mirror of
https://we.phorge.it/source/phorge.git
synced 2024-11-22 14:52:41 +01:00
Generate QR codes for TOTP tokens
Summary: Ref T4398. I found a reasonable-ish LGPLv3 library for doing this, which isn't too huge or unwieldy. Test Plan: - Scanned QR code with Authy. - Scanned QR code with Google Authenticator. {F149317} Reviewers: btrahan Reviewed By: btrahan Subscribers: epriestley Maniphest Tasks: T4398 Differential Revision: https://secure.phabricator.com/D8923
This commit is contained in:
parent
50376aad04
commit
e146958217
5 changed files with 3582 additions and 3 deletions
165
externals/phpqrcode/LICENSE
vendored
Normal file
165
externals/phpqrcode/LICENSE
vendored
Normal file
|
@ -0,0 +1,165 @@
|
||||||
|
GNU LESSER GENERAL PUBLIC LICENSE
|
||||||
|
Version 3, 29 June 2007
|
||||||
|
|
||||||
|
Copyright (C) 2007 Free Software Foundation, Inc. <http://fsf.org/>
|
||||||
|
Everyone is permitted to copy and distribute verbatim copies
|
||||||
|
of this license document, but changing it is not allowed.
|
||||||
|
|
||||||
|
|
||||||
|
This version of the GNU Lesser General Public License incorporates
|
||||||
|
the terms and conditions of version 3 of the GNU General Public
|
||||||
|
License, supplemented by the additional permissions listed below.
|
||||||
|
|
||||||
|
0. Additional Definitions.
|
||||||
|
|
||||||
|
As used herein, "this License" refers to version 3 of the GNU Lesser
|
||||||
|
General Public License, and the "GNU GPL" refers to version 3 of the GNU
|
||||||
|
General Public License.
|
||||||
|
|
||||||
|
"The Library" refers to a covered work governed by this License,
|
||||||
|
other than an Application or a Combined Work as defined below.
|
||||||
|
|
||||||
|
An "Application" is any work that makes use of an interface provided
|
||||||
|
by the Library, but which is not otherwise based on the Library.
|
||||||
|
Defining a subclass of a class defined by the Library is deemed a mode
|
||||||
|
of using an interface provided by the Library.
|
||||||
|
|
||||||
|
A "Combined Work" is a work produced by combining or linking an
|
||||||
|
Application with the Library. The particular version of the Library
|
||||||
|
with which the Combined Work was made is also called the "Linked
|
||||||
|
Version".
|
||||||
|
|
||||||
|
The "Minimal Corresponding Source" for a Combined Work means the
|
||||||
|
Corresponding Source for the Combined Work, excluding any source code
|
||||||
|
for portions of the Combined Work that, considered in isolation, are
|
||||||
|
based on the Application, and not on the Linked Version.
|
||||||
|
|
||||||
|
The "Corresponding Application Code" for a Combined Work means the
|
||||||
|
object code and/or source code for the Application, including any data
|
||||||
|
and utility programs needed for reproducing the Combined Work from the
|
||||||
|
Application, but excluding the System Libraries of the Combined Work.
|
||||||
|
|
||||||
|
1. Exception to Section 3 of the GNU GPL.
|
||||||
|
|
||||||
|
You may convey a covered work under sections 3 and 4 of this License
|
||||||
|
without being bound by section 3 of the GNU GPL.
|
||||||
|
|
||||||
|
2. Conveying Modified Versions.
|
||||||
|
|
||||||
|
If you modify a copy of the Library, and, in your modifications, a
|
||||||
|
facility refers to a function or data to be supplied by an Application
|
||||||
|
that uses the facility (other than as an argument passed when the
|
||||||
|
facility is invoked), then you may convey a copy of the modified
|
||||||
|
version:
|
||||||
|
|
||||||
|
a) under this License, provided that you make a good faith effort to
|
||||||
|
ensure that, in the event an Application does not supply the
|
||||||
|
function or data, the facility still operates, and performs
|
||||||
|
whatever part of its purpose remains meaningful, or
|
||||||
|
|
||||||
|
b) under the GNU GPL, with none of the additional permissions of
|
||||||
|
this License applicable to that copy.
|
||||||
|
|
||||||
|
3. Object Code Incorporating Material from Library Header Files.
|
||||||
|
|
||||||
|
The object code form of an Application may incorporate material from
|
||||||
|
a header file that is part of the Library. You may convey such object
|
||||||
|
code under terms of your choice, provided that, if the incorporated
|
||||||
|
material is not limited to numerical parameters, data structure
|
||||||
|
layouts and accessors, or small macros, inline functions and templates
|
||||||
|
(ten or fewer lines in length), you do both of the following:
|
||||||
|
|
||||||
|
a) Give prominent notice with each copy of the object code that the
|
||||||
|
Library is used in it and that the Library and its use are
|
||||||
|
covered by this License.
|
||||||
|
|
||||||
|
b) Accompany the object code with a copy of the GNU GPL and this license
|
||||||
|
document.
|
||||||
|
|
||||||
|
4. Combined Works.
|
||||||
|
|
||||||
|
You may convey a Combined Work under terms of your choice that,
|
||||||
|
taken together, effectively do not restrict modification of the
|
||||||
|
portions of the Library contained in the Combined Work and reverse
|
||||||
|
engineering for debugging such modifications, if you also do each of
|
||||||
|
the following:
|
||||||
|
|
||||||
|
a) Give prominent notice with each copy of the Combined Work that
|
||||||
|
the Library is used in it and that the Library and its use are
|
||||||
|
covered by this License.
|
||||||
|
|
||||||
|
b) Accompany the Combined Work with a copy of the GNU GPL and this license
|
||||||
|
document.
|
||||||
|
|
||||||
|
c) For a Combined Work that displays copyright notices during
|
||||||
|
execution, include the copyright notice for the Library among
|
||||||
|
these notices, as well as a reference directing the user to the
|
||||||
|
copies of the GNU GPL and this license document.
|
||||||
|
|
||||||
|
d) Do one of the following:
|
||||||
|
|
||||||
|
0) Convey the Minimal Corresponding Source under the terms of this
|
||||||
|
License, and the Corresponding Application Code in a form
|
||||||
|
suitable for, and under terms that permit, the user to
|
||||||
|
recombine or relink the Application with a modified version of
|
||||||
|
the Linked Version to produce a modified Combined Work, in the
|
||||||
|
manner specified by section 6 of the GNU GPL for conveying
|
||||||
|
Corresponding Source.
|
||||||
|
|
||||||
|
1) Use a suitable shared library mechanism for linking with the
|
||||||
|
Library. A suitable mechanism is one that (a) uses at run time
|
||||||
|
a copy of the Library already present on the user's computer
|
||||||
|
system, and (b) will operate properly with a modified version
|
||||||
|
of the Library that is interface-compatible with the Linked
|
||||||
|
Version.
|
||||||
|
|
||||||
|
e) Provide Installation Information, but only if you would otherwise
|
||||||
|
be required to provide such information under section 6 of the
|
||||||
|
GNU GPL, and only to the extent that such information is
|
||||||
|
necessary to install and execute a modified version of the
|
||||||
|
Combined Work produced by recombining or relinking the
|
||||||
|
Application with a modified version of the Linked Version. (If
|
||||||
|
you use option 4d0, the Installation Information must accompany
|
||||||
|
the Minimal Corresponding Source and Corresponding Application
|
||||||
|
Code. If you use option 4d1, you must provide the Installation
|
||||||
|
Information in the manner specified by section 6 of the GNU GPL
|
||||||
|
for conveying Corresponding Source.)
|
||||||
|
|
||||||
|
5. Combined Libraries.
|
||||||
|
|
||||||
|
You may place library facilities that are a work based on the
|
||||||
|
Library side by side in a single library together with other library
|
||||||
|
facilities that are not Applications and are not covered by this
|
||||||
|
License, and convey such a combined library under terms of your
|
||||||
|
choice, if you do both of the following:
|
||||||
|
|
||||||
|
a) Accompany the combined library with a copy of the same work based
|
||||||
|
on the Library, uncombined with any other library facilities,
|
||||||
|
conveyed under the terms of this License.
|
||||||
|
|
||||||
|
b) Give prominent notice with the combined library that part of it
|
||||||
|
is a work based on the Library, and explaining where to find the
|
||||||
|
accompanying uncombined form of the same work.
|
||||||
|
|
||||||
|
6. Revised Versions of the GNU Lesser General Public License.
|
||||||
|
|
||||||
|
The Free Software Foundation may publish revised and/or new versions
|
||||||
|
of the GNU Lesser General Public License from time to time. Such new
|
||||||
|
versions will be similar in spirit to the present version, but may
|
||||||
|
differ in detail to address new problems or concerns.
|
||||||
|
|
||||||
|
Each version is given a distinguishing version number. If the
|
||||||
|
Library as you received it specifies that a certain numbered version
|
||||||
|
of the GNU Lesser General Public License "or any later version"
|
||||||
|
applies to it, you have the option of following the terms and
|
||||||
|
conditions either of that published version or of any later version
|
||||||
|
published by the Free Software Foundation. If the Library as you
|
||||||
|
received it does not specify a version number of the GNU Lesser
|
||||||
|
General Public License, you may choose any version of the GNU Lesser
|
||||||
|
General Public License ever published by the Free Software Foundation.
|
||||||
|
|
||||||
|
If the Library as you received it specifies that a proxy can decide
|
||||||
|
whether future versions of the GNU Lesser General Public License shall
|
||||||
|
apply, that proxy's public statement of acceptance of any version is
|
||||||
|
permanent authorization for you to choose that version for the
|
||||||
|
Library.
|
45
externals/phpqrcode/README
vendored
Normal file
45
externals/phpqrcode/README
vendored
Normal file
|
@ -0,0 +1,45 @@
|
||||||
|
This is PHP implementation of QR Code 2-D barcode generator. It is pure-php
|
||||||
|
LGPL-licensed implementation based on C libqrencode by Kentaro Fukuchi.
|
||||||
|
|
||||||
|
== LICENSING ==
|
||||||
|
|
||||||
|
Copyright (C) 2010 by Dominik Dzienia
|
||||||
|
|
||||||
|
This library is free software; you can redistribute it and/or modify it under
|
||||||
|
the terms of the GNU Lesser General Public License as published by the Free
|
||||||
|
Software Foundation; either version 3 of the License, or any later version.
|
||||||
|
|
||||||
|
This library is distributed in the hope that it will be useful, but WITHOUT ANY
|
||||||
|
WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A
|
||||||
|
PARTICULAR PURPOSE. See the GNU Lesser General Public License (LICENSE file)
|
||||||
|
for more details.
|
||||||
|
|
||||||
|
You should have received a copy of the GNU Lesser General Public License along
|
||||||
|
with this library; if not, write to the Free Software Foundation, Inc., 51
|
||||||
|
Franklin St, Fifth Floor, Boston, MA 02110-1301 USA
|
||||||
|
|
||||||
|
== INSTALATION AND USAGE ==
|
||||||
|
|
||||||
|
* INSTALL file
|
||||||
|
* http://sourceforge.net/apps/mediawiki/phpqrcode/index.php?title=Main_Page
|
||||||
|
|
||||||
|
== CONTACT ==
|
||||||
|
|
||||||
|
Fell free to contact me via e-mail (deltalab at poczta dot fm) or using
|
||||||
|
folowing project pages:
|
||||||
|
|
||||||
|
* http://sourceforge.net/projects/phpqrcode/
|
||||||
|
* http://phpqrcode.sourceforge.net/
|
||||||
|
|
||||||
|
== ACKNOWLEDGMENTS ==
|
||||||
|
|
||||||
|
Based on C libqrencode library (ver. 3.1.1)
|
||||||
|
Copyright (C) 2006-2010 by Kentaro Fukuchi
|
||||||
|
http://megaui.net/fukuchi/works/qrencode/index.en.html
|
||||||
|
|
||||||
|
QR Code is registered trademarks of DENSO WAVE INCORPORATED in JAPAN and other
|
||||||
|
countries.
|
||||||
|
|
||||||
|
Reed-Solomon code encoder is written by Phil Karn, KA9Q.
|
||||||
|
Copyright (C) 2002, 2003, 2004, 2006 Phil Karn, KA9Q
|
||||||
|
|
2
externals/phpqrcode/VERSION
vendored
Normal file
2
externals/phpqrcode/VERSION
vendored
Normal file
|
@ -0,0 +1,2 @@
|
||||||
|
1.1.4
|
||||||
|
2010100721
|
3312
externals/phpqrcode/phpqrcode.php
vendored
Normal file
3312
externals/phpqrcode/phpqrcode.php
vendored
Normal file
File diff suppressed because it is too large
Load diff
|
@ -22,7 +22,6 @@ final class PhabricatorAuthFactorTOTP extends PhabricatorAuthFactor {
|
||||||
AphrontRequest $request,
|
AphrontRequest $request,
|
||||||
PhabricatorUser $user) {
|
PhabricatorUser $user) {
|
||||||
|
|
||||||
|
|
||||||
$key = $request->getStr('totpkey');
|
$key = $request->getStr('totpkey');
|
||||||
if (!strlen($key)) {
|
if (!strlen($key)) {
|
||||||
// TODO: When the user submits a key, we should require that it be
|
// TODO: When the user submits a key, we should require that it be
|
||||||
|
@ -69,8 +68,21 @@ final class PhabricatorAuthFactorTOTP extends PhabricatorAuthFactor {
|
||||||
$form->appendInstructions(
|
$form->appendInstructions(
|
||||||
pht(
|
pht(
|
||||||
'Launch the application on your phone, and add a new entry for '.
|
'Launch the application on your phone, and add a new entry for '.
|
||||||
'this Phabricator install. When prompted, enter the key shown '.
|
'this Phabricator install. When prompted, scan the QR code or '.
|
||||||
'below into the application.'));
|
'manually enter the key shown below into the application.'));
|
||||||
|
|
||||||
|
$prod_uri = new PhutilURI(PhabricatorEnv::getProductionURI('/'));
|
||||||
|
$issuer = $prod_uri->getDomain();
|
||||||
|
|
||||||
|
$uri = urisprintf(
|
||||||
|
'otpauth://totp/%s:%s?secret=%s&issuer=%s',
|
||||||
|
$issuer,
|
||||||
|
$user->getUsername(),
|
||||||
|
$key,
|
||||||
|
$issuer);
|
||||||
|
|
||||||
|
$qrcode = $this->renderQRCode($uri);
|
||||||
|
$form->appendChild($qrcode);
|
||||||
|
|
||||||
$form->appendChild(
|
$form->appendChild(
|
||||||
id(new AphrontFormStaticControl())
|
id(new AphrontFormStaticControl())
|
||||||
|
@ -219,4 +231,47 @@ final class PhabricatorAuthFactorTOTP extends PhabricatorAuthFactor {
|
||||||
return $code;
|
return $code;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @phutil-external-symbol class QRcode
|
||||||
|
*/
|
||||||
|
private function renderQRCode($uri) {
|
||||||
|
$root = dirname(phutil_get_library_root('phabricator'));
|
||||||
|
require_once $root.'/externals/phpqrcode/phpqrcode.php';
|
||||||
|
|
||||||
|
$lines = QRcode::text($uri);
|
||||||
|
|
||||||
|
$total_width = 240;
|
||||||
|
$cell_size = floor($total_width / count($lines));
|
||||||
|
|
||||||
|
$rows = array();
|
||||||
|
foreach ($lines as $line) {
|
||||||
|
$cells = array();
|
||||||
|
for ($ii = 0; $ii < strlen($line); $ii++) {
|
||||||
|
if ($line[$ii] == '1') {
|
||||||
|
$color = '#000';
|
||||||
|
} else {
|
||||||
|
$color = '#fff';
|
||||||
|
}
|
||||||
|
|
||||||
|
$cells[] = phutil_tag(
|
||||||
|
'td',
|
||||||
|
array(
|
||||||
|
'width' => $cell_size,
|
||||||
|
'height' => $cell_size,
|
||||||
|
'style' => 'background: '.$color,
|
||||||
|
),
|
||||||
|
'');
|
||||||
|
}
|
||||||
|
$rows[] = phutil_tag('tr', array(), $cells);
|
||||||
|
}
|
||||||
|
|
||||||
|
return phutil_tag(
|
||||||
|
'table',
|
||||||
|
array(
|
||||||
|
'style' => 'margin: 24px auto;',
|
||||||
|
),
|
||||||
|
$rows);
|
||||||
|
}
|
||||||
|
|
||||||
}
|
}
|
||||||
|
|
Loading…
Reference in a new issue