]> git.mxchange.org Git - friendica.git/blobdiff - src/Module/Security/TwoFactor/Verify.php
Add more 2fa properties
[friendica.git] / src / Module / Security / TwoFactor / Verify.php
index 7d42456be3b7ce577162af010d8d9c2193e71a04..16f146d6dea4cf7d9bdce13807e68bf99b77f15c 100644 (file)
@@ -1,6 +1,6 @@
 <?php
 /**
- * @copyright Copyright (C) 2020, Friendica
+ * @copyright Copyright (C) 2010-2022, the Friendica project
  *
  * @license GNU AGPL version 3 or any later version
  *
@@ -25,7 +25,9 @@ use Friendica\BaseModule;
 use Friendica\Core\Renderer;
 use Friendica\Core\Session;
 use Friendica\DI;
+use Friendica\Model\User;
 use PragmaRX\Google2FA\Google2FA;
+use Friendica\Security\TwoFactor;
 
 /**
  * Page 1: Authenticator code verification
@@ -36,7 +38,7 @@ class Verify extends BaseModule
 {
        private static $errors = [];
 
-       public static function post(array $parameters = [])
+       protected function post(array $request = [])
        {
                if (!local_user()) {
                        return;
@@ -55,15 +57,28 @@ class Verify extends BaseModule
                        if ($valid && Session::get('2fa') !== $code) {
                                Session::set('2fa', $code);
 
+                               // Trust this browser feature
+                               if (!empty($_REQUEST['trust_browser'])) {
+                                       $trustedBrowserFactory = new TwoFactor\Factory\TrustedBrowser(DI::logger());
+                                       $trustedBrowserRepository = new TwoFactor\Repository\TrustedBrowser(DI::dba(), DI::logger(), $trustedBrowserFactory);
+
+                                       $trustedBrowser = $trustedBrowserFactory->createForUserWithUserAgent(local_user(), $_SERVER['HTTP_USER_AGENT']);
+
+                                       $trustedBrowserRepository->save($trustedBrowser);
+
+                                       // The string is sent to the browser to be sent back with each request
+                                       DI::cookie()->set('trusted', $trustedBrowser->cookie_hash);
+                               }
+
                                // Resume normal login workflow
-                               DI::auth()->setForUser($a, $a->user, true, true);
+                               DI::auth()->setForUser($a, User::getById($a->getLoggedInUserId()), true, true);
                        } else {
                                self::$errors[] = DI::l10n()->t('Invalid code, please retry.');
                        }
                }
        }
 
-       public static function content(array $parameters = [])
+       protected function content(array $request = []): string
        {
                if (!local_user()) {
                        DI::baseUrl()->redirect();
@@ -81,8 +96,9 @@ class Verify extends BaseModule
                        '$message'          => DI::l10n()->t('<p>Open the two-factor authentication app on your device to get an authentication code and verify your identity.</p>'),
                        '$errors_label'     => DI::l10n()->tt('Error', 'Errors', count(self::$errors)),
                        '$errors'           => self::$errors,
-                       '$recovery_message' => DI::l10n()->t('Don’t have your phone? <a href="%s">Enter a two-factor recovery code</a>', '2fa/recovery'),
-                       '$verify_code'      => ['verify_code', DI::l10n()->t('Please enter a code from your authentication app'), '', '', 'required', 'autofocus placeholder="000000"', 'tel'],
+                       '$recovery_message' => DI::l10n()->t('If you do not have access to your authentication code you can use <a href="%s">a two-factor recovery code</a>.', '2fa/recovery'),
+                       '$verify_code'      => ['verify_code', DI::l10n()->t('Please enter a code from your authentication app'), '', '', DI::l10n()->t('Required'), 'autofocus autocomplete="one-time-code" placeholder="000000" inputmode="numeric" pattern="[0-9]*"', 'tel'],
+                       '$trust_browser'    => ['trust_browser', DI::l10n()->t('This is my two-factor authenticator app device'), !empty($_REQUEST['trust_browser'])],
                        '$verify_label'     => DI::l10n()->t('Verify code and complete login'),
                ]);
        }