Skip to content

Commit

Permalink
add OCC command to enable/disable 2FA for a user
Browse files Browse the repository at this point in the history
  • Loading branch information
ChristophWurst committed May 17, 2016
1 parent 6f85fe9 commit eecd262
Show file tree
Hide file tree
Showing 6 changed files with 170 additions and 3 deletions.
65 changes: 65 additions & 0 deletions core/Command/TwoFactorAuth/Disable.php
Original file line number Diff line number Diff line change
@@ -0,0 +1,65 @@
<?php

/**
* @author Christoph Wurst <[email protected]>
*
* @copyright Copyright (c) 2016, ownCloud, Inc.
* @license AGPL-3.0
*
* This code is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License, version 3,
* as published by the Free Software Foundation.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU Affero General Public License for more details.
*
* You should have received a copy of the GNU Affero General Public License, version 3,
* along with this program. If not, see <http://www.gnu.org/licenses/>
*
*/

namespace OC\Core\Command\TwoFactorAuth;

use OC\Authentication\TwoFactorAuth\Manager;
use OC\User\Manager as UserManager;
use OC\Core\Command\Base;
use Symfony\Component\Console\Input\InputArgument;
use Symfony\Component\Console\Input\InputInterface;
use Symfony\Component\Console\Output\OutputInterface;

class Disable extends Base {

/** @var Manager */
private $manager;

/** @var UserManager */
private $userManager;

public function __construct(Manager $manager, UserManager $userManager) {
parent::__construct('twofactorauth:disable');
$this->manager = $manager;
$this->userManager = $userManager;
}

protected function configure() {
parent::configure();

$this->setName('twofactorauth:disable');
$this->setDescription('Disable 2FA for a user');
$this->addArgument('uid', InputArgument::REQUIRED);
}

protected function execute(InputInterface $input, OutputInterface $output) {
$uid = $input->getArgument('uid');
$user = $this->userManager->get($uid);
if (is_null($user)) {
$output->writeln("<error>Invalid UID</error>");
return;
}
$this->manager->disableTwoFactorAuthentication($user);
$output->writeln("2FA disabled for user $uid");
}

}
65 changes: 65 additions & 0 deletions core/Command/TwoFactorAuth/Enable.php
Original file line number Diff line number Diff line change
@@ -0,0 +1,65 @@
<?php

/**
* @author Christoph Wurst <[email protected]>
*
* @copyright Copyright (c) 2016, ownCloud, Inc.
* @license AGPL-3.0
*
* This code is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License, version 3,
* as published by the Free Software Foundation.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU Affero General Public License for more details.
*
* You should have received a copy of the GNU Affero General Public License, version 3,
* along with this program. If not, see <http://www.gnu.org/licenses/>
*
*/

namespace OC\Core\Command\TwoFactorAuth;

use OC\Authentication\TwoFactorAuth\Manager;
use OC\User\Manager as UserManager;
use OC\Core\Command\Base;
use Symfony\Component\Console\Input\InputArgument;
use Symfony\Component\Console\Input\InputInterface;
use Symfony\Component\Console\Output\OutputInterface;

class Enable extends Base {

/** @var Manager */
private $manager;

/** @var UserManager */
private $userManager;

public function __construct(Manager $manager, UserManager $userManager) {
parent::__construct('twofactorauth:enable');
$this->manager = $manager;
$this->userManager = $userManager;
}

protected function configure() {
parent::configure();

$this->setName('twofactorauth:enable');
$this->setDescription('Enable 2FA for a user');
$this->addArgument('uid', InputArgument::REQUIRED);
}

protected function execute(InputInterface $input, OutputInterface $output) {
$uid = $input->getArgument('uid');
$user = $this->userManager->get($uid);
if (is_null($user)) {
$output->writeln("<error>Invalid UID</error>");
return;
}
$this->manager->enableTwoFactorAuthentication($user);
$output->writeln("2FA enabled for user $uid");
}

}
4 changes: 4 additions & 0 deletions core/Middleware/TwoFactorMiddleware.php
Original file line number Diff line number Diff line change
Expand Up @@ -72,6 +72,10 @@ public function beforeController($controller, $methodName) {

if ($this->twoFactorManager->isTwoFactorAuthenticated($user)) {
$this->checkTwoFactor($controller, $methodName);
} else if ($controller instanceof TwoFactorChallengeController) {
// Allow access to the two-factor controllers only if two-factor authentication
// is in progress.
throw new UserAlreadyLoggedInException();
}
}
// TODO: force login if controller != LoginController
Expand Down
8 changes: 8 additions & 0 deletions core/register_command.php
Original file line number Diff line number Diff line change
Expand Up @@ -50,6 +50,14 @@
$application->add(new \OC\Core\Command\Integrity\CheckCore(
\OC::$server->getIntegrityCodeChecker()
));
$application->add(new OC\Core\Command\TwoFactorAuth\Enable(
\OC::$server->getTwoFactorAuthManager(),
\OC::$server->getUserManager()
));
$application->add(new OC\Core\Command\TwoFactorAuth\Disable(
\OC::$server->getTwoFactorAuthManager(),
\OC::$server->getUserManager()
));


if (\OC::$server->getConfig()->getSystemValue('installed', false)) {
Expand Down
29 changes: 27 additions & 2 deletions lib/private/Authentication/TwoFactorAuth/Manager.php
Original file line number Diff line number Diff line change
Expand Up @@ -26,6 +26,7 @@
use OC\App\AppManager;
use OCP\AppFramework\QueryException;
use OCP\Authentication\TwoFactorAuth\IProvider;
use OCP\IConfig;
use OCP\ISession;
use OCP\IUser;

Expand All @@ -39,13 +40,18 @@ class Manager {
/** @var ISession */
private $session;

/** @var IConfig */
private $config;

/**
* @param AppManager $appManager
* @param ISession $session
* @param IConfig $config
*/
public function __construct(AppManager $appManager, ISession $session) {
public function __construct(AppManager $appManager, ISession $session, IConfig $config) {
$this->appManager = $appManager;
$this->session = $session;
$this->config = $config;
}

/**
Expand All @@ -55,7 +61,26 @@ public function __construct(AppManager $appManager, ISession $session) {
* @return boolean
*/
public function isTwoFactorAuthenticated(IUser $user) {
return count($this->getProviders($user)) > 0;
$twoFactorEnabled = ((int) $this->config->getUserValue($user->getUID(), 'core', 'two_factor_auth_disabled', 0)) === 0;
return $twoFactorEnabled && count($this->getProviders($user)) > 0;
}

/**
* Disable 2FA checks for the given user
*
* @param IUser $user
*/
public function disableTwoFactorAuthentication(IUser $user) {
$this->config->setUserValue($user->getUID(), 'core', 'two_factor_auth_disabled', 1);
}

/**
* Enable all 2FA checks for the given user
*
* @param IUser $user
*/
public function enableTwoFactorAuthentication(IUser $user) {
$this->config->deleteUserValue($user->getUID(), 'core', 'two_factor_auth_disabled');
}

/**
Expand Down
2 changes: 1 addition & 1 deletion lib/private/Server.php
Original file line number Diff line number Diff line change
Expand Up @@ -279,7 +279,7 @@ public function __construct($webRoot, \OC\Config $config) {
});

$this->registerService('\OC\Authentication\TwoFactorAuth\Manager', function (Server $c) {
return new \OC\Authentication\TwoFactorAuth\Manager($c->getAppManager(), $c->getSession());
return new \OC\Authentication\TwoFactorAuth\Manager($c->getAppManager(), $c->getSession(), $c->getConfig());
});

$this->registerService('NavigationManager', function ($c) {
Expand Down

0 comments on commit eecd262

Please sign in to comment.