Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 0 additions & 10 deletions admin/language/english/admin_accounts_lang.php
Original file line number Diff line number Diff line change
Expand Up @@ -41,16 +41,6 @@

$lang['accounts_edit_password_legend'] = 'Password';

$lang['accounts_edit_mfa_question_legend'] = 'Multi Factor Authentication: Questions';
$lang['accounts_edit_mfa_question_field_reset_label'] = 'Set new qustions on next log in';
$lang['accounts_edit_mfa_question_field_reset_yes'] = '<strong>Yes</strong>, require user to set new security questions on next log in.';
$lang['accounts_edit_mfa_question_field_reset_no'] = '<strong>No</strong>, do not require user to set new security questions on next log in.';

$lang['accounts_edit_mfa_device_legend'] = 'Multi Factor Authentication: Device';
$lang['accounts_edit_mfa_device_field_reset_label'] = 'Setup a new device on next log in';
$lang['accounts_edit_mfa_device_field_reset_yes'] = '<strong>Yes</strong>, require user to setup a new security device on next log in.';
$lang['accounts_edit_mfa_device_field_reset_no'] = '<strong>No</strong>, do not require user to setup a new security device on next log in.';

$lang['accounts_edit_basic_legend'] = 'Basic Information';
$lang['accounts_edit_basic_field_first_placeholder'] = 'The user\'s first name';
$lang['accounts_edit_basic_field_last_placeholder'] = 'The user\'s surname';
Expand Down
17 changes: 0 additions & 17 deletions admin/views/Accounts/edit/inc-mfa-device.php

This file was deleted.

17 changes: 0 additions & 17 deletions admin/views/Accounts/edit/inc-mfa-question.php

This file was deleted.

24 changes: 0 additions & 24 deletions auth/config/auth.php
Original file line number Diff line number Diff line change
Expand Up @@ -36,27 +36,3 @@
* On login show the last known IP of the user
*/
$config['authShowLastIpOnLogin'] = false;

// --------------------------------------------------------------------------

/**
* Auth sub config files
* Load both versions, app version overrides Nails version
*/
$sAppPath = NAILS_APP_PATH . 'application/modules/auth/config/';
$sNailsPath = NAILS_PATH . 'module-auth/auth/config/';

$aFiles = [
'auth.twofactor.php',
];

foreach ($aFiles as $sFile) {

if (file_exists($sNailsPath . $sFile)) {
include $sNailsPath . $sFile;
}

if (file_exists($sAppPath . $sFile)) {
include $sAppPath . $sFile;
}
}
56 changes: 0 additions & 56 deletions auth/config/auth.twofactor.php

This file was deleted.

75 changes: 0 additions & 75 deletions auth/controllers/Login.php
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,6 @@
use Nails\Auth\Controller\Base;
use Nails\Auth\Exception\AuthException;
use Nails\Auth\Exception\Login\NoUserException;
use Nails\Auth\Exception\Login\RequiresMfaException;
use Nails\Auth\Exception\Login\RequiresPasswordResetExpiredException;
use Nails\Auth\Exception\Login\RequiresPasswordResetTempException;
use Nails\Auth\Model\User\Password;
Expand Down Expand Up @@ -151,9 +150,6 @@ public function index()
} catch (NoUserException $e) {
$this->oUserFeedback->error($e->getMessage());

} catch (RequiresMfaException $e) {
$this->handleMfa($oUser);

} catch (RequiresPasswordResetTempException $e) {
$this->handlePasswordReset($oUser, $bRemember, 'TEMP');

Expand Down Expand Up @@ -217,8 +213,6 @@ protected function handleLogin(Resource\User $oUser, bool $bRemember = false, st
$oConfig = Factory::service('Config');
/** @var Password $oUserPasswordModel */
$oUserPasswordModel = Factory::model('UserPassword', Constants::MODULE_SLUG);
/** @var Authentication $oAuthService */
$oAuthService = Factory::service('Authentication', Constants::MODULE_SLUG);

if (!empty($oUser->temp_pw)) {

Expand All @@ -228,10 +222,6 @@ protected function handleLogin(Resource\User $oUser, bool $bRemember = false, st

$this->handlePasswordReset($oUser, $bRemember, 'EXPIRED');

} elseif ($oConfig->item('authTwoFactorMode')) {

$this->handleMfa($oUser);

} else {

// Finally! Send this user on their merry way...
Expand Down Expand Up @@ -283,8 +273,6 @@ protected function handleLogin(Resource\User $oUser, bool $bRemember = false, st
/**
* Whether to offer this user a passkey before sending them on their way
*
* An MFA-challenged login never returns through here.
*
* @throws FactoryException
*/
protected function shouldNudgeForPasskey(Resource\User $oUser): bool
Expand All @@ -308,69 +296,6 @@ protected function shouldNudgeForPasskey(Resource\User $oUser): bool

// --------------------------------------------------------------------------

/**
* Handle MFA redirect
*
* @param Resource\User $oUser The user who requires MFA
* @param bool $bRemember Whether to set the rememberMe cookie or not
*
* @throws AuthException
* @throws FactoryException
*/
protected function handleMfa(Resource\User $oUser, bool $bRemember = false): void
{
/** @var Authentication $oAuthService */
$oAuthService = Factory::service('Authentication', Constants::MODULE_SLUG);
/** @var Config $oConfig */
$oConfig = Factory::service('Config');

$aTwoFactorToken = $oAuthService->mfaTokenGenerate($oUser->id);

if (!$aTwoFactorToken) {
throw new AuthException(
'A user tried to login and the system failed to generate a two-factor auth token.'
);
}

// Is there any query data?
$aQuery = array_filter([
'return_to' => $this->data['return_to'] ?: null,
'remember' => $bRemember,
]);

$sQuery = !empty($aQuery) ? '?' . http_build_query($aQuery) : '';

// Where we sending the user?
switch ($oConfig->item('authTwoFactorMode')) {

case 'QUESTION':
$sController = 'mfa/question';
break;

case 'DEVICE':
$sController = 'mfa/device';
break;

default:
throw new AuthException('"' . $oConfig->item('authTwoFactorMode') . '" is not a valid MFA Mode');
break;
}

// Compile the URL
$aUrl = [
'auth',
$sController,
$oUser->id,
$aTwoFactorToken['salt'],
$aTwoFactorToken['token'],
];

// Login was successful, redirect to the appropriate MFA page
redirect(implode('/', $aUrl) . $sQuery);
}

// --------------------------------------------------------------------------

/**
* @param Resource\User $oUser The user who is resetting their password
* @param bool $bRemember Whether to set the rememberMe cookie or not
Expand Down
Loading
Loading