Class: Admin::MfaController
- Inherits:
-
BaseController
- Object
- ActionController::Base
- BaseController
- Admin::MfaController
- Defined in:
- lib/generators/open_loam/install/templates/admin/mfa_controller.rb
Overview
A user's own two-factor setup — self-service, so NOT role-gated (everyone
manages their own MFA). Enrollment is two steps: new (GET) shows a
CANDIDATE secret held in the session, create (POST) confirms a live code
and only then adopts it. Crucially, GET never mutates the credential, and the
old secret stays valid until the new one is proven — so neither a cross-site
GET nor an abandoned re-enrollment can downgrade an active credential.
Constant Summary collapse
- ISSUER =
Shown in authenticator apps as the account issuer; defaults to the app name.
Rails.application.class.module_parent_name.freeze
Constants included from Pagination
Instance Method Summary collapse
-
#create ⇒ Object
Confirm the candidate against a live code, then adopt it and reveal the recovery codes once.
- #destroy ⇒ Object
-
#new ⇒ Object
READ-ONLY: mint a candidate secret into the (encrypted cookie) session and display it.
- #show ⇒ Object
Methods inherited from BaseController
Methods included from Pagination
Instance Method Details
#create ⇒ Object
Confirm the candidate against a live code, then adopt it and reveal the recovery codes once. The active secret is replaced only on success.
34 35 36 37 38 39 40 41 42 43 44 45 46 47 |
# File 'lib/generators/open_loam/install/templates/admin/mfa_controller.rb', line 34 def create secret = session[:mfa_enrollment_secret] credential = OpenLoam::MfaCredential.find_or_initialize_by(user_id: current_actor.id) @recovery_codes = secret && credential.activate_with!(secret, params[:code]) if @recovery_codes session.delete(:mfa_enrollment_secret) render :activated else set_enrollment_secret @error = "That code did not match. Check your authenticator and try again." render :new, status: :unprocessable_entity end end |
#destroy ⇒ Object
49 50 51 52 53 |
# File 'lib/generators/open_loam/install/templates/admin/mfa_controller.rb', line 49 def destroy OpenLoam::MfaCredential.where(user_id: current_actor.id).delete_all session.delete(:mfa_enrollment_secret) redirect_to admin_mfa_path, notice: "Two-factor authentication disabled." end |
#new ⇒ Object
READ-ONLY: mint a candidate secret into the (encrypted cookie) session and display it. No credential is touched, so this is safe to reach via GET.
28 29 30 |
# File 'lib/generators/open_loam/install/templates/admin/mfa_controller.rb', line 28 def new set_enrollment_secret end |
#show ⇒ Object
22 23 24 |
# File 'lib/generators/open_loam/install/templates/admin/mfa_controller.rb', line 22 def show @credential = OpenLoam::MfaCredential.active_for(current_actor) end |