Tom
2 days ago
committed by
GitHub
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
3 changed files with
14 additions and
1 deletions
-
.env.template
-
src/auth.rs
-
src/config.rs
|
|
|
@ -617,6 +617,9 @@ |
|
|
|
## Note that the checkbox would still be present, but ignored. |
|
|
|
# DISABLE_2FA_REMEMBER=false |
|
|
|
## |
|
|
|
## Number of days before a remembered 2FA login expires (min: 1, max: 90). |
|
|
|
# TWO_FACTOR_REMEMBER_DAYS=30 |
|
|
|
## |
|
|
|
## Authenticator Settings |
|
|
|
## Disable authenticator time drifted codes to be valid. |
|
|
|
## TOTP codes of the previous and next 30 seconds will be invalid |
|
|
|
|
|
|
|
@ -474,13 +474,17 @@ pub fn generate_2fa_remember_claims(device_uuid: DeviceId, user_uuid: UserId) -> |
|
|
|
let time_now = Utc::now(); |
|
|
|
TwoFactorRememberClaims { |
|
|
|
nbf: time_now.timestamp(), |
|
|
|
exp: (time_now + TimeDelta::try_days(30).unwrap()).timestamp(), |
|
|
|
exp: two_factor_remember_expiration(time_now, CONFIG.two_factor_remember_days()), |
|
|
|
iss: JWT_2FA_REMEMBER_ISSUER.to_string(), |
|
|
|
sub: device_uuid, |
|
|
|
user_uuid, |
|
|
|
} |
|
|
|
} |
|
|
|
|
|
|
|
fn two_factor_remember_expiration(time_now: DateTime<Utc>, remember_days: i64) -> i64 { |
|
|
|
(time_now + TimeDelta::try_days(remember_days).expect("TWO_FACTOR_REMEMBER_DAYS is validated")).timestamp() |
|
|
|
} |
|
|
|
|
|
|
|
#[derive(Debug, Serialize, Deserialize)] |
|
|
|
pub struct BasicJwtClaims { |
|
|
|
// Not before
|
|
|
|
|
|
|
|
@ -716,6 +716,8 @@ make_config! { |
|
|
|
/// Disable Two-Factor remember |> Enabling this would force the users to use a second factor to login every time.
|
|
|
|
/// Note that the checkbox would still be present, but ignored.
|
|
|
|
disable_2fa_remember: bool, true, def, false; |
|
|
|
/// Two-Factor remember duration |> Number of days before a remembered Two-Factor login expires (min: 1, max: 90).
|
|
|
|
two_factor_remember_days: i64, true, def, 30; |
|
|
|
|
|
|
|
/// Disable authenticator time drifted codes to be valid |> Enabling this only allows the current TOTP code to be valid
|
|
|
|
/// TOTP codes of the previous and next 30 seconds will be invalid.
|
|
|
|
@ -1236,6 +1238,10 @@ fn validate_config(cfg: &ConfigItems, on_update: bool) -> Result<(), Error> { |
|
|
|
err!("`INVITATION_EXPIRATION_HOURS` has a minimum duration of 1 hour") |
|
|
|
} |
|
|
|
|
|
|
|
if !(1..=90).contains(&cfg.two_factor_remember_days) { |
|
|
|
err!("`TWO_FACTOR_REMEMBER_DAYS` must be between 1 and 90 days") |
|
|
|
} |
|
|
|
|
|
|
|
// Validate schedule crontab format
|
|
|
|
if !cfg.send_purge_schedule.is_empty() && cfg.send_purge_schedule.parse::<Schedule>().is_err() { |
|
|
|
err!("`SEND_PURGE_SCHEDULE` is not a valid cron expression") |
|
|
|
|