Add OTP_REQUIRED switch for email OTP login
This commit is contained in:
+18
-2
@@ -1,6 +1,7 @@
|
||||
<?php
|
||||
require '../session.php';
|
||||
require '../config.php';
|
||||
require_once '../assets/utils/otp_policy.php';
|
||||
require '../include_header.php';
|
||||
// successful login — redirect based on app_access
|
||||
if(!empty($_SESSION["login_status"])){
|
||||
@@ -32,6 +33,13 @@
|
||||
</div>
|
||||
|
||||
<form class="needs-validation mt-3" novalidate id="login-form">
|
||||
<?php if (!otp_required()): ?>
|
||||
<!-- OTP_REQUIRED=false in config.php: a weakened sign-in must never be invisible -->
|
||||
<div class="alert alert-warning small py-2 mb-3" title="OTP_REQUIRED=false in config.php">
|
||||
<i class="ti ti-alert-triangle me-1"></i>
|
||||
Email OTP is temporarily disabled — sign-in is password only.
|
||||
</div>
|
||||
<?php endif; ?>
|
||||
<!-- first step login [OTP] -->
|
||||
<?php if(!isset($_SESSION['login_data'])){?>
|
||||
<div class="mb-3">
|
||||
@@ -51,7 +59,7 @@
|
||||
|
||||
<div class="d-flex justify-content-between align-items-center mb-3">
|
||||
<!-- "Remember me" is intentionally excluded.
|
||||
This login uses 2FA (OTP via email) on every session.
|
||||
This login uses 2FA (OTP via email) on every session, unless OTP_REQUIRED=false in config.php.
|
||||
A persistent login would bypass the OTP step and undermine the security model.
|
||||
Do not add this back. -->
|
||||
</div>
|
||||
@@ -62,6 +70,7 @@
|
||||
</p>
|
||||
<?php }else{ ?>
|
||||
<!-- second step login -->
|
||||
<?php if (otp_required()): ?>
|
||||
<div class="alert alert-warning small py-2 mb-3">
|
||||
<i class="ti ti-mail me-1"></i>
|
||||
OTP is sent via your company's SMTP setting.
|
||||
@@ -73,13 +82,20 @@
|
||||
<span>One Time Password</span>
|
||||
</label>
|
||||
<input id="otp" type="otp" class="form-control"
|
||||
placeholder="your otp for reference number <?php echo $_SESSION["reference"]?>" required minlength="6">
|
||||
placeholder="your otp for reference number <?php echo $_SESSION["reference"] ?? ''?>" required minlength="6">
|
||||
<div class="invalid-feedback">Please provide a otp (min 6 characters).</div>
|
||||
</div>
|
||||
<?php else: ?>
|
||||
<!-- OTP_REQUIRED was switched off while this session sat on the OTP step:
|
||||
login_confirm.php no longer checks the code, so there is nothing to type. -->
|
||||
<input id="otp" type="hidden" value="">
|
||||
<?php endif; ?>
|
||||
<div class="mb-3">
|
||||
<label for="password" class="form-label d-flex justify-content-between">
|
||||
<a href="javascript:;" class="small link-primary" onclick="back()">Back</a>
|
||||
<?php if (otp_required()): ?>
|
||||
<a href="javascript:;" class="small link-primary" onclick="request_new_otp();">Request New OTP</a>
|
||||
<?php endif; ?>
|
||||
</label>
|
||||
</div>
|
||||
<button class="btn btn-primary w-100" onclick="login_confirm();">Sign in</button>
|
||||
|
||||
Reference in New Issue
Block a user