Add OTP_REQUIRED switch for email OTP login

This commit is contained in:
Thanakorn
2026-09-14 15:03:16 +07:00
parent 2f290ddb26
commit 9afcf072b0
11 changed files with 133 additions and 9 deletions
+35
View File
@@ -0,0 +1,35 @@
<?php
// app/assets/utils/otp_policy.php
//
// Email OTP login policy, set by OTP_REQUIRED in config.php.
//
// Fails safe: the OTP step is off only when the constant is defined and is
// exactly the boolean false. A missing constant (any config.php written before
// this switch existed), 0, 'false' or a typo all keep it on.
//
// While it is off, every sign-in that skips the OTP because of it is logged as
// OTP_BYPASSED, and the login page and top bar both say so on screen — a
// weakened sign-in must never be invisible to whoever is using it.
//
// Only the login OTP is affected. The staff/viewer and no-SMTP skips in
// login_otp.php still apply when it is on, and password-reset OTPs
// (PasswordResetManager) are a separate flow that stays on regardless.
if (!function_exists('otp_required')) {
function otp_required(): bool {
return !(defined('OTP_REQUIRED') && OTP_REQUIRED === false);
}
}
if (!function_exists('otp_log_bypass')) {
// There is no auth log table in this app, so bypasses go to the PHP error
// log (the container's Apache log) under a fixed, greppable tag.
function otp_log_bypass($user_id, string $where): void {
error_log(sprintf(
'[auth] OTP_BYPASSED user_id=%d ip=%s where=%s -- OTP_REQUIRED=false in config.php',
(int)$user_id,
$_SERVER['REMOTE_ADDR'] ?? '-',
$where
));
}
}