Make email OTP login off by default
This commit is contained in:
+1
-1
@@ -55,7 +55,7 @@ PUBLIC_HOST=$public_host
|
||||
EMIT_SECRET=$emit_secret
|
||||
SMTP_USERNAME=$smtp_user
|
||||
SMTP_PASSWORD=$smtp_pass
|
||||
OTP_REQUIRED=true
|
||||
OTP_REQUIRED=false
|
||||
HTTP_PORT=$http_port
|
||||
EOF
|
||||
chmod 600 "$ENV_FILE"
|
||||
|
||||
@@ -35,7 +35,7 @@ if (!defined('NODE_EMIT_SECRET')) {
|
||||
|
||||
// ── Login OTP ────────────────────────────────────────────────────────────────
|
||||
// Set from OTP_REQUIRED in .env and reconciled by the entrypoint on every start.
|
||||
// Fails safe: anything other than the boolean false keeps the OTP step on.
|
||||
// Off by default: anything other than the boolean true leaves the OTP step off.
|
||||
if (!defined('OTP_REQUIRED')) {
|
||||
define('OTP_REQUIRED', ${OTP_REQUIRED});
|
||||
}
|
||||
|
||||
@@ -4,10 +4,10 @@ set -e
|
||||
APP_DIR=/var/www/html/wms-app
|
||||
CONFIG=$APP_DIR/app/config.php
|
||||
|
||||
# Email OTP on sign-in. Anything but the exact string "false" means required,
|
||||
# so a typo or a missing variable can never switch it off.
|
||||
: "${OTP_REQUIRED:=true}"
|
||||
[ "$OTP_REQUIRED" = "false" ] || OTP_REQUIRED=true
|
||||
# Email OTP on sign-in, OFF BY DEFAULT. Only the exact string "true" turns it
|
||||
# on; a missing variable or anything else means false.
|
||||
: "${OTP_REQUIRED:=false}"
|
||||
[ "$OTP_REQUIRED" = "true" ] || OTP_REQUIRED=false
|
||||
export OTP_REQUIRED
|
||||
|
||||
# Generate app/config.php from template on first run only.
|
||||
@@ -34,7 +34,7 @@ else
|
||||
echo "[entrypoint] added OTP_REQUIRED = ${OTP_REQUIRED} to an existing config.php"
|
||||
fi
|
||||
if [ "$OTP_REQUIRED" = "false" ]; then
|
||||
echo "[entrypoint] WARNING -- email OTP is OFF; sign-in is password only."
|
||||
echo "[entrypoint] email OTP is off (OTP_REQUIRED=false); sign-in is password only."
|
||||
fi
|
||||
|
||||
mkdir -p "$APP_DIR/app/uploads"
|
||||
|
||||
Reference in New Issue
Block a user