You are here

configure_qrcode_authentication.php in Google Authenticator / 2 Factor Authentication - 2FA 8

Same filename and directory in other branches
  1. 8.2 src/Form/configure_qrcode_authentication.php

File

src/Form/configure_qrcode_authentication.php
View source
<?php

namespace Drupal\miniorange_2fa\form;

use Drupal\user\Entity\User;
use Drupal\Core\Form\FormBase;
use Drupal\miniorange_2fa\MiniorangeUser;
use Drupal\miniorange_2fa\MoAuthConstants;
use Drupal\miniorange_2fa\UsersAPIHandler;
use Drupal\miniorange_2fa\MoAuthUtilities;
use Drupal\miniorange_2fa\AuthenticationType;
use Drupal\Component\Render\FormattableMarkup;
use Drupal\miniorange_2fa\AuthenticationAPIHandler;
use Drupal\miniorange_2fa\MiniorangeCustomerProfile;
class configure_qrcode_authentication extends FormBase {
  public function getFormId() {
    return 'mo_auth_configure_qrcode_authentication';
  }
  public function buildForm(array $form, \Drupal\Core\Form\FormStateInterface $form_state) {
    $form['markup_library'] = array(
      '#attached' => array(
        'library' => array(
          "miniorange_2fa/miniorange_2fa.admin",
          "miniorange_2fa/miniorange_2fa.license",
        ),
      ),
    );
    global $base_url;
    $url = $base_url . '/admin/config/people/miniorange_2fa/setup_twofactor';
    $input = $form_state
      ->getUserInput();
    $user = User::load(\Drupal::currentUser()
      ->id());
    $user_id = $user
      ->id();
    $utilities = new MoAuthUtilities();
    $custom_attribute = $utilities::get_users_custom_attribute($user_id);
    $form['actions'] = array(
      '#type' => 'actions',
    );

    /* To check which method (Soft Token, QR Code, Push Notification') is being configured by user
     * $authTypeCode:- Code of the authentication Type
     * $messageHeader:- Title of the Page
     */
    $query_param = \Drupal::service('path.current')
      ->getPath();
    $url_parts = explode('/', $query_param);
    $authTypeCode = '';
    $messageHeader = '';
    if (in_array("soft-token", $url_parts)) {
      $authTypeCode = AuthenticationType::$SOFT_TOKEN['code'];
      $messageHeader = 'Configure Soft Token';
    }
    elseif (in_array("push-notifications", $url_parts)) {
      $authTypeCode = AuthenticationType::$PUSH_NOTIFICATIONS['code'];
      $messageHeader = 'Configure Push Notifications';
    }
    else {
      $authTypeCode = AuthenticationType::$QR_CODE['code'];
      $messageHeader = 'Configure QR Code Authentication';
    }
    $androidAppLink = file_create_url($base_url . '/' . drupal_get_path('module', 'miniorange_2fa') . '/includes/images/android-google-authenticator-app-link.png');
    $iPhoneAppLink = file_create_url($base_url . '/' . drupal_get_path('module', 'miniorange_2fa') . '/includes/images/iphone-google-authenticator-app-link.png');
    $androidAppQR = file_create_url($base_url . '/' . drupal_get_path('module', 'miniorange_2fa') . '/includes/images/android-mo-authenticator-app-qr.jpg');
    $iPhoneAppQR = file_create_url($base_url . '/' . drupal_get_path('module', 'miniorange_2fa') . '/includes/images/iphone-mo-authenticator-app-qr.png');
    if (array_key_exists('txId', $input) === FALSE) {
      $user_email = $custom_attribute[0]->miniorange_registered_email;
      $customer = new MiniorangeCustomerProfile();
      $miniorange_user = new MiniorangeUser($customer
        ->getCustomerID(), $user_email, NULL, NULL, AuthenticationType::$QR_CODE['code']);
      $auth_api_handler = new AuthenticationAPIHandler($customer
        ->getCustomerID(), $customer
        ->getAPIKey());
      $response = $auth_api_handler
        ->register($miniorange_user, AuthenticationType::$QR_CODE['code'], NULL, NULL, NULL);
      $qrCode = isset($response->qrCode) ? $response->qrCode : '';
      $image = new FormattableMarkup('<img src="data:image/jpg;base64, ' . $qrCode . '"/>', [
        ':src' => $qrCode,
      ]);
      $form['markup_top_2'] = array(
        '#markup' => '<div class="mo_saml_table_layout_1"><div class="mo_saml_table_layout mo_saml_container">',
      );
      $form['header']['#markup'] = '<div class="mo2f-setup-header"><div class="mo2f-setup-header-top-left">' . $messageHeader . '</div></div><br>';

      //. $this->mo_auth_create_form($base_url, $qrCode);
      $form['actions_1'] = array(
        '#markup' => '
                    <div class="googleauth-steps"><b>Step 1:</b> Download & Install the miniOrange Authenticator app.
                      <br>
                      <div class="maindiv_1">
                          <div>
                              <div class="googleauth-download-header">Manual Installation</div>
                              <div class="subDivPosition"><br>
                                <h6>iPhone Users</h6>
                                <ul>
                                  <li>Go to App Store.</li>
                                  <li>Search for miniOrange.</li>
                                  <li>Download and install the app.<br> <b>(NOT MOAuth)</b></li>
                                </ul>
                                <a target="_blank" href="https://apps.apple.com/app/id1482362759"><img src="' . $iPhoneAppLink . '"></a>
                              </div>

                              <div><br>
                                <h6>Android Users</h6>
                                <ul>
                                  <li>Go to Google Play Store.</li>
                                  <li>Search for miniOrange.</li>
                                  <li>Download and install <b> Authenticator</b> app <br> <b>(NOT miniOrange Authenticator)</b></li>
                                </ul>
                                <div>
                                   <a target="_blank" href="https://play.google.com/store/apps/details?id=com.miniorange.android.authenticator"><img src="' . $androidAppLink . '"></a>
                                </div>
                              </div>
                          </div>
                      </div>
                      <br>
                      <br>
                      <h4 id="mo_2fa_config_option_or">OR</h4>

                      <br>
                      <div class="maindiv_2">

                          <div class="googleauth-download-header">Scan QR Code</div>

                            <div class="subDivPosition">
                              <div><br>
                                <img src="' . $iPhoneAppQR . '">
                              </div>
                              <span>Apple App Store <b>(iOS)</b></span>
                            </div>

                            <div>
                              <div><br>
                                <img src="' . $androidAppQR . '">
                              </div>
                              <span>Google Play Store <b>(Android)</b></span>
                            </div>
                        </div>
                      </div>
                ',
      );
      $form['actions_2'] = array(
        '#markup' => '<div></div><div class="googleauth-steps"><br><br><b>Step 2:</b> Scan the below QR Code from miniOrange Authenticator app.</div>
                        <br>',
      );
      $form['actions_qrcode'] = array(
        '#markup' => $image,
      );

      /* Accessed form mo_authentication.js file */
      $form['txId'] = array(
        '#type' => 'hidden',
        '#value' => $response->txId,
      );
      $form['url'] = array(
        '#type' => 'hidden',
        '#value' => MoAuthConstants::$AUTH_REGISTRATION_STATUS_API,
      );
      $form['authTypeCode'] = array(
        '#type' => 'hidden',
        '#value' => $authTypeCode,
      );
    }
    $form['actions_submit'] = array(
      '#type' => 'submit',
      '#value' => t('s'),
      //Save
      '#attributes' => array(
        'class' => array(
          'hidebutton',
        ),
      ),
    );
    $form['actions_cancel'] = array(
      '#markup' => '&emsp;&emsp;&emsp; <a href=" ' . $url . ' ">Cancel</a>',
      '#suffix' => '</div>',
      '#prefix' => '<br><br>',
    );
    MoAuthUtilities::AddsupportTab($form, $form_state);
    return $form;
  }
  public function submitForm(array &$form, \Drupal\Core\Form\FormStateInterface $form_state) {
    $form_state
      ->setRebuild();
    $input = $form_state
      ->getUserInput();
    $txId = $input['txId'];
    $authTypeCode = $input['authTypeCode'];
    $user = User::load(\Drupal::currentUser()
      ->id());
    $user_id = $user
      ->id();
    $utilities = new MoAuthUtilities();
    $custom_attribute = $utilities::get_users_custom_attribute($user_id);
    $user_email = $custom_attribute[0]->miniorange_registered_email;
    $customer = new MiniorangeCustomerProfile();
    $miniorange_user = new MiniorangeUser($customer
      ->getCustomerID(), $user_email, NULL, NULL, AuthenticationType::$QR_CODE['code']);
    $auth_api_handler = new AuthenticationAPIHandler($customer
      ->getCustomerID(), $customer
      ->getAPIKey());
    $response = $auth_api_handler
      ->getRegistrationStatus($txId);

    // Clear all the messages
    \Drupal::messenger()
      ->deleteAll();

    // read API response
    if ($response->status == 'SUCCESS') {
      $configured_methods = MoAuthUtilities::mo_auth_get_configured_methods($user_id);

      /* If one of the methods in Soft Token, QR Code Authentication, Push Notification is configured then all three methods are configured.*/
      if (!in_array(AuthenticationType::$SOFT_TOKEN['code'], $configured_methods)) {
        array_push($configured_methods, AuthenticationType::$SOFT_TOKEN['code']);
      }
      if (!in_array(AuthenticationType::$QR_CODE['code'], $configured_methods)) {
        array_push($configured_methods, AuthenticationType::$QR_CODE['code']);
      }
      if (!in_array(AuthenticationType::$PUSH_NOTIFICATIONS['code'], $configured_methods)) {
        array_push($configured_methods, AuthenticationType::$PUSH_NOTIFICATIONS['code']);
      }
      $config_methods = implode(', ', $configured_methods);
      $user_api_handler = new UsersAPIHandler($customer
        ->getCustomerID(), $customer
        ->getAPIKey());

      // Updating the authentication method for the user
      $miniorange_user
        ->setAuthType($authTypeCode);
      $response = $user_api_handler
        ->update($miniorange_user);
      if ($response->status == 'SUCCESS') {

        // Save user
        $user_id = $user
          ->id();
        $utilities = new MoAuthUtilities();
        $available = $utilities::check_for_userID($user_id);
        $database = \Drupal::database();
        if ($available == TRUE) {
          $database
            ->update('UserAuthenticationType')
            ->fields([
            'configured_auth_methods' => $config_methods,
          ])
            ->condition('uid', $user_id, '=')
            ->execute();
          $database
            ->update('UserAuthenticationType')
            ->fields([
            'activated_auth_methods' => $authTypeCode,
          ])
            ->condition('uid', $user_id, '=')
            ->execute();
        }
        else {
          echo "error while saving authentication method.";
          exit;
        }
        if ($authTypeCode == AuthenticationType::$SOFT_TOKEN['code']) {
          $message = 'Soft Token configured successfully.';
        }
        elseif ($authTypeCode == AuthenticationType::$PUSH_NOTIFICATIONS['code']) {
          $message = 'Push Notifications configured successfully.';
        }
        else {
          $message = 'QR Code Authentication configured successfully.';
        }
        MoAuthUtilities::show_error_or_success_message($message, 'status');
      }
      return;
    }
    $message = 'An error occured while processing your request. Please try again.';
    MoAuthUtilities::show_error_or_success_message($message, 'error');
  }

}