-
Notifications
You must be signed in to change notification settings - Fork 2
Expand file tree
/
Copy pathcodeigniter-login.example.php
More file actions
32 lines (29 loc) · 1.37 KB
/
Copy pathcodeigniter-login.example.php
File metadata and controls
32 lines (29 loc) · 1.37 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
<?php
/**
* Integration fragment for a CI 3 login controller.
* @author Yash Desai
*
* Documentation, not an endpoint or a complete login controller.
* Adapt $authenticatedUser to your own authentication result. Run only AFTER
* password/SSO, MFA, active-account and email-ownership checks have succeeded.
* Never construct these claims directly from POST data or a supplied email.
*/
defined('BASEPATH') || exit('No direct script access allowed');
// $authenticatedUser must come from your trusted authentication service:
// array('id' => immutable database ID, 'email' => verified account email).
// Also clear old claims at the START of login/account-switch flows, before any
// operation that could fail. The successful-login fragment below replaces them.
$this->session->unset_userdata('ciwp_identity');
$this->session->sess_regenerate(true);
$this->session->set_userdata('ciwp_identity', array(
'authenticated' => true,
'subject' => (string) $authenticatedUser['id'],
'email' => $authenticatedUser['email'],
'email_verified' => true,
));
// Persist before redirecting to WordPress so it sees the completed login.
session_write_close();
// In your separate logout handler, after the app's normal CSRF checks:
// $this->session->unset_userdata('ciwp_identity');
// $this->session->sess_destroy();
// Invalidate relevant sessions on account disablement or security revocation.