MDL-85015 tool_mfa: Include extra param in email factor cancel check
This commit is contained in:
@@ -41,7 +41,8 @@ class factor_email_renderer extends plugin_renderer_base {
|
||||
$authurl = new \moodle_url('/admin/tool/mfa/factor/email/email.php',
|
||||
['instance' => $instance->id, 'pass' => 1, 'secret' => $instance->secret]);
|
||||
$authurlstring = \html_writer::link($authurl, get_string('email:link', 'factor_email'));
|
||||
$blockurl = new \moodle_url('/admin/tool/mfa/factor/email/email.php', ['instance' => $instanceid]);
|
||||
$blockurl = new \moodle_url('/admin/tool/mfa/factor/email/email.php',
|
||||
['instance' => $instance->id, 'secret' => $instance->secret]);
|
||||
$blockurlstring = \html_writer::link($blockurl, get_string('email:stoploginlink', 'factor_email'));
|
||||
$geoinfo = iplookup_find_location($instance->createdfromip);
|
||||
|
||||
|
||||
@@ -42,7 +42,8 @@ $PAGE->set_cacheable(false);
|
||||
$instance = $DB->get_record('tool_mfa', ['id' => $instanceid]);
|
||||
$factor = \tool_mfa\plugininfo\factor::get_factor('email');
|
||||
|
||||
// If pass is set, require login to force $SESSION and user, and pass for that session.
|
||||
// If pass is set, do checks and pass for this session.
|
||||
// Require login to force $SESSION and user, and pass for that session.
|
||||
if (!empty($instance) && $pass != 0 && $secret != 0) {
|
||||
require_login();
|
||||
if ($factor->get_state() === \tool_mfa\plugininfo\factor::STATE_LOCKED) {
|
||||
@@ -69,8 +70,12 @@ $form = new \factor_email\form\email($url);
|
||||
|
||||
if ($form->is_cancelled()) {
|
||||
redirect(new moodle_url('/'));
|
||||
} else if ($fromform = $form->get_data()) {
|
||||
if (empty($instance)) {
|
||||
}
|
||||
|
||||
// If submitted without the pass param, is a cancel request - do checks and revoke email factor.
|
||||
if ($fromform = $form->get_data()) {
|
||||
// Only allow revoke attempts from requests with a valid instance and secret.
|
||||
if (empty($instance) || empty($secret) || $instance->secret != $secret) {
|
||||
$message = get_string('error:badcode', 'factor_email');
|
||||
} else {
|
||||
$user = $DB->get_record('user', ['id' => $instance->userid]);
|
||||
|
||||
@@ -33,7 +33,7 @@ $string['email:loginlink'] = 'Or, if you\'re on the same device, use this {$a}.'
|
||||
$string['email:message'] = 'Here\'s your verification code for {$a->sitename} ({$a->siteurl}).';
|
||||
$string['email:originatingip'] = 'This login request was made from \'{$a}\'';
|
||||
$string['email:revokelink'] = 'If this wasn\'t you, you can {$a}.';
|
||||
$string['email:revokesuccess'] = 'This code has been successfully revoked. All sessions for {$a} have been ended.
|
||||
$string['email:revokesuccess'] = 'This code has been successfully revoked. All sessions for this user have been ended.
|
||||
Email will not be usable as a factor until account security has been verified.';
|
||||
$string['email:subject'] = 'Here\'s your verification code';
|
||||
$string['email:stoploginlink'] = 'stop this login attempt';
|
||||
|
||||
Reference in New Issue
Block a user