Add OTP_REQUIRED switch for email OTP login

This commit is contained in:
Thanakorn
2026-09-14 15:03:16 +07:00
parent 2f290ddb26
commit 9afcf072b0
11 changed files with 133 additions and 9 deletions
+10
View File
@@ -38,6 +38,16 @@ if (!defined('NODE_EMIT_SECRET')) {
define('NODE_EMIT_SECRET', 'YOUR_NODE_EMIT_SECRET'); // must match nodejs/.env EMIT_SECRET
}
// ── Login OTP ────────────────────────────────────────────────────────────────
// Email OTP on sign-in. LEAVE THIS TRUE unless password-only sign-in is wanted
// on purpose (e.g. a demo). It fails safe: anything other than the boolean
// false — the constant being absent included — keeps the OTP step on. While it
// is off, every sign-in is logged as OTP_BYPASSED and the login page and top
// bar both say so. Password-reset OTPs are not affected.
if (!defined('OTP_REQUIRED')) {
define('OTP_REQUIRED', true);
}
// ── Usage packages ───────────────────────────────────────────────────────────
// Keyed by company_list.package (defaults to 'starter'). Read by UsageGuard to
// enforce daily/weekly action limits and which features lock once exceeded.