Class: Admin::MfaController

Inherits:
BaseController show all
Defined in:
lib/generators/open_loam/install/templates/admin/mfa_controller.rb

Overview

A user's own two-factor setup — self-service, so NOT role-gated (everyone manages their own MFA). Enrollment is two steps: new (GET) shows a CANDIDATE secret held in the session, create (POST) confirms a live code and only then adopts it. Crucially, GET never mutates the credential, and the old secret stays valid until the new one is proven — so neither a cross-site GET nor an abandoned re-enrollment can downgrade an active credential.

Constant Summary collapse

ISSUER =

Shown in authenticator apps as the account issuer; defaults to the app name.

Rails.application.class.module_parent_name.freeze

Constants included from Pagination

Pagination::PER_PAGE

Instance Method Summary collapse

Methods inherited from BaseController

skip_authorization!

Methods included from Pagination

#paginate

Instance Method Details

#create ⇒ Object

Confirm the candidate against a live code, then adopt it and reveal the recovery codes once. The active secret is replaced only on success.



34
35
36
37
38
39
40
41
42
43
44
45
46
47
# File 'lib/generators/open_loam/install/templates/admin/mfa_controller.rb', line 34

def create
  secret = session[:mfa_enrollment_secret]
  credential = OpenLoam::MfaCredential.find_or_initialize_by(user_id: current_actor.id)
  @recovery_codes = secret && credential.activate_with!(secret, params[:code])

  if @recovery_codes
    session.delete(:mfa_enrollment_secret)
    render :activated
  else
    set_enrollment_secret
    @error = "That code did not match. Check your authenticator and try again."
    render :new, status: :unprocessable_entity
  end
end

#destroy ⇒ Object



49
50
51
52
53
# File 'lib/generators/open_loam/install/templates/admin/mfa_controller.rb', line 49

def destroy
  OpenLoam::MfaCredential.where(user_id: current_actor.id).delete_all
  session.delete(:mfa_enrollment_secret)
  redirect_to admin_mfa_path, notice: "Two-factor authentication disabled."
end

#new ⇒ Object

READ-ONLY: mint a candidate secret into the (encrypted cookie) session and display it. No credential is touched, so this is safe to reach via GET.



28
29
30
# File 'lib/generators/open_loam/install/templates/admin/mfa_controller.rb', line 28

def new
  set_enrollment_secret
end

#show ⇒ Object



22
23
24
# File 'lib/generators/open_loam/install/templates/admin/mfa_controller.rb', line 22

def show
  @credential = OpenLoam::MfaCredential.active_for(current_actor)
end