Add OTP_REQUIRED switch for email OTP login
This commit is contained in:
@@ -0,0 +1,35 @@
|
||||
<?php
|
||||
// app/assets/utils/otp_policy.php
|
||||
//
|
||||
// Email OTP login policy, set by OTP_REQUIRED in config.php.
|
||||
//
|
||||
// Fails safe: the OTP step is off only when the constant is defined and is
|
||||
// exactly the boolean false. A missing constant (any config.php written before
|
||||
// this switch existed), 0, 'false' or a typo all keep it on.
|
||||
//
|
||||
// While it is off, every sign-in that skips the OTP because of it is logged as
|
||||
// OTP_BYPASSED, and the login page and top bar both say so on screen — a
|
||||
// weakened sign-in must never be invisible to whoever is using it.
|
||||
//
|
||||
// Only the login OTP is affected. The staff/viewer and no-SMTP skips in
|
||||
// login_otp.php still apply when it is on, and password-reset OTPs
|
||||
// (PasswordResetManager) are a separate flow that stays on regardless.
|
||||
|
||||
if (!function_exists('otp_required')) {
|
||||
function otp_required(): bool {
|
||||
return !(defined('OTP_REQUIRED') && OTP_REQUIRED === false);
|
||||
}
|
||||
}
|
||||
|
||||
if (!function_exists('otp_log_bypass')) {
|
||||
// There is no auth log table in this app, so bypasses go to the PHP error
|
||||
// log (the container's Apache log) under a fixed, greppable tag.
|
||||
function otp_log_bypass($user_id, string $where): void {
|
||||
error_log(sprintf(
|
||||
'[auth] OTP_BYPASSED user_id=%d ip=%s where=%s -- OTP_REQUIRED=false in config.php',
|
||||
(int)$user_id,
|
||||
$_SERVER['REMOTE_ADDR'] ?? '-',
|
||||
$where
|
||||
));
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user