Version 4.5.0

This commit is contained in:
Neo committed 2025-12-19 05:51:58 -08:00
1 parent 1a0c7fd3c2
commit f79dcf067a
3791 files changed
+248032 -76372

No files matched your search

+12 -12
View File
@@ -11,7 +11,7 @@
namespace IPS\MFA\GoogleAuthenticator;
/* To prevent PHP errors (extending class does not exist) revealing path */
if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
{
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
exit;
@@ -77,15 +77,15 @@ class _Handler extends \IPS\MFA\MFAHandler
}
else
{
if ( function_exists( 'random_bytes' ) )
if ( \function_exists( 'random_bytes' ) )
{
$randomString = random_bytes( 16 );
}
elseif ( function_exists( 'mcrypt_create_iv' ) )
elseif ( \function_exists( 'mcrypt_create_iv' ) )
{
$randomString = mcrypt_create_iv( 16, MCRYPT_DEV_URANDOM );
}
elseif ( function_exists( 'openssl_random_pseudo_bytes' ) )
elseif ( \function_exists( 'openssl_random_pseudo_bytes' ) )
{
$randomString = openssl_random_pseudo_bytes( 16 );
}
@@ -97,7 +97,7 @@ class _Handler extends \IPS\MFA\MFAHandler
$secret = '';
for ( $i = 0; $i < 16; ++$i )
{
$secret .= $validChars[ ord( $randomString[ $i ] ) & 31 ];
$secret .= $validChars[ \ord( $randomString[ $i ] ) & 31 ];
}
}
@@ -151,7 +151,7 @@ class _Handler extends \IPS\MFA\MFAHandler
{
try
{
$waitUntil = ( \IPS\Db::i()->select( 'time', 'core_googleauth_used_codes', array( 'member=?', $member->member_id ), 'time DESC', 1 )->first() * 30 ) + 30;
$waitUntil = ( \IPS\Db::i()->select( 'time', 'core_googleauth_used_codes', array( '`member`=?', $member->member_id ), 'time DESC', 1 )->first() * 30 ) + 30;
}
catch ( \UnderflowException $e )
{
@@ -257,13 +257,13 @@ class _Handler extends \IPS\MFA\MFAHandler
$submittedCode = str_replace( ' ', '', $submittedCode );
$validTimes = array( new \IPS\DateTime(), ( new \IPS\DateTime() )->add( new \DateInterval('PT30S') ), ( new \IPS\DateTime() )->sub( new \DateInterval('PT30S') ) );
$blockedTimes = iterator_to_array( \IPS\Db::i()->select( 'time', 'core_googleauth_used_codes', array( 'member=?', $member->member_id ) ) );
$blockedTimes = iterator_to_array( \IPS\Db::i()->select( 'time', 'core_googleauth_used_codes', array( '`member`=?', $member->member_id ) ) );
$allowedCodes = array();
foreach ( $validTimes as $time )
{
$codeTime = floor( $time->getTimestamp() / 30 );
if ( !in_array( $codeTime, $blockedTimes ) )
if ( !\in_array( $codeTime, $blockedTimes ) )
{
$allowedCodes[ static::getCodeForSecretAtTime( $secret, $time ) ] = $codeTime;
}
@@ -301,17 +301,17 @@ class _Handler extends \IPS\MFA\MFAHandler
$block .= str_pad( base_convert( $chars[ $secret[ $i + $j ] ], 10, 2 ), 5, '0', STR_PAD_LEFT );
}
$eightBits = str_split( $block, 8 );
for ( $z = 0; $z < count( $eightBits ); ++$z )
for ( $z = 0; $z < \count( $eightBits ); ++$z )
{
$decodedSecretKey .= ( ( $y = chr( base_convert( $eightBits[ $z ], 2, 10) ) ) || ord( $y ) == 48) ? $y : '';
$decodedSecretKey .= ( ( $y = \chr( base_convert( $eightBits[ $z ], 2, 10) ) ) || \ord( $y ) == 48) ? $y : '';
}
}
/* Hash the timestamp with the secret key */
$hash = hash_hmac('SHA1', chr(0).chr(0).chr(0).chr(0).pack('N*', floor( $time->getTimestamp() / 30 ) ), $decodedSecretKey, true);
$hash = hash_hmac('SHA1', \chr(0).\chr(0).\chr(0).\chr(0).pack('N*', floor( $time->getTimestamp() / 30 ) ), $decodedSecretKey, true);
/* Unpack it */
$value = unpack( 'N', \substr( $hash, ord( \substr( $hash, -1 ) ) & 0x0F, 4 ) );
$value = unpack( 'N', \substr( $hash, \ord( \substr( $hash, -1 ) ) & 0x0F, 4 ) );
$value = $value[1];
/* Get 32 bits */