1
|
|
|
<?php |
2
|
|
|
|
3
|
|
|
declare(strict_types=1); |
4
|
|
|
|
5
|
|
|
namespace Cortex\Auth\Http\Controllers\Frontarea; |
6
|
|
|
|
7
|
|
|
use Illuminate\Http\Request; |
8
|
|
|
use Illuminate\Support\Facades\Hash; |
9
|
|
|
use Cortex\Auth\Traits\TwoFactorAuthenticatesUsers; |
10
|
|
|
use Cortex\Foundation\Http\Controllers\AuthenticatedController; |
11
|
|
|
|
12
|
|
|
class ReauthenticationController extends AuthenticatedController |
13
|
|
|
{ |
14
|
|
|
use TwoFactorAuthenticatesUsers; |
15
|
|
|
|
16
|
|
|
/** |
17
|
|
|
* @param Request $request |
18
|
|
|
* |
19
|
|
|
* @return \Illuminate\Http\JsonResponse|\Illuminate\Http\RedirectResponse |
20
|
|
|
*/ |
21
|
|
|
public function processPassword(Request $request) |
22
|
|
|
{ |
23
|
|
|
$redirect_url = session('cortex.auth.reauthentication.intended'); |
24
|
|
|
$session_name = session('cortex.auth.reauthentication.session_name'); |
25
|
|
|
|
26
|
|
|
if (Hash::check($request->input('password'), request()->user($this->getGuard())->password)) { |
|
|
|
|
27
|
|
|
$this->setSession($session_name); |
28
|
|
|
|
29
|
|
|
return intend([ |
30
|
|
|
'intended' => url($redirect_url), |
31
|
|
|
]); |
32
|
|
|
} |
33
|
|
|
|
34
|
|
|
return intend([ |
35
|
|
|
'intended' => url($redirect_url), |
36
|
|
|
'withErrors' => [ |
37
|
|
|
'password' => trans('cortex/auth::messages.auth.failed'), |
38
|
|
|
], |
39
|
|
|
]); |
40
|
|
|
} |
41
|
|
|
|
42
|
|
|
/** |
43
|
|
|
* @param Request $request |
44
|
|
|
* |
45
|
|
|
* @return \Illuminate\Http\JsonResponse|\Illuminate\Http\RedirectResponse |
46
|
|
|
*/ |
47
|
|
|
public function processTwofactor(Request $request) |
48
|
|
|
{ |
49
|
|
|
$redirect_url = session('cortex.auth.reauthentication.intended'); |
50
|
|
|
$session_name = session('cortex.auth.reauthentication.session_name'); |
51
|
|
|
|
52
|
|
|
$user = $request->user($this->getGuard()); |
53
|
|
|
$token = (int) $request->input('token'); |
54
|
|
|
|
55
|
|
|
if ($this->attemptTwoFactor($user, $token)) { |
56
|
|
|
$this->setSession($session_name); |
57
|
|
|
|
58
|
|
|
return intend([ |
59
|
|
|
'intended' => url($redirect_url), |
60
|
|
|
]); |
61
|
|
|
} |
62
|
|
|
|
63
|
|
|
return intend([ |
64
|
|
|
'intended' => url($redirect_url), |
65
|
|
|
'withErrors' => ['token' => trans('cortex/auth::messages.verification.twofactor.invalid_token')], |
66
|
|
|
]); |
67
|
|
|
} |
68
|
|
|
|
69
|
|
|
/** |
70
|
|
|
* @param $session_name |
71
|
|
|
*/ |
72
|
|
|
protected function setSession($session_name) |
73
|
|
|
{ |
74
|
|
|
session()->put($session_name, time()); |
75
|
|
|
session()->forget('cortex.auth.reauthentication.intended'); |
76
|
|
|
session()->forget('cortex.auth.reauthentication.session_name'); |
77
|
|
|
} |
78
|
|
|
} |
79
|
|
|
|
This check looks at variables that are passed out again to other methods.
If the outgoing method call has stricter type requirements than the method itself, an issue is raised.
An additional type check may prevent trouble.