An easy point of sale system with automatic inventory tracking. https://netsyms.biz/apps/nickelbox/
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

124 lines
5.2KB

  1. <?php
  2. require_once __DIR__ . "/required.php";
  3. require_once __DIR__ . "/lib/login.php";
  4. /* Authenticate user */
  5. $userpass_ok = false;
  6. $multiauth = false;
  7. if ($VARS['progress'] == "1") {
  8. if (authenticate_user($VARS['username'], $VARS['password'])) {
  9. switch (get_account_status($VARS['username'])) {
  10. case "LOCKED_OR_DISABLED":
  11. $alert = lang("account locked", false);
  12. break;
  13. case "TERMINATED":
  14. $alert = lang("account terminated", false);
  15. break;
  16. case "CHANGE_PASSWORD":
  17. $alert = lang("password expired", false);
  18. case "NORMAL":
  19. $userpass_ok = true;
  20. break;
  21. case "ALERT_ON_ACCESS":
  22. sendLoginAlertEmail($VARS['username']);
  23. $userpass_ok = true;
  24. break;
  25. }
  26. if ($userpass_ok) {
  27. if (userHasTOTP($VARS['username'])) {
  28. $multiauth = true;
  29. } else {
  30. doLoginUser($VARS['username'], $VARS['password']);
  31. header('Location: app.php');
  32. die("Logged in, go to app.php");
  33. }
  34. }
  35. } else {
  36. $alert = lang("login incorrect", false);
  37. }
  38. } else if ($VARS['progress'] == "2") {
  39. if (verifyTOTP($VARS['username'], $VARS['authcode'])) {
  40. if (doLoginUser($VARS['username'])) {
  41. header('Location: app.php');
  42. die("Logged in, go to app.php");
  43. } else {
  44. $alert = lang("login server user data error", false);
  45. }
  46. } else {
  47. $alert = lang("2fa incorrect", false);
  48. }
  49. }
  50. ?>
  51. <!DOCTYPE html>
  52. <html>
  53. <head>
  54. <meta charset="UTF-8">
  55. <meta http-equiv="X-UA-Compatible" content="IE=edge">
  56. <meta name="viewport" contgreent="width=device-width, initial-scale=1">
  57. <title><?php echo SITE_TITLE; ?></title>
  58. <link href="static/css/bootstrap.min.css" rel="stylesheet">
  59. <link href="static/css/app.css" rel="stylesheet">
  60. </head>
  61. <body>
  62. <div class="container">
  63. <div class="row">
  64. <div class="col-xs-12 col-sm-6 col-md-4 col-lg-4 col-sm-offset-3 col-md-offset-4 col-lg-offset-4">
  65. <div>
  66. <?php
  67. if (SHOW_ICON == "both" || SHOW_ICON == "index") {
  68. ?>
  69. <img class="img-responsive banner-image" src="static/img/logo.png" />
  70. <?php } ?>
  71. </div>
  72. <div class="panel panel-primary">
  73. <div class="panel-heading">
  74. <h3 class="panel-title"><?php lang("sign in"); ?></h3>
  75. </div>
  76. <div class="panel-body">
  77. <form action="" method="POST">
  78. <?php
  79. if (!is_empty($alert)) {
  80. ?>
  81. <div class="alert alert-danger">
  82. <?php echo $alert; ?>
  83. </div>
  84. <?php
  85. }
  86. if ($multiauth != true) {
  87. ?>
  88. <input type="text" class="form-control" name="username" placeholder="<?php lang("username"); ?>" required="required" autofocus /><br />
  89. <input type="password" class="form-control" name="password" placeholder="<?php lang("password"); ?>" required="required" /><br />
  90. <input type="hidden" name="progress" value="1" />
  91. <?php
  92. } else if ($multiauth) {
  93. ?>
  94. <div class="alert alert-info">
  95. <?php lang("2fa prompt"); ?>
  96. </div>
  97. <input type="text" class="form-control" name="authcode" placeholder="<?php lang("authcode"); ?>" required="required" autofocus /><br />
  98. <input type="hidden" name="progress" value="2" />
  99. <input type="hidden" name="username" value="<?php echo $VARS['username']; ?>" />
  100. <?php
  101. }
  102. ?>
  103. <button type="submit" class="btn btn-primary">
  104. <?php lang("continue"); ?>
  105. </button>
  106. </form>
  107. </div>
  108. </div>
  109. </div>
  110. </div>
  111. <div class="footer">
  112. <?php echo LICENSE_TEXT; ?><br />
  113. Copyright &copy; <?php echo date('Y'); ?> <?php echo COPYRIGHT_NAME; ?>
  114. </div>
  115. </div>
  116. <script src="static/js/jquery-3.2.1.min.js"></script>
  117. <script src="static/js/bootstrap.min.js"></script>
  118. </body>
  119. </html>