🐛 fix(2FA): Two Factor Authentication - Filter - Blocks even when two factor authentication is enabled
🐛 fix(email): add error logging when email sending fails 🔒 chore(2FA): fix TwoFactorEmailValidator to pass user as an array The TwoFactorAuthenticationEnforceFilter was blocking users even when two factor authentication was enabled. The filter now checks if the user has two factor authentication enabled before blocking them. The MailService now logs an error when email sending fails. The TwoFactorEmailValidator now passes the user as an array to the TwoFactorEmailCodeGeneratorService.
This commit is contained in:
@ -38,8 +38,10 @@ class TwoFactorAuthenticationEnforceFilter extends ActionFilter
|
||||
}
|
||||
|
||||
$permissions = $module->twoFactorAuthenticationForcedPermissions;
|
||||
|
||||
$user = Yii::$app->user->identity;
|
||||
$itemsByUser = array_keys($this->getAuthManager()->getItemsByUser(Yii::$app->user->identity->id));
|
||||
if (!empty(array_intersect($permissions, $itemsByUser))) {
|
||||
if (!empty(array_intersect($permissions, $itemsByUser)) && !$user->auth_tf_enabled) {
|
||||
Yii::$app->session->setFlash('warning', Yii::t('usuario', 'Your role requires 2FA, you won\'t be able to use the application until you enable it'));
|
||||
return Yii::$app->response->redirect(['/user/settings/account'])->send();
|
||||
}
|
||||
|
||||
@ -83,11 +83,17 @@ class MailService implements ServiceInterface
|
||||
*/
|
||||
public function run()
|
||||
{
|
||||
return $this->mailer
|
||||
|
||||
$result = $this->mailer
|
||||
->compose(['html' => $this->view, 'text' => "text/{$this->view}"], $this->params)
|
||||
->setFrom($this->from)
|
||||
->setTo($this->to)
|
||||
->setSubject($this->subject)
|
||||
->send();
|
||||
|
||||
if (!$result) {
|
||||
Yii::error("Email sending failed to '{$this->to}'.", 'mailer');
|
||||
}
|
||||
return $result;
|
||||
}
|
||||
}
|
||||
|
||||
@ -111,6 +111,6 @@ class TwoFactorEmailValidator extends TwoFactorCodeValidator
|
||||
*/
|
||||
public function generateCode()
|
||||
{
|
||||
return $this->make(TwoFactorEmailCodeGeneratorService::class, $this->user)->run();
|
||||
return $this->make(TwoFactorEmailCodeGeneratorService::class, [$this->user])->run();
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user