| 123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158 | <?php/** * MageSpecialist * * NOTICE OF LICENSE * * This source file is subject to the Open Software License (OSL 3.0) * that is bundled with this package in the file LICENSE.txt. * It is also available through the world-wide-web at this URL: * http://opensource.org/licenses/osl-3.0.php * If you did not receive a copy of the license and are unable to * obtain it through the world-wide-web, please send an email * to info@magespecialist.it so we can send you a copy immediately. * * @category   MSP * @package    MSP_TwoFactorAuth * @copyright  Copyright (c) 2017 Skeeller srl (http://www.magespecialist.it) * @license    http://opensource.org/licenses/osl-3.0.php  Open Software License (OSL 3.0) */namespace MSP\TwoFactorAuth\Controller\Adminhtml\Duo;use Magento\Backend\Model\Auth\Session;use Magento\Backend\App\Action;use Magento\Framework\DataObjectFactory;use Magento\Framework\View\Result\PageFactory;use MSP\TwoFactorAuth\Model\AlertInterface;use MSP\TwoFactorAuth\Api\TfaInterface;use MSP\TwoFactorAuth\Api\TfaSessionInterface;use MSP\TwoFactorAuth\Controller\Adminhtml\AbstractAction;use MSP\TwoFactorAuth\Model\Provider\Engine\DuoSecurity;/** * @SuppressWarnings(PHPMD.CamelCaseMethodName) */class Authpost extends AbstractAction{    /**     * @var TfaInterface     */    private $tfa;    /**     * @var Session     */    private $session;    /**     * @var PageFactory     */    private $pageFactory;    /**     * @var TfaSessionInterface     */    private $tfaSession;    /**     * @var DuoSecurity     */    private $duoSecurity;    /**     * @var DataObjectFactory     */    private $dataObjectFactory;    /**     * @var AlertInterface     */    private $alert;    /**     * @var Action\Context     */    private $context;    /**     * Authpost constructor.     * @param Action\Context $context     * @param Session $session     * @param PageFactory $pageFactory     * @param DuoSecurity $duoSecurity     * @param TfaSessionInterface $tfaSession     * @param DataObjectFactory $dataObjectFactory     * @param AlertInterface $alert     * @param TfaInterface $tfa     */    public function __construct(        Action\Context $context,        Session $session,        PageFactory $pageFactory,        DuoSecurity $duoSecurity,        TfaSessionInterface $tfaSession,        DataObjectFactory $dataObjectFactory,        AlertInterface $alert,        TfaInterface $tfa    ) {        parent::__construct($context);        $this->tfa = $tfa;        $this->session = $session;        $this->pageFactory = $pageFactory;        $this->tfaSession = $tfaSession;        $this->duoSecurity = $duoSecurity;        $this->dataObjectFactory = $dataObjectFactory;        $this->alert = $alert;        $this->context = $context;    }    /**     * Get current user     * @return \Magento\User\Model\User|null     */    private function getUser()    {        return $this->session->getUser();    }    /**     * @inheritdoc     */    public function execute()    {        $user = $this->getUser();        if ($this->duoSecurity->verify($user, $this->dataObjectFactory->create([            'data' => $this->getRequest()->getParams(),        ]))) {            $this->tfa->getProvider(DuoSecurity::CODE)->activate($user->getId());            $this->tfaSession->grantAccess();            return $this->_redirect($this->context->getBackendUrl()->getStartupPageUrl());        } else {            $this->alert->event(                'MSP_TwoFactorAuth',                'DuoSecurity invalid auth',                AlertInterface::LEVEL_WARNING,                $user->getUserName()            );            return $this->_redirect('*/*/auth');        }    }    /**     * Check if admin has permissions to visit related pages     *     * @return bool     */    protected function _isAllowed()    {        // Do not check for activation        $user = $this->getUser();        return            $user &&            $this->tfa->getProviderIsAllowed($user->getId(), DuoSecurity::CODE);    }}
 |