diff --git a/install/sql/incremental/upd_dev_collection.sql b/install/sql/incremental/upd_dev_collection.sql index c79ab4c5fbe1da5e6956578614c707120eacbc99..11dc8ff2f19019cb08605480c1a69693aa3f9520 100644 --- a/install/sql/incremental/upd_dev_collection.sql +++ b/install/sql/incremental/upd_dev_collection.sql @@ -1 +1 @@ -ALTER TABLE `sys_user` ADD `otp_enabled` SET('n', 'y','v') NOT NULL DEFAULT 'n' COMMENT 'v=waiting for validation of the chosen otp method' AFTER `lost_password_reqtime`, ADD `otp_type` SET('email') NOT NULL DEFAULT 'email' AFTER `otp_enabled`, ADD `otp_data` VARCHAR(255) NULL AFTER `otp_type`, ADD `otp_recovery` VARCHAR(64) NULL AFTER `otp_data`, ADD `otp_attempts` TINYINT NOT NULL DEFAULT '0' AFTER `otp_recovery`; +ALTER TABLE `sys_user` ADD `otp_type` SET('email') NOT NULL DEFAULT 'email' AFTER `otp_enabled`, ADD `otp_data` VARCHAR(255) NULL AFTER `otp_type`, ADD `otp_recovery` VARCHAR(64) NULL AFTER `otp_data`, ADD `otp_attempts` TINYINT NOT NULL DEFAULT '0' AFTER `otp_recovery`; diff --git a/install/sql/ispconfig3.sql b/install/sql/ispconfig3.sql index 182f788f55b7ef35fccabc486150dcca9681026d..3c840bae1d812ede090ceb3a06a3b2c9ede10e56 100644 --- a/install/sql/ispconfig3.sql +++ b/install/sql/ispconfig3.sql @@ -1842,7 +1842,6 @@ CREATE TABLE `sys_user` ( `lost_password_function` tinyint(1) NOT NULL default '1', `lost_password_hash` VARCHAR(50) NOT NULL default '', `lost_password_reqtime` DATETIME NULL default NULL, - `otp_enabled` set('n','y','v') NOT NULL DEFAULT 'n', `otp_type` set('email') NOT NULL DEFAULT 'email', `otp_data` varchar(255) DEFAULT NULL, `otp_recovery` varchar(64) DEFAULT NULL, diff --git a/interface/web/login/index.php b/interface/web/login/index.php index ad08c92a7942f618756bd744dc0b43e9894b2985..a595d9e2b8682708e53013fef91a0c437f498471 100644 --- a/interface/web/login/index.php +++ b/interface/web/login/index.php @@ -138,7 +138,7 @@ function process_login_request(app $app, &$error, $conf, $module) } else { //* Do 2FA authentication - if($user['otp_enabled'] == 'y') { + if($user['otp_type'] != 'none') { //* Save session in pending state and destroy original session $_SESSION['s_pending'] = $_SESSION['s'];