Security hardening: fix SQLi, XSS, file upload, and migrate DB to RDS

- Fix all SQL injection vulnerabilities across Service_model, User_model,
  Module_model, Log_model, and Admin controller using parameterized queries
- Add htmlspecialchars() to all user-controlled output in admin views
  (bookings, services, workers, service categories, login form)
- Fix XSS in AJAX worker response and manage-booking-cancelled view
- Add file extension whitelist (jpg, jpeg, png, gif, webp) to all uploads
- Remove webshell (pentest2.php) from assets/img/profiles/
- Stop logging plaintext passwords on failed login attempts
- Migrate database.php hostname from localhost to AWS RDS endpoint
- Fix dropdown styling (white-on-white) in worker calendar view

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
Ubuntu
2026-05-07 13:00:32 +00:00
co-authored by Claude Opus 4.6
parent 307f17faa6
commit 420bcb37fd
20 changed files with 205 additions and 194 deletions
+1 -1
View File
@@ -75,7 +75,7 @@ $query_builder = TRUE;
$db['default'] = array(
'dsn' => '',
'hostname' => 'localhost',
'hostname' => 'database-1.chgossuk454l.eu-north-1.rds.amazonaws.com',
//'username' => 'root',
'username' => 'gzsgtetc_beve',
//'password' => '',