66 lines
1.8 KiB
PHP
66 lines
1.8 KiB
PHP
<?php
|
|
|
|
namespace Modules\Core\Auth\Services;
|
|
|
|
use Illuminate\Support\Facades\Hash;
|
|
use Illuminate\Support\Facades\Mail;
|
|
use Modules\Core\Auth\Mail\OtpMail;
|
|
use Modules\Core\Auth\Models\Staff;
|
|
|
|
class OtpService
|
|
{
|
|
private const EXPIRY_MINUTES = 10;
|
|
private const CODE_LENGTH = 6;
|
|
|
|
/**
|
|
* $purpose is forwarded as-is to OtpMail, which only recognizes a
|
|
* fixed set of keys (see its own COPY_BY_PURPOSE) — an unrecognized
|
|
* value there just falls back to 'login' rather than failing here, so
|
|
* this method has nothing of its own to validate.
|
|
*/
|
|
public function generateAndSend(string $email, string $purpose = 'login'): bool
|
|
{
|
|
$staff = Staff::where('email', $email)->first();
|
|
|
|
if (! $staff) {
|
|
return false;
|
|
}
|
|
|
|
$code = str_pad((string) random_int(0, 999999), self::CODE_LENGTH, '0', STR_PAD_LEFT);
|
|
|
|
// otp_code_hash's 'hashed' cast (see Staff's own $casts) hashes
|
|
// this automatically on assignment, same as password — never
|
|
// stored or compared in plaintext.
|
|
$staff->otp_code_hash = $code;
|
|
$staff->otp_expires_at = now()->addMinutes(self::EXPIRY_MINUTES);
|
|
$staff->save();
|
|
|
|
Mail::to($staff->email)->send(new OtpMail($staff->first_name, $code, $purpose));
|
|
|
|
return true;
|
|
}
|
|
|
|
public function validate(string $email, string $code): ?Staff
|
|
{
|
|
$staff = Staff::where('email', $email)->first();
|
|
|
|
if (! $staff) {
|
|
return null;
|
|
}
|
|
|
|
if (! $staff->otp_code_hash || ! $staff->otp_expires_at || now()->isAfter($staff->otp_expires_at)) {
|
|
return null;
|
|
}
|
|
|
|
if (! Hash::check($code, $staff->otp_code_hash)) {
|
|
return null;
|
|
}
|
|
|
|
$staff->otp_code_hash = null;
|
|
$staff->otp_expires_at = null;
|
|
$staff->save();
|
|
|
|
return $staff;
|
|
}
|
|
}
|