Version 4.5.0
This commit is contained in:
1 parent
1a0c7fd3c2
commit
f79dcf067a
3791 files changed
+248032
-76372
No files matched your search
@@ -11,7 +11,7 @@
|
||||
namespace IPS\MFA\GoogleAuthenticator;
|
||||
|
||||
/* To prevent PHP errors (extending class does not exist) revealing path */
|
||||
if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
{
|
||||
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
|
||||
exit;
|
||||
@@ -77,15 +77,15 @@ class _Handler extends \IPS\MFA\MFAHandler
|
||||
}
|
||||
else
|
||||
{
|
||||
if ( function_exists( 'random_bytes' ) )
|
||||
if ( \function_exists( 'random_bytes' ) )
|
||||
{
|
||||
$randomString = random_bytes( 16 );
|
||||
}
|
||||
elseif ( function_exists( 'mcrypt_create_iv' ) )
|
||||
elseif ( \function_exists( 'mcrypt_create_iv' ) )
|
||||
{
|
||||
$randomString = mcrypt_create_iv( 16, MCRYPT_DEV_URANDOM );
|
||||
}
|
||||
elseif ( function_exists( 'openssl_random_pseudo_bytes' ) )
|
||||
elseif ( \function_exists( 'openssl_random_pseudo_bytes' ) )
|
||||
{
|
||||
$randomString = openssl_random_pseudo_bytes( 16 );
|
||||
}
|
||||
@@ -97,7 +97,7 @@ class _Handler extends \IPS\MFA\MFAHandler
|
||||
$secret = '';
|
||||
for ( $i = 0; $i < 16; ++$i )
|
||||
{
|
||||
$secret .= $validChars[ ord( $randomString[ $i ] ) & 31 ];
|
||||
$secret .= $validChars[ \ord( $randomString[ $i ] ) & 31 ];
|
||||
}
|
||||
}
|
||||
|
||||
@@ -151,7 +151,7 @@ class _Handler extends \IPS\MFA\MFAHandler
|
||||
{
|
||||
try
|
||||
{
|
||||
$waitUntil = ( \IPS\Db::i()->select( 'time', 'core_googleauth_used_codes', array( 'member=?', $member->member_id ), 'time DESC', 1 )->first() * 30 ) + 30;
|
||||
$waitUntil = ( \IPS\Db::i()->select( 'time', 'core_googleauth_used_codes', array( '`member`=?', $member->member_id ), 'time DESC', 1 )->first() * 30 ) + 30;
|
||||
}
|
||||
catch ( \UnderflowException $e )
|
||||
{
|
||||
@@ -257,13 +257,13 @@ class _Handler extends \IPS\MFA\MFAHandler
|
||||
$submittedCode = str_replace( ' ', '', $submittedCode );
|
||||
|
||||
$validTimes = array( new \IPS\DateTime(), ( new \IPS\DateTime() )->add( new \DateInterval('PT30S') ), ( new \IPS\DateTime() )->sub( new \DateInterval('PT30S') ) );
|
||||
$blockedTimes = iterator_to_array( \IPS\Db::i()->select( 'time', 'core_googleauth_used_codes', array( 'member=?', $member->member_id ) ) );
|
||||
$blockedTimes = iterator_to_array( \IPS\Db::i()->select( 'time', 'core_googleauth_used_codes', array( '`member`=?', $member->member_id ) ) );
|
||||
|
||||
$allowedCodes = array();
|
||||
foreach ( $validTimes as $time )
|
||||
{
|
||||
$codeTime = floor( $time->getTimestamp() / 30 );
|
||||
if ( !in_array( $codeTime, $blockedTimes ) )
|
||||
if ( !\in_array( $codeTime, $blockedTimes ) )
|
||||
{
|
||||
$allowedCodes[ static::getCodeForSecretAtTime( $secret, $time ) ] = $codeTime;
|
||||
}
|
||||
@@ -301,17 +301,17 @@ class _Handler extends \IPS\MFA\MFAHandler
|
||||
$block .= str_pad( base_convert( $chars[ $secret[ $i + $j ] ], 10, 2 ), 5, '0', STR_PAD_LEFT );
|
||||
}
|
||||
$eightBits = str_split( $block, 8 );
|
||||
for ( $z = 0; $z < count( $eightBits ); ++$z )
|
||||
for ( $z = 0; $z < \count( $eightBits ); ++$z )
|
||||
{
|
||||
$decodedSecretKey .= ( ( $y = chr( base_convert( $eightBits[ $z ], 2, 10) ) ) || ord( $y ) == 48) ? $y : '';
|
||||
$decodedSecretKey .= ( ( $y = \chr( base_convert( $eightBits[ $z ], 2, 10) ) ) || \ord( $y ) == 48) ? $y : '';
|
||||
}
|
||||
}
|
||||
|
||||
/* Hash the timestamp with the secret key */
|
||||
$hash = hash_hmac('SHA1', chr(0).chr(0).chr(0).chr(0).pack('N*', floor( $time->getTimestamp() / 30 ) ), $decodedSecretKey, true);
|
||||
$hash = hash_hmac('SHA1', \chr(0).\chr(0).\chr(0).\chr(0).pack('N*', floor( $time->getTimestamp() / 30 ) ), $decodedSecretKey, true);
|
||||
|
||||
/* Unpack it */
|
||||
$value = unpack( 'N', \substr( $hash, ord( \substr( $hash, -1 ) ) & 0x0F, 4 ) );
|
||||
$value = unpack( 'N', \substr( $hash, \ord( \substr( $hash, -1 ) ) & 0x0F, 4 ) );
|
||||
$value = $value[1];
|
||||
|
||||
/* Get 32 bits */
|
||||
|
||||
Reference in new issue
Block a user