golden hour
/home/doctorbruno/public_html/taeionline.com/support/include
⬆️ Go Up
Upload
File/Folder
Size
Actions
.MANIFEST
194.97 KB
Del
OK
.htaccess
14 B
Del
OK
JSON.php
33.13 KB
Del
OK
PasswordHash.php
6.92 KB
Del
OK
Spyc.php
31.74 KB
Del
OK
UniversalClassLoader.php
8.61 KB
Del
OK
ajax.admin.php
7.29 KB
Del
OK
ajax.config.php
4.61 KB
Del
OK
ajax.content.php
9.76 KB
Del
OK
ajax.draft.php
13.03 KB
Del
OK
ajax.email.php
2.33 KB
Del
OK
ajax.export.php
1006 B
Del
OK
ajax.filter.php
874 B
Del
OK
ajax.forms.php
13.84 KB
Del
OK
ajax.i18n.php
5.1 KB
Del
OK
ajax.kbase.php
2.93 KB
Del
OK
ajax.note.php
2.05 KB
Del
OK
ajax.orgs.php
11.73 KB
Del
OK
ajax.plugins.php
2.15 KB
Del
OK
ajax.schedule.php
4.29 KB
Del
OK
ajax.search.php
12.72 KB
Del
OK
ajax.sequence.php
3.2 KB
Del
OK
ajax.staff.php
11.62 KB
Del
OK
ajax.tasks.php
33.87 KB
Del
OK
ajax.thread.php
8.81 KB
Del
OK
ajax.tickets.php
79.7 KB
Del
OK
ajax.tips.php
1.66 KB
Del
OK
ajax.upgrader.php
2.24 KB
Del
OK
ajax.users.php
18.33 KB
Del
OK
api.cron.php
1.06 KB
Del
OK
api.tickets.php
10.36 KB
Del
OK
class.2fa.php
7.76 KB
Del
OK
class.ajax.php
1.45 KB
Del
OK
class.api.php
15.31 KB
Del
OK
class.app.php
1.49 KB
Del
OK
class.attachment.php
6.95 KB
Del
OK
class.auth.php
50.73 KB
Del
OK
class.avatar.php
6.44 KB
Del
OK
class.banlist.php
2.58 KB
Del
OK
class.base32.php
4.07 KB
Del
OK
class.businesshours.php
7.08 KB
Del
OK
class.canned.php
9.05 KB
Del
OK
class.captcha.php
1.73 KB
Del
OK
class.category.php
11.14 KB
Del
OK
class.charset.php
3.41 KB
Del
OK
class.cli.php
9.48 KB
Del
OK
class.client.php
15.39 KB
Del
OK
class.collaborator.php
5.65 KB
Del
OK
class.company.php
2.65 KB
Del
OK
class.config.php
60.36 KB
Del
OK
class.controller.php
1.15 KB
Del
OK
class.cron.php
3.6 KB
Del
OK
class.crypto.php
18.92 KB
Del
OK
class.csrf.php
2.38 KB
Del
OK
class.dept.php
33.21 KB
Del
OK
class.dispatcher.php
7.12 KB
Del
OK
class.draft.php
6.23 KB
Del
OK
class.dynamic_forms.php
64.98 KB
Del
OK
class.email.php
49 KB
Del
OK
class.error.php
1.69 KB
Del
OK
class.export.php
32.92 KB
Del
OK
class.faq.php
15.05 KB
Del
OK
class.file.php
34.59 KB
Del
OK
class.filter.php
31.9 KB
Del
OK
class.filter_action.php
23.67 KB
Del
OK
class.format.php
44.3 KB
Del
OK
class.forms.php
195.58 KB
Del
OK
class.http.php
7.16 KB
Del
OK
class.i18n.php
24.28 KB
Del
OK
class.import.php
6.9 KB
Del
OK
class.json.php
2.71 KB
Del
OK
class.knowledgebase.php
5.8 KB
Del
OK
class.list.php
42 KB
Del
OK
class.lock.php
4.05 KB
Del
OK
class.log.php
1.55 KB
Del
OK
class.mail.php
35.76 KB
Del
OK
class.mailer.php
25.75 KB
Del
OK
class.mailfetch.php
9.72 KB
Del
OK
class.mailparse.php
30.99 KB
Del
OK
class.message.php
6.42 KB
Del
OK
class.migrater.php
5.2 KB
Del
OK
class.misc.php
7.5 KB
Del
OK
class.model.php
2.3 KB
Del
OK
class.nav.php
14.15 KB
Del
OK
class.note.php
2.39 KB
Del
OK
class.oauth2.php
4.04 KB
Del
OK
class.organization.php
22.45 KB
Del
OK
class.orm.php
120.9 KB
Del
OK
class.osticket.php
20.64 KB
Del
OK
class.ostsession.php
21.86 KB
Del
OK
class.page.php
10.59 KB
Del
OK
class.pagenate.php
5.53 KB
Del
OK
class.passwd.php
1.21 KB
Del
OK
class.pdf.php
3.83 KB
Del
OK
class.plugin.php
36.13 KB
Del
OK
class.priority.php
1.81 KB
Del
OK
class.queue.php
103.51 KB
Del
OK
class.report.php
11.76 KB
Del
OK
class.role.php
11.27 KB
Del
OK
class.schedule.php
46.28 KB
Del
OK
class.search.php
61.66 KB
Del
OK
class.sequence.php
7.27 KB
Del
OK
class.session.php
19.25 KB
Del
OK
class.setup.php
3.55 KB
Del
OK
class.signal.php
4.16 KB
Del
OK
class.sla.php
9.11 KB
Del
OK
class.staff.php
60.21 KB
Del
OK
class.task.php
56.21 KB
Del
OK
class.team.php
12.31 KB
Del
OK
class.template.php
23.45 KB
Del
OK
class.thread.php
108.96 KB
Del
OK
class.thread_actions.php
17.08 KB
Del
OK
class.ticket.php
167.39 KB
Del
OK
class.timezone.php
21.94 KB
Del
OK
class.topic.php
20.06 KB
Del
OK
class.translation.php
34.79 KB
Del
OK
class.upgrader.php
13.76 KB
Del
OK
class.user.php
43.4 KB
Del
OK
class.usersession.php
7.55 KB
Del
OK
class.util.php
10.07 KB
Del
OK
class.validator.php
12.94 KB
Del
OK
class.variable.php
11.93 KB
Del
OK
class.xml.php
3.23 KB
Del
OK
class.yaml.php
1.15 KB
Del
OK
cli
-
Del
OK
client
-
Del
OK
config
-
Del
OK
fpdf
-
Del
OK
htmLawed.php
53.53 KB
Del
OK
html2text.php
33.71 KB
Del
OK
i18n
-
Del
OK
index.php
37 B
Del
OK
laminas-mail
-
Del
OK
mpdf
-
Del
OK
mysqli.php
9.55 KB
Del
OK
ost-config.php
5.63 KB
Del
OK
ost-sampleconfig.php
6.24 KB
Del
OK
pear
-
Del
OK
plugins
-
Del
OK
staff
-
Del
OK
tnef_decoder.php
19.82 KB
Del
OK
upgrader
-
Del
OK
Edit: class.2fa.php
<?php /** * TwoFactorAuthentication backend * * Provides the basis of abstracting 2fa backends * The authentication backend should define a validate() method which * receives a user and OPT. */ abstract class TwoFactorAuthenticationBackend extends ServiceRegistry { // Global registry static protected $registry = array(); // Grace period in minutes before OTP is expired and user logged out // It's hardcoded to 6 minutes here but downstream backends can make it // configurable protected $timeout = 6; // Maximum number of validation attempts before the user is logged out // It's hardcoded to 3 attempts here but downstream backends can make it // configurable protected $maxstrikes = 3; // Base properties static $id; static $name; static $desc; // Forms private $_setupform; private $_inputform; // Send OTP to user specified and stash it abstract function send($user); // validate OTP provided by user abstract function validate($form, $user); function getDescription() { return __(static::$desc); } function getTimeout() { return $this->timeout; } function getMaxStrikes() { return $this->maxstrikes; } protected function getSetupOptions() { return array(); } protected function getInputOptions() { return array(); } // stash OTP info in the session protected function store($otp) { $store = &$_SESSION['_2fa'][$this->getId()]; $store = ['otp' => $otp, 'time' => time(), 'strikes' => 0]; return $store; } // Validate OPT // On strict mode check strikes and timeout protected function _validate($otp, $strict=true) { $store = &$_SESSION['_2fa'][$this->getId()]; // Track and check the attempts $store['strikes'] += 1; if ($strict && $store['strikes'] > $this->getMaxStrikes()) throw new ExpiredOTP(__('Too many attempts')); // Check timeout - if expired throw an exception. if ($strict && ($timeout=$this->getTimeout()) && ($store['time']+($timeout*60)) < time()) throw new ExpiredOTP(__('Expired OTP')); // Check the OTP return (!strcmp($store['otp'], $otp)); } // Called on a successfull validation for house keeping e.g clear 2fa // flags protected function onValidate($user) { $user->clear2FA(); } // Get a form the user uses to setup 2fa function getSetupForm($data=null) { if (!$this->_setupForm) { $this->_setupForm = new SimpleForm($this->getSetupOptions(), $data); } return $this->_setupForm; } // Get a form the user uses to input OTP function getInputForm($data=null) { if (!$this->_inputForm) { $this->_inputForm = new SimpleForm($this->getInputOptions(), $data); } return $this->_inputForm; } static function register($class) { if (is_string($class) && class_exists($class)) $class = new $class(); if (!is_object($class) || !($class instanceof TwoFactorAuthenticationBackend)) return false; static::$registry[$class->getBkId()] = $class; } static function allRegistered() { return array_merge(self::$registry, parent::getRegistry()); } static function getBackend($id) { if ($id && ($backends = static::allRegistered()) && isset($backends[$id])) return $backends[$id]; } static function lookup($id) { return static::getBackend($id); } } class ExpiredOTP extends Exception {} /* * user type container classes to aid in registry segmentation * */ abstract class Staff2FABackend extends TwoFactorAuthenticationBackend { static protected $registry = array(); static function allRegistered() { return array_merge(self::$registry, parent::allRegistered()); } abstract function send($user); abstract function validate($form, $user); } abstract class User2FABackend extends TwoFactorAuthenticationBackend { static protected $registry = array(); static function allRegistered() { return array_merge(self::$registry, parent::allRegistered()); } abstract function send($user); abstract function validate($form, $user); } /* * Email2FABackend * * Email based two factor authentication. * * This is the default 2FA that works out of the box once users configure * it. * */ class Email2FABackend extends TwoFactorAuthenticationBackend { static $id = "2fa-email"; static $name = /* @trans */ 'Email'; static $desc = /* @trans */ 'Verification codes are sent by email'; protected function getSetupOptions() { return array( 'email' => new TextboxField(array( 'id'=>2, 'label'=>__('Email Address'), 'required'=>true, 'default'=>'', 'validator'=>'email', 'hint'=>__('Valid email address'), 'configuration'=>array('size'=>40, 'length'=>40), )), ); } protected function getInputOptions() { return array( 'token' => new TextboxField(array( 'id'=>1, 'label'=>__('Verification Code'), 'required'=>true, 'default'=>'', 'validator'=>'number', 'hint'=>__('Please enter the code you were sent'), 'configuration'=>array( 'size'=>40, 'length'=>40, 'autocomplete' => 'one-time-code', 'inputmode' => 'numeric', 'pattern' => '[0-9]*', 'validator-error' => __('Invalid Code format'), ), )), ); } function validate($form, $user) { // Make sure form is valid and token exists if (!($form->isValid() && ($clean=$form->getClean()) && $clean['token'])) return false; // upstream validation might throw an exception due to expired token // or too many attempts (timeout). It's the responsibility of the // caller to catch and handle such exceptions. if (!$this->_validate($clean['token'])) return false; // Validator doesn't do house cleaning - it's our responsibility $this->onValidate($user); return true; } function send($user) { global $ost, $cfg; // Get backend configuration for this user if (!$cfg || !($info = $user->get2FAConfig($this->getId()))) return false; // Email to send the OTP via if (!($email = $cfg->getAlertEmail() ?: $cfg->getDefaultEmail())) return false; // Generate OTP $otp = Misc::randNumber(6); // Stash it in the session $this->store($otp); $template = 'email2fa-staff'; $content = Page::lookupByType($template); if (!$content) return new BaseError(/* @trans */ 'Unable to retrieve two factor authentication email template'); $vars = array( 'url' => $ost->getConfig()->getBaseUrl(), 'otp' => $otp, 'staff' => $user, 'recipient' => $user, ); $lang = $user->lang ?: $user->getExtraAttr('browser_lang'); $msg = $ost->replaceTemplateVariables(array( 'subj' => $content->getLocalName($lang), 'body' => $content->getLocalBody($lang), ), $vars); $email->send($user->getEmail(), Format::striptags($msg['subj']), $msg['body']); // MD5 here is not meant to be secure here - just done to avoid plain leaks return md5($otp); } } // Register email2fa for both agents and users (parent class) TwoFactorAuthenticationBackend::register('Email2FABackend'); ?>
Save