Add OTP_REQUIRED switch for email OTP login
This commit is contained in:
@@ -62,6 +62,7 @@ require_once '../../../config.php';
|
||||
require_once '../../../preset.php';
|
||||
define('UNAUTHENTICATED_ROUTE', true);
|
||||
require_once '../../../assets/utils/db_auth.php';
|
||||
require_once '../../../assets/utils/otp_policy.php';
|
||||
|
||||
// ── Step 1: Resolve user_id from username or email (case-insensitive) ────────
|
||||
$sth = $pdo1->prepare("select user_id from user where ? in (username,email) ");
|
||||
@@ -253,11 +254,15 @@ if (password_verify(trim($data["password"]), $temp["password"])) {
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
|
||||
// ── Step 5g: Role check — staff/viewer skip OTP entirely ─────────────────
|
||||
// Owners always require 2FA. Invited users (license='user') require 2FA only
|
||||
// ── Step 5g: OTP policy, then role check — staff/viewer skip OTP entirely ─
|
||||
// OTP_REQUIRED=false in config.php turns the email OTP off for everyone and
|
||||
// logs the sign-in as a bypass (see assets/utils/otp_policy.php).
|
||||
// Otherwise owners always require 2FA. Invited users (license='user') require 2FA only
|
||||
// if their role in this company is admin or owner; staff/viewer go straight in.
|
||||
$requires_otp = true;
|
||||
if (($r['license'] ?? 'owner') !== 'owner') {
|
||||
$requires_otp = otp_required();
|
||||
if (!$requires_otp) {
|
||||
otp_log_bypass($user_id, 'login_otp');
|
||||
} elseif (($r['license'] ?? 'owner') !== 'owner') {
|
||||
$sth_role = $pdo1->prepare(
|
||||
"SELECT role FROM company_map_user WHERE company_id = :cid AND user_id = :uid LIMIT 1"
|
||||
);
|
||||
|
||||
Reference in New Issue
Block a user