* Add native property types Includes TypeHints.UnionTypeHintFormat Signed-off-by: Kamil Tekiela <tekiela246@gmail.com> * Set some default values for properties Signed-off-by: Kamil Tekiela <tekiela246@gmail.com> * Format and promote properties Signed-off-by: Kamil Tekiela <tekiela246@gmail.com> * Remove redundant asserts Signed-off-by: Kamil Tekiela <tekiela246@gmail.com> * Redundant cast Signed-off-by: Kamil Tekiela <tekiela246@gmail.com> * $tmanager->theme is never null Signed-off-by: Kamil Tekiela <tekiela246@gmail.com> * Redundant variable Signed-off-by: Kamil Tekiela <tekiela246@gmail.com> * Fix empty on $statementInfo bool Signed-off-by: Kamil Tekiela <tekiela246@gmail.com> * Redundant casts Signed-off-by: Kamil Tekiela <tekiela246@gmail.com> * Redundant issets Signed-off-by: Kamil Tekiela <tekiela246@gmail.com> * getPacked() returns nullable string Signed-off-by: Kamil Tekiela <tekiela246@gmail.com> * Redundant if Signed-off-by: Kamil Tekiela <tekiela246@gmail.com> * $this->content can be null Signed-off-by: Kamil Tekiela <tekiela246@gmail.com> * Simplify ThemeManager::getInstance() Signed-off-by: Kamil Tekiela <tekiela246@gmail.com> * Use isset for checking if property is initialized Signed-off-by: Kamil Tekiela <tekiela246@gmail.com> * Use nullable instead of uninitialized property Signed-off-by: Kamil Tekiela <tekiela246@gmail.com> * password is no longer nullable I can't verify that none of the globals ever tried to set it to null, but the variable should never be nullable. Signed-off-by: Kamil Tekiela <tekiela246@gmail.com> * Update baselines Signed-off-by: Kamil Tekiela <tekiela246@gmail.com> * $same_wide_width param can be float or int Signed-off-by: Kamil Tekiela <tekiela246@gmail.com> * Update Message.php Signed-off-by: Kamil Tekiela <tekiela246@gmail.com> * Cast Sub_part to int Signed-off-by: Kamil Tekiela <tekiela246@gmail.com> * Fix one line doc comments Signed-off-by: Kamil Tekiela <tekiela246@gmail.com> --------- Signed-off-by: Kamil Tekiela <tekiela246@gmail.com>
212 lines
5.7 KiB
PHP
212 lines
5.7 KiB
PHP
<?php
|
|
/**
|
|
* Second authentication factor handling
|
|
*/
|
|
|
|
declare(strict_types=1);
|
|
|
|
namespace PhpMyAdmin\Plugins\TwoFactor;
|
|
|
|
use CodeLts\U2F\U2FServer\U2FException;
|
|
use CodeLts\U2F\U2FServer\U2FServer;
|
|
use PhpMyAdmin\Plugins\TwoFactorPlugin;
|
|
use PhpMyAdmin\ResponseRenderer;
|
|
use PhpMyAdmin\TwoFactor;
|
|
use stdClass;
|
|
use Throwable;
|
|
use Twig\Error\LoaderError;
|
|
use Twig\Error\RuntimeError;
|
|
use Twig\Error\SyntaxError;
|
|
|
|
use function __;
|
|
use function is_array;
|
|
use function is_object;
|
|
use function json_decode;
|
|
use function json_encode;
|
|
|
|
/**
|
|
* Hardware key based two-factor authentication
|
|
*
|
|
* Supports FIDO U2F tokens
|
|
*/
|
|
class Key extends TwoFactorPlugin
|
|
{
|
|
public static string $id = 'key';
|
|
|
|
public function __construct(TwoFactor $twofactor)
|
|
{
|
|
parent::__construct($twofactor);
|
|
|
|
if (
|
|
isset($this->twofactor->config['settings']['registrations'])
|
|
&& is_array($this->twofactor->config['settings']['registrations'])
|
|
) {
|
|
return;
|
|
}
|
|
|
|
$this->twofactor->config['settings']['registrations'] = [];
|
|
}
|
|
|
|
/**
|
|
* Returns array of U2F registration objects
|
|
*
|
|
* @return stdClass[]
|
|
*/
|
|
public function getRegistrations(): array
|
|
{
|
|
$result = [];
|
|
foreach ($this->twofactor->config['settings']['registrations'] as $index => $data) {
|
|
$reg = new stdClass();
|
|
$reg->keyHandle = $data['keyHandle'];
|
|
$reg->publicKey = $data['publicKey'];
|
|
$reg->certificate = $data['certificate'];
|
|
$reg->counter = $data['counter'];
|
|
$reg->index = $index;
|
|
$result[] = $reg;
|
|
}
|
|
|
|
return $result;
|
|
}
|
|
|
|
/**
|
|
* Checks authentication, returns true on success
|
|
*/
|
|
public function check(): bool
|
|
{
|
|
$this->provided = false;
|
|
if (! isset($_POST['u2f_authentication_response'], $_SESSION['authenticationRequest'])) {
|
|
return false;
|
|
}
|
|
|
|
$this->provided = true;
|
|
try {
|
|
$response = json_decode($_POST['u2f_authentication_response']);
|
|
if (! is_object($response)) {
|
|
return false;
|
|
}
|
|
|
|
$auth = U2FServer::authenticate(
|
|
$_SESSION['authenticationRequest'],
|
|
$this->getRegistrations(),
|
|
$response,
|
|
);
|
|
$this->twofactor->config['settings']['registrations'][$auth->index]['counter'] = $auth->counter;
|
|
$this->twofactor->save();
|
|
|
|
return true;
|
|
} catch (U2FException $e) {
|
|
$this->message = $e->getMessage();
|
|
|
|
return false;
|
|
}
|
|
}
|
|
|
|
/**
|
|
* Loads needed javascripts into the page
|
|
*/
|
|
public function loadScripts(): void
|
|
{
|
|
$response = ResponseRenderer::getInstance();
|
|
$scripts = $response->getHeader()->getScripts();
|
|
$scripts->addFile('vendor/u2f-api-polyfill.js');
|
|
$scripts->addFile('u2f.js');
|
|
}
|
|
|
|
/**
|
|
* Renders user interface to enter two-factor authentication
|
|
*
|
|
* @return string HTML code
|
|
*/
|
|
public function render(): string
|
|
{
|
|
$request = U2FServer::makeAuthentication(
|
|
$this->getRegistrations(),
|
|
$this->getAppId(true),
|
|
);
|
|
$_SESSION['authenticationRequest'] = $request;
|
|
$this->loadScripts();
|
|
|
|
return $this->template->render('login/twofactor/key', [
|
|
'request' => json_encode($request),
|
|
'is_https' => $GLOBALS['config']->isHttps(),
|
|
]);
|
|
}
|
|
|
|
/**
|
|
* Renders user interface to configure two-factor authentication
|
|
*
|
|
* @return string HTML code
|
|
*
|
|
* @throws U2FException
|
|
* @throws Throwable
|
|
* @throws LoaderError
|
|
* @throws RuntimeError
|
|
* @throws SyntaxError
|
|
*/
|
|
public function setup(): string
|
|
{
|
|
$registrationData = U2FServer::makeRegistration(
|
|
$this->getAppId(true),
|
|
$this->getRegistrations(),
|
|
);
|
|
$_SESSION['registrationRequest'] = $registrationData['request'];
|
|
|
|
$this->loadScripts();
|
|
|
|
return $this->template->render('login/twofactor/key_configure', [
|
|
'request' => json_encode($registrationData['request']),
|
|
'signatures' => json_encode($registrationData['signatures']),
|
|
'is_https' => $GLOBALS['config']->isHttps(),
|
|
]);
|
|
}
|
|
|
|
/**
|
|
* Performs backend configuration
|
|
*/
|
|
public function configure(): bool
|
|
{
|
|
$this->provided = false;
|
|
if (! isset($_POST['u2f_registration_response'], $_SESSION['registrationRequest'])) {
|
|
return false;
|
|
}
|
|
|
|
$this->provided = true;
|
|
try {
|
|
$response = json_decode($_POST['u2f_registration_response']);
|
|
if (! is_object($response)) {
|
|
return false;
|
|
}
|
|
|
|
$registration = U2FServer::register($_SESSION['registrationRequest'], $response);
|
|
$this->twofactor->config['settings']['registrations'][] = [
|
|
'keyHandle' => $registration->getKeyHandle(),
|
|
'publicKey' => $registration->getPublicKey(),
|
|
'certificate' => $registration->getCertificate(),
|
|
'counter' => $registration->getCounter(),
|
|
];
|
|
|
|
return true;
|
|
} catch (U2FException $e) {
|
|
$this->message = $e->getMessage();
|
|
|
|
return false;
|
|
}
|
|
}
|
|
|
|
/**
|
|
* Get user visible name
|
|
*/
|
|
public static function getName(): string
|
|
{
|
|
return __('Hardware Security Key (FIDO U2F)');
|
|
}
|
|
|
|
/**
|
|
* Get user visible description
|
|
*/
|
|
public static function getDescription(): string
|
|
{
|
|
return __('Provides authentication using hardware security tokens supporting FIDO U2F, such as a YubiKey.');
|
|
}
|
|
}
|