@@ -4,7 +4,6 @@ |
||
4 | 4 | |
5 | 5 | use app\forms\Activation; |
6 | 6 | use yrc\rest\Action as RestAction; |
7 | - |
|
8 | 7 | use yii\web\HttpException; |
9 | 8 | use Yii; |
10 | 9 |
@@ -5,7 +5,6 @@ |
||
5 | 5 | use app\forms\Login; |
6 | 6 | use app\models\Token; |
7 | 7 | use yrc\rest\Action as RestAction; |
8 | - |
|
9 | 8 | use yii\web\UnauthorizedHttpException; |
10 | 9 | use Yii; |
11 | 10 |
@@ -38,7 +38,7 @@ |
||
38 | 38 | |
39 | 39 | /** |
40 | 40 | * Deauthenticates a user |
41 | - * @return mixed |
|
41 | + * @return boolean |
|
42 | 42 | */ |
43 | 43 | public function delete($params) |
44 | 44 | { |
@@ -4,7 +4,6 @@ |
||
4 | 4 | |
5 | 5 | use app\models\User; |
6 | 6 | use yrc\rest\Action as RestAction; |
7 | - |
|
8 | 7 | use yii\web\HttpException; |
9 | 8 | use Yii; |
10 | 9 |
@@ -224,7 +224,7 @@ |
||
224 | 224 | |
225 | 225 | /** |
226 | 226 | * Provisions TOTP for the account |
227 | - * @return boolean|string |
|
227 | + * @return false|string |
|
228 | 228 | */ |
229 | 229 | public function provisionOTP() |
230 | 230 | { |
@@ -4,7 +4,6 @@ |
||
4 | 4 | |
5 | 5 | use Base32\Base32; |
6 | 6 | use OTPHP\TOTP; |
7 | - |
|
8 | 7 | use yii\behaviors\TimestampBehavior; |
9 | 8 | use yii\db\ActiveRecord; |
10 | 9 | use yii\filters\RateLimitInterface; |
@@ -273,8 +273,8 @@ discard block |
||
273 | 273 | $encodedSecret = Base32::encode($secret); |
274 | 274 | $totp = TOTP::create( |
275 | 275 | $encodedSecret, |
276 | - 30, // 30 second window |
|
277 | - 'sha256', // SHA256 for the hashing algorithm |
|
276 | + 30, // 30 second window |
|
277 | + 'sha256', // SHA256 for the hashing algorithm |
|
278 | 278 | 6 // 6 digits |
279 | 279 | ); |
280 | 280 | $totp->setLabel($this->username); |
@@ -328,8 +328,8 @@ discard block |
||
328 | 328 | { |
329 | 329 | $totp = TOTP::create( |
330 | 330 | $this->otp_secret, |
331 | - 30, // 30 second window |
|
332 | - 'sha256', // SHA256 for the hashing algorithm |
|
331 | + 30, // 30 second window |
|
332 | + 'sha256', // SHA256 for the hashing algorithm |
|
333 | 333 | 6 // 6 digits |
334 | 334 | ); |
335 | 335 |
@@ -92,7 +92,7 @@ |
||
92 | 92 | private function isHMACSignatureValid($accessToken, $ikm, $salt, $request, $hmac = null) |
93 | 93 | { |
94 | 94 | static $selfHMAC = null; |
95 | - static $hkdf = null; |
|
95 | + static $hkdf = null; |
|
96 | 96 | |
97 | 97 | // Null check the HMAC string |
98 | 98 | if (empty($hmac) || $hmac === null) { |
@@ -87,6 +87,7 @@ discard block |
||
87 | 87 | * @param string $accessToken |
88 | 88 | * @param string $salt |
89 | 89 | * @param \yii\web\request $request |
90 | + * @param string $ikm |
|
90 | 91 | * @return bool |
91 | 92 | */ |
92 | 93 | private function isHMACSignatureValid($accessToken, $ikm, $salt, $request, $hmac = null) |
@@ -152,7 +153,7 @@ discard block |
||
152 | 153 | |
153 | 154 | /** |
154 | 155 | * Gets the datetime drift that has occured since the request was sent |
155 | - * @param yii\web\Request $request |
|
156 | + * @param \yii\web\Request $request |
|
156 | 157 | * @return int |
157 | 158 | */ |
158 | 159 | private function getTimeDrift($request) |
@@ -3,10 +3,7 @@ |
||
3 | 3 | namespace yrc\filters\auth; |
4 | 4 | |
5 | 5 | use app\models\Token; |
6 | - |
|
7 | -use yii\helpers\Json; |
|
8 | 6 | use yii\filters\auth\AuthMethod; |
9 | - |
|
10 | 7 | use Yii; |
11 | 8 | |
12 | 9 | /** |
@@ -137,9 +137,9 @@ |
||
137 | 137 | |
138 | 138 | // Calculate the signature string |
139 | 139 | $signatureString = hash('sha256', $body) . "\n" . |
140 | - $request->method . "+" . $request->getUrl() . "\n" . |
|
141 | - $request->getHeaders()->get(self::DATE_HEADER) . "\n" . |
|
142 | - \base64_encode($salt); |
|
140 | + $request->method . "+" . $request->getUrl() . "\n" . |
|
141 | + $request->getHeaders()->get(self::DATE_HEADER) . "\n" . |
|
142 | + \base64_encode($salt); |
|
143 | 143 | |
144 | 144 | // Calculate the HMAC |
145 | 145 | $selfHMAC = \base64_encode(\hash_hmac('sha256', $signatureString, \bin2hex($hkdf), true)); |
@@ -3,7 +3,6 @@ |
||
3 | 3 | namespace yrc\api\forms; |
4 | 4 | |
5 | 5 | use app\models\Token; |
6 | -use yii\web\UnauthorizedHttpException; |
|
7 | 6 | use Yii; |
8 | 7 | |
9 | 8 | /** |
@@ -2,7 +2,6 @@ |
||
2 | 2 | |
3 | 3 | namespace yrc\api\forms; |
4 | 4 | |
5 | -use Base32\Base32; |
|
6 | 5 | use Yii; |
7 | 6 | |
8 | 7 | /** |
@@ -4,8 +4,6 @@ |
||
4 | 4 | |
5 | 5 | use app\forms\ResetPassword; |
6 | 6 | use yrc\rest\Action as RestAction; |
7 | -use yrc\api\models\Code; |
|
8 | - |
|
9 | 7 | use yii\web\HttpException; |
10 | 8 | use Yii; |
11 | 9 |
@@ -2,9 +2,7 @@ |
||
2 | 2 | |
3 | 3 | namespace yrc\api\forms; |
4 | 4 | |
5 | -use Base32\Base32; |
|
6 | 5 | use Yii; |
7 | - |
|
8 | 6 | use yrc\api\models\Code; |
9 | 7 | |
10 | 8 | /** |