが issue の本文から書いたものです。

評価

技術スタック
mysql, php
領域
authentication, backend, security
issue の種類
バグ
難易度
5/5
見積もり時間
1週間以上
活発さ
活発
明瞭さ
おおむね明確
初心者へのやさしさ
35/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。