Feat: Adding hashes for otp codes
This commit is contained in:
@@ -2,6 +2,7 @@
|
||||
|
||||
namespace Modules\Core\Auth\Services;
|
||||
|
||||
use Illuminate\Support\Facades\Hash;
|
||||
use Illuminate\Support\Facades\Mail;
|
||||
use Modules\Core\Auth\Mail\OtpMail;
|
||||
use Modules\Core\Auth\Models\Staff;
|
||||
@@ -27,7 +28,10 @@ class OtpService
|
||||
|
||||
$code = str_pad((string) random_int(0, 999999), self::CODE_LENGTH, '0', STR_PAD_LEFT);
|
||||
|
||||
$staff->otp_code = $code;
|
||||
// otp_code_hash's 'hashed' cast (see Staff's own $casts) hashes
|
||||
// this automatically on assignment, same as password — never
|
||||
// stored or compared in plaintext.
|
||||
$staff->otp_code_hash = $code;
|
||||
$staff->otp_expires_at = now()->addMinutes(self::EXPIRY_MINUTES);
|
||||
$staff->save();
|
||||
|
||||
@@ -44,11 +48,15 @@ class OtpService
|
||||
return null;
|
||||
}
|
||||
|
||||
if (! $staff->otp_expires_at || $staff->otp_code != $code || now()->isAfter($staff->otp_expires_at)) {
|
||||
if (! $staff->otp_code_hash || ! $staff->otp_expires_at || now()->isAfter($staff->otp_expires_at)) {
|
||||
return null;
|
||||
}
|
||||
|
||||
$staff->otp_code = null;
|
||||
if (! Hash::check($code, $staff->otp_code_hash)) {
|
||||
return null;
|
||||
}
|
||||
|
||||
$staff->otp_code_hash = null;
|
||||
$staff->otp_expires_at = null;
|
||||
$staff->save();
|
||||
|
||||
|
||||
Reference in New Issue
Block a user