Skip to content
Extraits de code Groupes Projets
sessions_controller.rb 1,77 ko
Newer Older
# frozen_string_literal: true

danielgrippi's avatar
danielgrippi a validé
#   Copyright (c) 2010-2011, Diaspora Inc.  This file is
#   licensed under the Affero General Public License version 3 or later.  See
#   the COPYRIGHT file.

class SessionsController < Devise::SessionsController
lislis's avatar
lislis a validé
  # rubocop:disable Rails/LexicallyScopedActionFilter
  before_action :authenticate_with_2fa, only: :create
  after_action :reset_authentication_token, only: :create
  before_action :reset_authentication_token, only: :destroy
  # rubocop:enable Rails/LexicallyScopedActionFilter

  def find_user
    return User.find_for_authentication(username: params[:user][:username]) if params[:user][:username]
    User.find(session[:otp_user_id]) if session[:otp_user_id]
lislis's avatar
lislis a validé
  end

  def authenticate_with_2fa
    self.resource = find_user

    return true unless resource&.otp_required_for_login?
lislis's avatar
lislis a validé

    if params[:user][:otp_attempt].present? && session[:otp_user_id]
      authenticate_with_two_factor_via_otp(resource)
    else
      strategy = Warden::Strategies[:database_authenticatable].new(warden.env, :user)
      prompt_for_two_factor(strategy.user) if strategy.valid? && strategy._run!.successful?
lislis's avatar
lislis a validé
    end
  end

  def valid_otp_attempt?(user)
    user.validate_and_consume_otp!(params[:user][:otp_attempt]) ||
      user.invalidate_otp_backup_code!(params[:user][:otp_attempt])
  rescue OpenSSL::Cipher::CipherError => _error
    false
  end

  def authenticate_with_two_factor_via_otp(user)
    if valid_otp_attempt?(user)
      session.delete(:otp_user_id)
      sign_in(user)
    else
      flash.now[:alert] = "Invalid token"
      prompt_for_two_factor(user)
    end
  end

  def prompt_for_two_factor(user)
    session[:otp_user_id] = user.id
    render :two_factor
  end
Lukas Matt's avatar
Lukas Matt a validé

  def reset_authentication_token
lislis's avatar
lislis a validé
    current_user&.reset_authentication_token!
Lukas Matt's avatar
Lukas Matt a validé
  end
Jonne Haß's avatar
Jonne Haß a validé
end