| 
									
										
										
										
											2017-12-23 20:46:52 +01:00
										 |  |  | <?php | 
					
						
							| 
									
										
										
										
											2019-10-02 06:38:00 +02:00
										 |  |  | /** | 
					
						
							|  |  |  |  * google2fa.php | 
					
						
							| 
									
										
										
										
											2020-03-17 16:06:30 +00:00
										 |  |  |  * Copyright (c) 2019 james@firefly-iii.org. | 
					
						
							| 
									
										
										
										
											2019-10-02 06:38:00 +02:00
										 |  |  |  * | 
					
						
							|  |  |  |  * This file is part of Firefly III (https://github.com/firefly-iii). | 
					
						
							|  |  |  |  * | 
					
						
							|  |  |  |  * This program is free software: you can redistribute it and/or modify | 
					
						
							|  |  |  |  * it under the terms of the GNU Affero General Public License as | 
					
						
							|  |  |  |  * published by the Free Software Foundation, either version 3 of the | 
					
						
							|  |  |  |  * License, or (at your option) any later version. | 
					
						
							|  |  |  |  * | 
					
						
							|  |  |  |  * This program is distributed in the hope that it will be useful, | 
					
						
							|  |  |  |  * but WITHOUT ANY WARRANTY; without even the implied warranty of | 
					
						
							|  |  |  |  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the | 
					
						
							|  |  |  |  * GNU Affero General Public License for more details. | 
					
						
							|  |  |  |  * | 
					
						
							|  |  |  |  * You should have received a copy of the GNU Affero General Public License | 
					
						
							|  |  |  |  * along with this program.  If not, see <https://www.gnu.org/licenses/>. | 
					
						
							|  |  |  |  */ | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2019-08-17 12:09:03 +02:00
										 |  |  | declare(strict_types=1); | 
					
						
							| 
									
										
										
										
											2017-12-23 20:46:52 +01:00
										 |  |  | 
 | 
					
						
							|  |  |  | return [ | 
					
						
							|  |  |  |     /* | 
					
						
							|  |  |  |      * Auth container binding | 
					
						
							|  |  |  |      */ | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     'enabled' => true, | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     /* | 
					
						
							|  |  |  |      * Lifetime in minutes. | 
					
						
							|  |  |  |      * In case you need your users to be asked for a new one time passwords from time to time. | 
					
						
							|  |  |  |      */ | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     'lifetime' => 0, // 0 = eternal
 | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     /* | 
					
						
							|  |  |  |      * Renew lifetime at every new request. | 
					
						
							|  |  |  |      */ | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     'keep_alive' => true, | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     /* | 
					
						
							|  |  |  |      * Auth container binding | 
					
						
							|  |  |  |      */ | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     'auth' => 'auth', | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     /* | 
					
						
							|  |  |  |      * 2FA verified session var | 
					
						
							|  |  |  |      */ | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2020-03-20 17:31:54 +01:00
										 |  |  |     'session_var'          => 'google2fa', | 
					
						
							| 
									
										
										
										
											2017-12-23 20:46:52 +01:00
										 |  |  | 
 | 
					
						
							|  |  |  |     /* | 
					
						
							|  |  |  |      * One Time Password request input name | 
					
						
							|  |  |  |      */ | 
					
						
							| 
									
										
										
										
											2020-03-20 17:31:54 +01:00
										 |  |  |     'otp_input'            => 'one_time_password', | 
					
						
							| 
									
										
										
										
											2017-12-23 20:46:52 +01:00
										 |  |  | 
 | 
					
						
							|  |  |  |     /* | 
					
						
							|  |  |  |      * One Time Password Window | 
					
						
							|  |  |  |      */ | 
					
						
							| 
									
										
										
										
											2020-03-20 17:31:54 +01:00
										 |  |  |     'window'               => 1, | 
					
						
							| 
									
										
										
										
											2017-12-23 20:46:52 +01:00
										 |  |  | 
 | 
					
						
							|  |  |  |     /* | 
					
						
							|  |  |  |      * Forbid user to reuse One Time Passwords. | 
					
						
							|  |  |  |      */ | 
					
						
							|  |  |  |     'forbid_old_passwords' => false, | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     /* | 
					
						
							|  |  |  |      * User's table column for google2fa secret | 
					
						
							|  |  |  |      */ | 
					
						
							| 
									
										
										
										
											2020-03-20 17:31:54 +01:00
										 |  |  |     'otp_secret_column'    => 'mfa_secret', | 
					
						
							| 
									
										
										
										
											2017-12-23 20:46:52 +01:00
										 |  |  | 
 | 
					
						
							|  |  |  |     /* | 
					
						
							|  |  |  |      * One Time Password View | 
					
						
							|  |  |  |      */ | 
					
						
							| 
									
										
										
										
											2021-02-01 06:57:29 +01:00
										 |  |  |     'view'                 => sprintf('%s.auth.mfa', env('FIREFLY_III_LAYOUT', 'v1')), | 
					
						
							| 
									
										
										
										
											2017-12-23 20:46:52 +01:00
										 |  |  | 
 | 
					
						
							|  |  |  |     /* | 
					
						
							|  |  |  |      * One Time Password error message | 
					
						
							|  |  |  |      */ | 
					
						
							| 
									
										
										
										
											2020-03-20 17:31:54 +01:00
										 |  |  |     'error_messages'       => [ | 
					
						
							| 
									
										
										
										
											2017-12-23 20:46:52 +01:00
										 |  |  |         'wrong_otp' => "The 'One Time Password' typed was wrong.", | 
					
						
							|  |  |  |     ], | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2019-08-03 19:49:32 +02:00
										 |  |  |     /* | 
					
						
							|  |  |  |      * Throw exceptions or just fire events? | 
					
						
							|  |  |  |      */ | 
					
						
							| 
									
										
										
										
											2020-03-20 17:31:54 +01:00
										 |  |  |     'throw_exceptions'     => true, | 
					
						
							| 
									
										
										
										
											2019-08-03 19:49:32 +02:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2019-12-07 17:44:33 +01:00
										 |  |  |     'store_in_cookie' => true, | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2017-12-23 20:46:52 +01:00
										 |  |  | ]; |