mirror of
https://github.com/RobThree/TwoFactorAuth.git
synced 2026-08-24 19:46:35 +00:00
first batch
This commit is contained in:
+34
-135
@@ -7,7 +7,6 @@ use RobThree\Auth\Providers\Qr\QRServerProvider;
|
||||
use RobThree\Auth\Providers\Rng\CSRNGProvider;
|
||||
use RobThree\Auth\Providers\Rng\HashRNGProvider;
|
||||
use RobThree\Auth\Providers\Rng\IRNGProvider;
|
||||
use RobThree\Auth\Providers\Rng\MCryptRNGProvider;
|
||||
use RobThree\Auth\Providers\Rng\OpenSSLRNGProvider;
|
||||
use RobThree\Auth\Providers\Time\HttpTimeProvider;
|
||||
use RobThree\Auth\Providers\Time\ITimeProvider;
|
||||
@@ -18,69 +17,28 @@ use RobThree\Auth\Providers\Time\NTPTimeProvider;
|
||||
// Algorithms, digits, period etc. explained: https://github.com/google/google-authenticator/wiki/Key-Uri-Format
|
||||
class TwoFactorAuth
|
||||
{
|
||||
/** @var string */
|
||||
private $algorithm;
|
||||
private static string $_base32dict = 'ABCDEFGHIJKLMNOPQRSTUVWXYZ234567=';
|
||||
|
||||
/** @var int */
|
||||
private $period;
|
||||
private static array $_base32;
|
||||
|
||||
/** @var int */
|
||||
private $digits;
|
||||
private static array $_base32lookup = array();
|
||||
|
||||
/** @var string */
|
||||
private $issuer;
|
||||
|
||||
/** @var ?IQRCodeProvider */
|
||||
private $qrcodeprovider = null;
|
||||
|
||||
/** @var ?IRNGProvider */
|
||||
private $rngprovider = null;
|
||||
|
||||
/** @var ?ITimeProvider */
|
||||
private $timeprovider = null;
|
||||
|
||||
/** @var string */
|
||||
private static $_base32dict = 'ABCDEFGHIJKLMNOPQRSTUVWXYZ234567=';
|
||||
|
||||
/** @var array */
|
||||
private static $_base32;
|
||||
|
||||
/** @var array */
|
||||
private static $_base32lookup = array();
|
||||
|
||||
/** @var array */
|
||||
private static $_supportedalgos = array('sha1', 'sha256', 'sha512', 'md5');
|
||||
|
||||
/**
|
||||
* @param ?string $issuer
|
||||
* @param int $digits
|
||||
* @param int $period
|
||||
* @param string $algorithm
|
||||
* @param ?IQRCodeProvider $qrcodeprovider
|
||||
* @param ?IRNGProvider $rngprovider
|
||||
* @param ?ITimeProvider $timeprovider
|
||||
*/
|
||||
public function __construct($issuer = null, $digits = 6, $period = 30, $algorithm = 'sha1', IQRCodeProvider $qrcodeprovider = null, IRNGProvider $rngprovider = null, ITimeProvider $timeprovider = null)
|
||||
{
|
||||
$this->issuer = $issuer;
|
||||
if (!is_int($digits) || $digits <= 0) {
|
||||
throw new TwoFactorAuthException('Digits must be int > 0');
|
||||
public function __construct(
|
||||
private ?string $issuer = null,
|
||||
private int $digits = 6,
|
||||
private int $period = 30,
|
||||
private Algorithm $algorithm = Algorithm::Sha1,
|
||||
private ?IQRCodeProvider $qrcodeprovider = null,
|
||||
private ?IRNGProvider $rngprovider = null,
|
||||
private ?ITimeProvider $timeprovider = null
|
||||
) {
|
||||
if ($this->digits <= 0) {
|
||||
throw new TwoFactorAuthException('Digits must be > 0');
|
||||
}
|
||||
$this->digits = $digits;
|
||||
|
||||
if (!is_int($period) || $period <= 0) {
|
||||
if ($this->period <= 0) {
|
||||
throw new TwoFactorAuthException('Period must be int > 0');
|
||||
}
|
||||
$this->period = $period;
|
||||
|
||||
$algorithm = strtolower(trim($algorithm));
|
||||
if (!in_array($algorithm, self::$_supportedalgos)) {
|
||||
throw new TwoFactorAuthException('Unsupported algorithm: ' . $algorithm);
|
||||
}
|
||||
$this->algorithm = $algorithm;
|
||||
$this->qrcodeprovider = $qrcodeprovider;
|
||||
$this->rngprovider = $rngprovider;
|
||||
$this->timeprovider = $timeprovider;
|
||||
|
||||
self::$_base32 = str_split(self::$_base32dict);
|
||||
self::$_base32lookup = array_flip(self::$_base32);
|
||||
@@ -88,16 +46,11 @@ class TwoFactorAuth
|
||||
|
||||
/**
|
||||
* Create a new secret
|
||||
*
|
||||
* @param int $bits
|
||||
* @param bool $requirecryptosecure
|
||||
*
|
||||
* @return string
|
||||
*/
|
||||
public function createSecret($bits = 80, $requirecryptosecure = true)
|
||||
public function createSecret(int $bits = 80, bool $requirecryptosecure = true): string
|
||||
{
|
||||
$secret = '';
|
||||
$bytes = (int) ceil($bits / 5); //We use 5 bits of each byte (since we have a 32-character 'alphabet' / BASE32)
|
||||
$bytes = (int) ceil($bits / 5); // We use 5 bits of each byte (since we have a 32-character 'alphabet' / BASE32)
|
||||
$rngprovider = $this->getRngProvider();
|
||||
if ($requirecryptosecure && !$rngprovider->isCryptographicallySecure()) {
|
||||
throw new TwoFactorAuthException('RNG provider is not cryptographically secure');
|
||||
@@ -111,18 +64,13 @@ class TwoFactorAuth
|
||||
|
||||
/**
|
||||
* Calculate the code with given secret and point in time
|
||||
*
|
||||
* @param string $secret
|
||||
* @param ?int $time
|
||||
*
|
||||
* @return string
|
||||
*/
|
||||
public function getCode($secret, $time = null)
|
||||
public function getCode(string $secret, ?int $time = null): string
|
||||
{
|
||||
$secretkey = $this->base32Decode($secret);
|
||||
|
||||
$timestamp = "\0\0\0\0" . pack('N*', $this->getTimeSlice($this->getTime($time))); // Pack time into binary string
|
||||
$hashhmac = hash_hmac($this->algorithm, $timestamp, $secretkey, true); // Hash it with users secret key
|
||||
$hashhmac = hash_hmac($this->algorithm->value, $timestamp, $secretkey, true); // Hash it with users secret key
|
||||
$hashpart = substr($hashhmac, ord(substr($hashhmac, -1)) & 0x0F, 4); // Use last nibble of result as index/offset and grab 4 bytes of the result
|
||||
$value = unpack('N', $hashpart); // Unpack binary value
|
||||
$value = $value[1] & 0x7FFFFFFF; // Drop MSB, keep only 31 bits
|
||||
@@ -132,16 +80,8 @@ class TwoFactorAuth
|
||||
|
||||
/**
|
||||
* Check if the code is correct. This will accept codes starting from ($discrepancy * $period) sec ago to ($discrepancy * period) sec from now
|
||||
*
|
||||
* @param string $secret
|
||||
* @param string $code
|
||||
* @param int $discrepancy
|
||||
* @param ?int $time
|
||||
* @param int $timeslice
|
||||
*
|
||||
* @return bool
|
||||
*/
|
||||
public function verifyCode($secret, $code, $discrepancy = 1, $time = null, &$timeslice = 0)
|
||||
public function verifyCode(string $secret, string $code, int $discrepancy = 1, ?int $time = null, ?int &$timeslice = 0): bool
|
||||
{
|
||||
$timestamp = $this->getTime($time);
|
||||
|
||||
@@ -162,13 +102,8 @@ class TwoFactorAuth
|
||||
|
||||
/**
|
||||
* Timing-attack safe comparison of 2 codes (see http://blog.ircmaxell.com/2014/11/its-all-about-time.html)
|
||||
*
|
||||
* @param string $safe
|
||||
* @param string $user
|
||||
*
|
||||
* @return bool
|
||||
*/
|
||||
private function codeEquals($safe, $user)
|
||||
private function codeEquals(string $safe, string $user): bool
|
||||
{
|
||||
if (function_exists('hash_equals')) {
|
||||
return hash_equals($safe, $user);
|
||||
@@ -187,17 +122,11 @@ class TwoFactorAuth
|
||||
|
||||
/**
|
||||
* Get data-uri of QRCode
|
||||
*
|
||||
* @param string $label
|
||||
* @param string $secret
|
||||
* @param mixed $size
|
||||
*
|
||||
* @return string
|
||||
*/
|
||||
public function getQRCodeImageAsDataUri($label, $secret, $size = 200)
|
||||
public function getQRCodeImageAsDataUri(string $label, string $secret, int $size = 200): string
|
||||
{
|
||||
if (!is_int($size) || $size <= 0) {
|
||||
throw new TwoFactorAuthException('Size must be int > 0');
|
||||
if ($size <= 0) {
|
||||
throw new TwoFactorAuthException('Size must be > 0');
|
||||
}
|
||||
|
||||
$qrcodeprovider = $this->getQrCodeProvider();
|
||||
@@ -209,12 +138,8 @@ class TwoFactorAuth
|
||||
|
||||
/**
|
||||
* Compare default timeprovider with specified timeproviders and ensure the time is within the specified number of seconds (leniency)
|
||||
* @param ?array $timeproviders
|
||||
* @param int $leniency
|
||||
*
|
||||
* @return void
|
||||
*/
|
||||
public function ensureCorrectTime(array $timeproviders = null, $leniency = 5)
|
||||
public function ensureCorrectTime(?array $timeproviders = null, int $leniency = 5): void
|
||||
{
|
||||
if ($timeproviders === null) {
|
||||
$timeproviders = array(
|
||||
@@ -239,50 +164,30 @@ class TwoFactorAuth
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* @param ?int $time
|
||||
*
|
||||
* @return int
|
||||
*/
|
||||
private function getTime($time = null)
|
||||
private function getTime(?int $time = null): int
|
||||
{
|
||||
return ($time === null) ? $this->getTimeProvider()->getTime() : $time;
|
||||
}
|
||||
|
||||
/**
|
||||
* @param int $time
|
||||
* @param int $offset
|
||||
*
|
||||
* @return int
|
||||
*/
|
||||
private function getTimeSlice($time = null, $offset = 0)
|
||||
private function getTimeSlice(?int $time = null, int $offset = 0): int
|
||||
{
|
||||
return (int)floor($time / $this->period) + ($offset * $this->period);
|
||||
return (int) floor($time / $this->period) + ($offset * $this->period);
|
||||
}
|
||||
|
||||
/**
|
||||
* Builds a string to be encoded in a QR code
|
||||
*
|
||||
* @param string $label
|
||||
* @param string $secret
|
||||
*
|
||||
* @return string
|
||||
*/
|
||||
public function getQRText($label, $secret)
|
||||
public function getQRText(string $label, string $secret): string
|
||||
{
|
||||
return 'otpauth://totp/' . rawurlencode($label)
|
||||
. '?secret=' . rawurlencode($secret)
|
||||
. '&issuer=' . rawurlencode((string)$this->issuer)
|
||||
. '&period=' . intval($this->period)
|
||||
. '&algorithm=' . rawurlencode(strtoupper($this->algorithm))
|
||||
. '&algorithm=' . rawurlencode(strtoupper($this->algorithm->value))
|
||||
. '&digits=' . intval($this->digits);
|
||||
}
|
||||
|
||||
/**
|
||||
* @param string $value
|
||||
* @return string
|
||||
*/
|
||||
private function base32Decode($value)
|
||||
private function base32Decode(string $value): string
|
||||
{
|
||||
if (strlen($value) == 0) {
|
||||
return '';
|
||||
@@ -309,10 +214,9 @@ class TwoFactorAuth
|
||||
}
|
||||
|
||||
/**
|
||||
* @return IQRCodeProvider
|
||||
* @throws TwoFactorAuthException
|
||||
*/
|
||||
public function getQrCodeProvider()
|
||||
public function getQrCodeProvider(): IQRCodeProvider
|
||||
{
|
||||
// Set default QR Code provider if none was specified
|
||||
if (null === $this->qrcodeprovider) {
|
||||
@@ -322,10 +226,9 @@ class TwoFactorAuth
|
||||
}
|
||||
|
||||
/**
|
||||
* @return IRNGProvider
|
||||
* @throws TwoFactorAuthException
|
||||
*/
|
||||
public function getRngProvider()
|
||||
public function getRngProvider(): IRNGProvider
|
||||
{
|
||||
if (null !== $this->rngprovider) {
|
||||
return $this->rngprovider;
|
||||
@@ -333,9 +236,6 @@ class TwoFactorAuth
|
||||
if (function_exists('random_bytes')) {
|
||||
return $this->rngprovider = new CSRNGProvider();
|
||||
}
|
||||
if (function_exists('mcrypt_create_iv')) {
|
||||
return $this->rngprovider = new MCryptRNGProvider();
|
||||
}
|
||||
if (function_exists('openssl_random_pseudo_bytes')) {
|
||||
return $this->rngprovider = new OpenSSLRNGProvider();
|
||||
}
|
||||
@@ -346,10 +246,9 @@ class TwoFactorAuth
|
||||
}
|
||||
|
||||
/**
|
||||
* @return ITimeProvider
|
||||
* @throws TwoFactorAuthException
|
||||
*/
|
||||
public function getTimeProvider()
|
||||
public function getTimeProvider(): ITimeProvider
|
||||
{
|
||||
// Set default time provider if none was specified
|
||||
if (null === $this->timeprovider) {
|
||||
|
||||
Reference in New Issue
Block a user