36 lines
1.4 KiB
PHP
36 lines
1.4 KiB
PHP
<?php
|
|
// app/assets/utils/otp_policy.php
|
|
//
|
|
// Email OTP login policy, set by OTP_REQUIRED in config.php.
|
|
//
|
|
// Fails safe: the OTP step is off only when the constant is defined and is
|
|
// exactly the boolean false. A missing constant (any config.php written before
|
|
// this switch existed), 0, 'false' or a typo all keep it on.
|
|
//
|
|
// While it is off, every sign-in that skips the OTP because of it is logged as
|
|
// OTP_BYPASSED, and the login page and top bar both say so on screen — a
|
|
// weakened sign-in must never be invisible to whoever is using it.
|
|
//
|
|
// Only the login OTP is affected. The staff/viewer and no-SMTP skips in
|
|
// login_otp.php still apply when it is on, and password-reset OTPs
|
|
// (PasswordResetManager) are a separate flow that stays on regardless.
|
|
|
|
if (!function_exists('otp_required')) {
|
|
function otp_required(): bool {
|
|
return !(defined('OTP_REQUIRED') && OTP_REQUIRED === false);
|
|
}
|
|
}
|
|
|
|
if (!function_exists('otp_log_bypass')) {
|
|
// There is no auth log table in this app, so bypasses go to the PHP error
|
|
// log (the container's Apache log) under a fixed, greppable tag.
|
|
function otp_log_bypass($user_id, string $where): void {
|
|
error_log(sprintf(
|
|
'[auth] OTP_BYPASSED user_id=%d ip=%s where=%s -- OTP_REQUIRED=false in config.php',
|
|
(int)$user_id,
|
|
$_SERVER['REMOTE_ADDR'] ?? '-',
|
|
$where
|
|
));
|
|
}
|
|
}
|