Repository navigation
Expand file tree
/
Copy pathTestUserTwoFactor.php
More file actions
154 lines (126 loc) · 3.82 KB
/
Copy pathTestUserTwoFactor.php
File metadata and controls
154 lines (126 loc) · 3.82 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
<?php
namespace SyncEngine\Tests\Fixture;
use Doctrine\ORM\EntityManagerInterface;
use Symfony\Component\PasswordHasher\Hasher\UserPasswordHasherInterface;
use SyncEngine\Entity\TwoFactor;
use SyncEngine\Entity\User;
class TestUserTwoFactor
{
/**
* Create a user with TOTP enabled and a known secret for testing.
*/
public static function getTotpEnabled( EntityManagerInterface $em, UserPasswordHasherInterface $passwordHasher ): User
{
$user = TestUser::getOrCreate( $em, $passwordHasher );
// Only set up TOTP if not already enabled.
if ( ! $user->isTwoFactorEnabled() || ! $user->isTotpAuthenticationEnabled() ) {
$secret = bin2hex( random_bytes( 20 ) );
$twoFactor = new TwoFactor();
$twoFactor->setUser( $user );
$twoFactor->setType( 'totp' );
$twoFactor->setSecret( $secret );
$twoFactor->setEnabled( true );
$user->addTwoFactorMethod( $twoFactor );
$user->setTwoFactorEnabled( true );
$em->persist( $twoFactor );
}
return $user;
}
/**
* Create a user with email 2FA enabled (no TOTP).
*/
public static function getEmailEnabled( EntityManagerInterface $em, UserPasswordHasherInterface $passwordHasher ): User
{
$user = TestUser::getOrCreate( $em, $passwordHasher );
// Only set up email 2FA if not already enabled.
if ( ! $user->isTwoFactorEnabled() ) {
$twoFactor = new TwoFactor();
$twoFactor->setUser( $user );
$twoFactor->setType( 'email' );
$twoFactor->setEnabled( true );
$user->addTwoFactorMethod( $twoFactor );
$user->setTwoFactorEnabled( true );
$em->persist( $twoFactor );
}
return $user;
}
/**
* Create a user with 2FA disabled (default state).
*/
public static function getDisabled( EntityManagerInterface $em, UserPasswordHasherInterface $passwordHasher ): User
{
$user = TestUser::getOrCreate( $em, $passwordHasher );
// Ensure 2FA is disabled and no methods exist.
if ( $user->isTwoFactorEnabled() ) {
foreach ( $user->getTwoFactorMethods() as $method ) {
$user->removeTwoFactorMethod( $method );
$em->remove( $method );
}
$user->setTwoFactorEnabled( false );
$em->flush();
}
return $user;
}
/**
* Get the TOTP secret for a user (if enabled).
*/
public static function getTotpSecret( User $user ): ?string
{
foreach ( $user->getTwoFactorMethods() as $method ) {
if ( $method->getType() === 'totp' && $method->isEnabled() ) {
return $method->getSecret();
}
}
return null;
}
/**
* Enable TOTP for a user with a specific secret.
*/
public static function enableTotpWithSecret( EntityManagerInterface $em, User $user, string $secret ): void
{
// Remove any existing TOTP methods.
foreach ( $user->getTwoFactorMethods() as $method ) {
if ( $method->getType() === 'totp' ) {
$user->removeTwoFactorMethod( $method );
$em->remove( $method );
}
}
// Add new TOTP method.
$twoFactor = new TwoFactor();
$twoFactor->setUser( $user );
$twoFactor->setType( 'totp' );
$twoFactor->setSecret( $secret );
$twoFactor->setEnabled( true );
$user->addTwoFactorMethod( $twoFactor );
$user->setTwoFactorEnabled( true );
$em->persist( $twoFactor );
$em->flush();
}
/**
* Disable TOTP for a user.
*/
public static function disableTotp( EntityManagerInterface $em, User $user ): void
{
foreach ( $user->getTwoFactorMethods() as $method ) {
if ( $method->getType() === 'totp' ) {
$user->removeTwoFactorMethod( $method );
$em->remove( $method );
}
}
// Check if any other 2FA methods remain.
if ( $user->getTwoFactorMethods()->isEmpty() ) {
$user->setTwoFactorEnabled( false );
}
$em->flush();
}
public static function generateTotpSecret(): string
{
$totp = \OTPHP\TOTP::create();
return $totp->getSecret();
}
public static function generateTotpCode( string $secret ): string
{
$totp = \OTPHP\TOTP::create( $secret );
return $totp->now();
}
}