Make email OTP login off by default

This commit is contained in:
Thanakorn
2026-09-14 15:38:36 +07:00
parent 21148bf50c
commit 6b3a590aa9
9 changed files with 33 additions and 32 deletions
+10 -9
View File
@@ -3,21 +3,22 @@
//
// Email OTP login policy, set by OTP_REQUIRED in config.php.
//
// Fails safe: the OTP step is off only when the constant is defined and is
// exactly the boolean false. A missing constant (any config.php written before
// this switch existed), 0, 'false' or a typo all keep it on.
// OFF BY DEFAULT: the OTP step runs only when the constant is defined and is
// exactly the boolean true. A missing constant (any config.php written before
// this switch existed), 1, 'true' or a typo all leave it off, so sign-in is
// password only and no SMTP is needed to log in.
//
// While it is off, every sign-in that skips the OTP because of it is logged as
// OTP_BYPASSED, and the login page and top bar both say so on screen — a
// weakened sign-in must never be invisible to whoever is using it.
// password-only sign-in must never be invisible to whoever is using it.
//
// Only the login OTP is affected. The staff/viewer and no-SMTP skips in
// login_otp.php still apply when it is on, and password-reset OTPs
// (PasswordResetManager) are a separate flow that stays on regardless.
// Only the login OTP is affected. When it is on, the staff/viewer and no-SMTP
// skips in login_otp.php still apply; password-reset OTPs (PasswordResetManager)
// are a separate flow that stays on regardless.
if (!function_exists('otp_required')) {
function otp_required(): bool {
return !(defined('OTP_REQUIRED') && OTP_REQUIRED === false);
return defined('OTP_REQUIRED') && OTP_REQUIRED === true;
}
}
@@ -26,7 +27,7 @@ if (!function_exists('otp_log_bypass')) {
// log (the container's Apache log) under a fixed, greppable tag.
function otp_log_bypass($user_id, string $where): void {
error_log(sprintf(
'[auth] OTP_BYPASSED user_id=%d ip=%s where=%s -- OTP_REQUIRED=false in config.php',
'[auth] OTP_BYPASSED user_id=%d ip=%s where=%s -- OTP_REQUIRED is not true in config.php',
(int)$user_id,
$_SERVER['REMOTE_ADDR'] ?? '-',
$where
+5 -6
View File
@@ -39,13 +39,12 @@ if (!defined('NODE_EMIT_SECRET')) {
}
// ── Login OTP ────────────────────────────────────────────────────────────────
// Email OTP on sign-in. LEAVE THIS TRUE unless password-only sign-in is wanted
// on purpose (e.g. a demo). It fails safe: anything other than the boolean
// false — the constant being absent included — keeps the OTP step on. While it
// is off, every sign-in is logged as OTP_BYPASSED and the login page and top
// bar both say so. Password-reset OTPs are not affected.
// Email OTP on sign-in. OFF BY DEFAULT: only the boolean true turns it on —
// anything else, the constant being absent included, leaves sign-in password
// only (logged as OTP_BYPASSED, shown on the login page and top bar). Turn it
// on only with working SMTP. Password-reset OTPs are not affected.
if (!defined('OTP_REQUIRED')) {
define('OTP_REQUIRED', true);
define('OTP_REQUIRED', false);
}
// ── Usage packages ───────────────────────────────────────────────────────────
+2 -2
View File
@@ -199,12 +199,12 @@ $_usage_full = $_usage_max_pct >= 100;
</li>
<?php endif; ?>
<!-- Email OTP off: a weakened sign-in must never be invisible to whoever is using it -->
<!-- Email OTP off (the default): a password-only sign-in must never be invisible to whoever is using it -->
<?php if (!otp_required()): ?>
<li class="d-none d-md-block">
<span class="badge bg-warning text-dark d-flex align-items-center gap-1 px-2 py-1"
style="font-size:11px; cursor:default;"
title="OTP_REQUIRED=false in config.php">
title="OTP_REQUIRED is not true in config.php">
<i class="ti ti-shield-off"></i>
OTP off
</span>
+4 -4
View File
@@ -34,10 +34,10 @@
<form class="needs-validation mt-3" novalidate id="login-form">
<?php if (!otp_required()): ?>
<!-- OTP_REQUIRED=false in config.php: a weakened sign-in must never be invisible -->
<div class="alert alert-warning small py-2 mb-3" title="OTP_REQUIRED=false in config.php">
<!-- OTP_REQUIRED is not true in config.php (the default): a password-only sign-in must never be invisible -->
<div class="alert alert-warning small py-2 mb-3" title="OTP_REQUIRED is not true in config.php">
<i class="ti ti-alert-triangle me-1"></i>
Email OTP is temporarily disabled — sign-in is password only.
Email OTP is off — sign-in is password only.
</div>
<?php endif; ?>
<!-- first step login [OTP] -->
@@ -59,7 +59,7 @@
<div class="d-flex justify-content-between align-items-center mb-3">
<!-- "Remember me" is intentionally excluded.
This login uses 2FA (OTP via email) on every session, unless OTP_REQUIRED=false in config.php.
This login uses 2FA (OTP via email) on every session when OTP_REQUIRED=true in config.php (off by default).
A persistent login would bypass the OTP step and undermine the security model.
Do not add this back. -->
</div>