Add OTP_REQUIRED switch for email OTP login
This commit is contained in:
@@ -33,6 +33,13 @@ if (!defined('NODE_EMIT_SECRET')) {
|
||||
define('NODE_EMIT_SECRET', '${EMIT_SECRET}');
|
||||
}
|
||||
|
||||
// ── Login OTP ────────────────────────────────────────────────────────────────
|
||||
// Set from OTP_REQUIRED in .env and reconciled by the entrypoint on every start.
|
||||
// Fails safe: anything other than the boolean false keeps the OTP step on.
|
||||
if (!defined('OTP_REQUIRED')) {
|
||||
define('OTP_REQUIRED', ${OTP_REQUIRED});
|
||||
}
|
||||
|
||||
// ── Usage packages ───────────────────────────────────────────────────────────
|
||||
$packages = [
|
||||
'starter' => [
|
||||
|
||||
@@ -4,15 +4,39 @@ set -e
|
||||
APP_DIR=/var/www/html/wms-app
|
||||
CONFIG=$APP_DIR/app/config.php
|
||||
|
||||
# Email OTP on sign-in. Anything but the exact string "false" means required,
|
||||
# so a typo or a missing variable can never switch it off.
|
||||
: "${OTP_REQUIRED:=true}"
|
||||
[ "$OTP_REQUIRED" = "false" ] || OTP_REQUIRED=true
|
||||
export OTP_REQUIRED
|
||||
|
||||
# Generate app/config.php from template on first run only.
|
||||
# Restrict envsubst to known placeholders so it never touches the app's own
|
||||
# $variable syntax (envsubst blanks out any $NAME it doesn't recognize).
|
||||
if [ ! -f "$CONFIG" ]; then
|
||||
echo "[entrypoint] generating app/config.php"
|
||||
envsubst '${DB_ROOT_PASSWORD} ${PUBLIC_HOST} ${EMIT_SECRET} ${SMTP_USERNAME} ${SMTP_PASSWORD}' \
|
||||
envsubst '${DB_ROOT_PASSWORD} ${PUBLIC_HOST} ${EMIT_SECRET} ${SMTP_USERNAME} ${SMTP_PASSWORD} ${OTP_REQUIRED}' \
|
||||
< /usr/local/etc/wms/config.php.template > "$CONFIG"
|
||||
fi
|
||||
|
||||
# config.php is never regenerated once it exists, so OTP_REQUIRED is the one
|
||||
# line reconciled on every start: the .env value always wins, and a config.php
|
||||
# written before this switch existed gets the line added.
|
||||
if grep -q "define('OTP_REQUIRED'" "$CONFIG"; then
|
||||
if ! grep -q "define('OTP_REQUIRED', ${OTP_REQUIRED});" "$CONFIG"; then
|
||||
sed -i "s/define('OTP_REQUIRED', [A-Za-z]*);/define('OTP_REQUIRED', ${OTP_REQUIRED});/" "$CONFIG"
|
||||
echo "[entrypoint] OTP_REQUIRED is now ${OTP_REQUIRED}"
|
||||
fi
|
||||
else
|
||||
# Drop a closing ?> on the last line so the appended block stays inside PHP.
|
||||
sed -i -e '${/^[[:space:]]*?>[[:space:]]*$/d}' "$CONFIG"
|
||||
printf "\nif (!defined('OTP_REQUIRED')) {\n\tdefine('OTP_REQUIRED', %s);\n}\n" "$OTP_REQUIRED" >> "$CONFIG"
|
||||
echo "[entrypoint] added OTP_REQUIRED = ${OTP_REQUIRED} to an existing config.php"
|
||||
fi
|
||||
if [ "$OTP_REQUIRED" = "false" ]; then
|
||||
echo "[entrypoint] WARNING -- email OTP is OFF; sign-in is password only."
|
||||
fi
|
||||
|
||||
mkdir -p "$APP_DIR/app/uploads"
|
||||
chown -R www-data:www-data "$APP_DIR/app/uploads"
|
||||
|
||||
|
||||
Reference in New Issue
Block a user