TwoFactorAuth.php 1.0 KB

1234567891011121314151617181920212223242526272829303132333435
  1. <?php
  2. namespace App\Http\Middleware;
  3. use Auth;
  4. use Closure;
  5. class TwoFactorAuth
  6. {
  7. /**
  8. * Handle an incoming request.
  9. *
  10. * @param \Illuminate\Http\Request $request
  11. * @param \Closure $next
  12. * @return mixed
  13. */
  14. public function handle($request, Closure $next)
  15. {
  16. if($request->user()) {
  17. $user = $request->user();
  18. $enabled = (bool) $user->{'2fa_enabled'};
  19. if($enabled != false) {
  20. $checkpoint = 'i/auth/checkpoint';
  21. if($request->session()->has('2fa.session.active') !== true && !$request->is($checkpoint) && !$request->is('logout'))
  22. {
  23. return redirect('/i/auth/checkpoint');
  24. } elseif($request->session()->has('2fa.attempts') && (int) $request->session()->get('2fa.attempts') > 3) {
  25. $request->session()->pull('2fa.attempts');
  26. Auth::logout();
  27. }
  28. }
  29. }
  30. return $next($request);
  31. }
  32. }