BackupCodeStorage.php 2.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109
  1. <?php
  2. declare(strict_types=1);
  3. /**
  4. * SPDX-FileCopyrightText: 2016 Nextcloud GmbH and Nextcloud contributors
  5. * SPDX-License-Identifier: AGPL-3.0-or-later
  6. */
  7. namespace OCA\TwoFactorBackupCodes\Service;
  8. use OCA\TwoFactorBackupCodes\Db\BackupCode;
  9. use OCA\TwoFactorBackupCodes\Db\BackupCodeMapper;
  10. use OCA\TwoFactorBackupCodes\Event\CodesGenerated;
  11. use OCP\EventDispatcher\IEventDispatcher;
  12. use OCP\IUser;
  13. use OCP\Security\IHasher;
  14. use OCP\Security\ISecureRandom;
  15. class BackupCodeStorage {
  16. private static $CODE_LENGTH = 16;
  17. public function __construct(
  18. private BackupCodeMapper $mapper,
  19. private ISecureRandom $random,
  20. private IHasher $hasher,
  21. private IEventDispatcher $eventDispatcher,
  22. ) {
  23. }
  24. /**
  25. * @param IUser $user
  26. * @param int $number
  27. * @return string[]
  28. */
  29. public function createCodes(IUser $user, int $number = 10): array {
  30. $result = [];
  31. // Delete existing ones
  32. $this->mapper->deleteCodes($user);
  33. $uid = $user->getUID();
  34. foreach (range(1, min([$number, 20])) as $i) {
  35. $code = $this->random->generate(self::$CODE_LENGTH, ISecureRandom::CHAR_HUMAN_READABLE);
  36. $dbCode = new BackupCode();
  37. $dbCode->setUserId($uid);
  38. $dbCode->setCode($this->hasher->hash($code));
  39. $dbCode->setUsed(0);
  40. $this->mapper->insert($dbCode);
  41. $result[] = $code;
  42. }
  43. $this->eventDispatcher->dispatchTyped(new CodesGenerated($user));
  44. return $result;
  45. }
  46. /**
  47. * @param IUser $user
  48. * @return bool
  49. */
  50. public function hasBackupCodes(IUser $user): bool {
  51. $codes = $this->mapper->getBackupCodes($user);
  52. return count($codes) > 0;
  53. }
  54. /**
  55. * @param IUser $user
  56. * @return array
  57. */
  58. public function getBackupCodesState(IUser $user): array {
  59. $codes = $this->mapper->getBackupCodes($user);
  60. $total = count($codes);
  61. $used = 0;
  62. array_walk($codes, function (BackupCode $code) use (&$used): void {
  63. if ((int)$code->getUsed() === 1) {
  64. $used++;
  65. }
  66. });
  67. return [
  68. 'enabled' => $total > 0,
  69. 'total' => $total,
  70. 'used' => $used,
  71. ];
  72. }
  73. /**
  74. * @param IUser $user
  75. * @param string $code
  76. * @return bool
  77. */
  78. public function validateCode(IUser $user, string $code): bool {
  79. $dbCodes = $this->mapper->getBackupCodes($user);
  80. foreach ($dbCodes as $dbCode) {
  81. if ((int)$dbCode->getUsed() === 0 && $this->hasher->verify($code, $dbCode->getCode())) {
  82. $dbCode->setUsed(1);
  83. $this->mapper->update($dbCode);
  84. return true;
  85. }
  86. }
  87. return false;
  88. }
  89. public function deleteCodes(IUser $user): void {
  90. $this->mapper->deleteCodes($user);
  91. }
  92. }