Add OTP_REQUIRED switch for email OTP login
This commit is contained in:
@@ -58,6 +58,7 @@ require_once '../../../config.php';
|
||||
require_once '../../../preset.php';
|
||||
define('UNAUTHENTICATED_ROUTE', true);
|
||||
require_once '../../../assets/utils/db_auth.php';
|
||||
require_once '../../../assets/utils/otp_policy.php';
|
||||
|
||||
// ── Step 1: Load session state written by login_otp.php ───────────────────────
|
||||
$data["username"] = $_SESSION["login_data"]['username'];
|
||||
@@ -100,9 +101,15 @@ $_SESSION["diff"] = $otp_diff_minutes;
|
||||
|
||||
// ── Step 4: Validate OTP value and expiry ─────────────────────────────────────
|
||||
// Skipped for staff/viewer roles — login_otp.php sets skip_otp=true in session
|
||||
// so they never receive or enter an OTP. Admin/owner always go through this check.
|
||||
// so they never receive or enter an OTP. Admin/owner always go through this check,
|
||||
// unless OTP_REQUIRED=false in config.php: that also covers a user who was already
|
||||
// on the OTP screen when the switch was turned off.
|
||||
if (empty($_SESSION['skip_otp'])) {
|
||||
if ($data["otp"] != $otp || $otp_diff_minutes > 5) {
|
||||
if (!otp_required()) {
|
||||
if (!empty($user_id)) {
|
||||
otp_log_bypass($user_id, 'login_confirm');
|
||||
}
|
||||
} elseif ($data["otp"] != $otp || $otp_diff_minutes > 5) {
|
||||
$answer["message"] = "Wrong OTP! Please try again. (Our OTP is valid for 5 minute)";
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user