Make email OTP login off by default
This commit is contained in:
@@ -3,21 +3,22 @@
|
||||
//
|
||||
// Email OTP login policy, set by OTP_REQUIRED in config.php.
|
||||
//
|
||||
// Fails safe: the OTP step is off only when the constant is defined and is
|
||||
// exactly the boolean false. A missing constant (any config.php written before
|
||||
// this switch existed), 0, 'false' or a typo all keep it on.
|
||||
// OFF BY DEFAULT: the OTP step runs only when the constant is defined and is
|
||||
// exactly the boolean true. A missing constant (any config.php written before
|
||||
// this switch existed), 1, 'true' or a typo all leave it off, so sign-in is
|
||||
// password only and no SMTP is needed to log in.
|
||||
//
|
||||
// While it is off, every sign-in that skips the OTP because of it is logged as
|
||||
// OTP_BYPASSED, and the login page and top bar both say so on screen — a
|
||||
// weakened sign-in must never be invisible to whoever is using it.
|
||||
// password-only sign-in must never be invisible to whoever is using it.
|
||||
//
|
||||
// Only the login OTP is affected. The staff/viewer and no-SMTP skips in
|
||||
// login_otp.php still apply when it is on, and password-reset OTPs
|
||||
// (PasswordResetManager) are a separate flow that stays on regardless.
|
||||
// Only the login OTP is affected. When it is on, the staff/viewer and no-SMTP
|
||||
// skips in login_otp.php still apply; password-reset OTPs (PasswordResetManager)
|
||||
// are a separate flow that stays on regardless.
|
||||
|
||||
if (!function_exists('otp_required')) {
|
||||
function otp_required(): bool {
|
||||
return !(defined('OTP_REQUIRED') && OTP_REQUIRED === false);
|
||||
return defined('OTP_REQUIRED') && OTP_REQUIRED === true;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -26,7 +27,7 @@ if (!function_exists('otp_log_bypass')) {
|
||||
// log (the container's Apache log) under a fixed, greppable tag.
|
||||
function otp_log_bypass($user_id, string $where): void {
|
||||
error_log(sprintf(
|
||||
'[auth] OTP_BYPASSED user_id=%d ip=%s where=%s -- OTP_REQUIRED=false in config.php',
|
||||
'[auth] OTP_BYPASSED user_id=%d ip=%s where=%s -- OTP_REQUIRED is not true in config.php',
|
||||
(int)$user_id,
|
||||
$_SERVER['REMOTE_ADDR'] ?? '-',
|
||||
$where
|
||||
|
||||
Reference in New Issue
Block a user