HEX
Server: LiteSpeed
System: Linux d8 4.18.0-553.121.1.lve.el8.x86_64 #1 SMP Thu Apr 30 16:40:41 UTC 2026 x86_64
User: wbwebdes (3015)
PHP: 8.1.31
Disabled: exec,system,passthru,shell_exec,proc_close,proc_open,dl,popen,show_source,posix_kill,posix_mkfifo,posix_getpwuid,posix_setpgid,posix_setsid,posix_setuid,posix_setgid,posix_seteuid,posix_setegid,posix_uname
Upload Files
File: /home/wbwebdes/domains/files.wb-cloud.nl/public_html/core/Controller/TwoFactorApiController.php
<?php

declare(strict_types=1);
/**
 * SPDX-FileCopyrightText: 2024 Nextcloud GmbH and Nextcloud contributors
 * SPDX-License-Identifier: AGPL-3.0-or-later
 */

namespace OC\Core\Controller;

use OC\Authentication\TwoFactorAuth\ProviderManager;
use OCP\AppFramework\Http;
use OCP\AppFramework\Http\Attribute\ApiRoute;
use OCP\AppFramework\Http\DataResponse;
use OCP\AppFramework\OCSController;
use OCP\Authentication\TwoFactorAuth\IRegistry;
use OCP\IRequest;
use OCP\IUserManager;

class TwoFactorApiController extends OCSController {
	public function __construct(
		string $appName,
		IRequest $request,
		private ProviderManager $tfManager,
		private IRegistry $tfRegistry,
		private IUserManager $userManager,
	) {
		parent::__construct($appName, $request);
	}

	/**
	 * Get two factor authentication provider states
	 *
	 * @param string $user system user id
	 *
	 * @return DataResponse<Http::STATUS_OK, array<string, bool>, array{}>|DataResponse<Http::STATUS_NOT_FOUND, null, array{}>
	 *
	 * 200: provider states
	 * 404: user not found
	 */
	#[ApiRoute(verb: 'GET', url: '/state', root: '/twofactor')]
	public function state(string $user): DataResponse {
		$userObject = $this->userManager->get($user);
		if ($userObject !== null) {
			$state = $this->tfRegistry->getProviderStates($userObject);
			return new DataResponse($state);
		}
		return new DataResponse(null, Http::STATUS_NOT_FOUND);
	}

	/**
	 * Enable two factor authentication providers for specific user
	 *
	 * @param string $user system user identifier
	 * @param list<string> $providers collection of TFA provider ids
	 *
	 * @return DataResponse<Http::STATUS_OK, array<string, bool>, array{}>|DataResponse<Http::STATUS_NOT_FOUND, null, array{}>
	 *
	 * 200: provider states
	 * 404: user not found
	 */
	#[ApiRoute(verb: 'POST', url: '/enable', root: '/twofactor')]
	public function enable(string $user, array $providers = []): DataResponse {
		$userObject = $this->userManager->get($user);
		if ($userObject !== null) {
			foreach ($providers as $providerId) {
				$this->tfManager->tryEnableProviderFor($providerId, $userObject);
			}
			$state = $this->tfRegistry->getProviderStates($userObject);
			return new DataResponse($state);
		}
		return new DataResponse(null, Http::STATUS_NOT_FOUND);
	}

	/**
	 * Disable two factor authentication providers for specific user
	 *
	 * @param string $user system user identifier
	 * @param list<string> $providers collection of TFA provider ids
	 *
	 * @return DataResponse<Http::STATUS_OK, array<string, bool>, array{}>|DataResponse<Http::STATUS_NOT_FOUND, null, array{}>
	 *
	 * 200: provider states
	 * 404: user not found
	 */
	#[ApiRoute(verb: 'POST', url: '/disable', root: '/twofactor')]
	public function disable(string $user, array $providers = []): DataResponse {
		$userObject = $this->userManager->get($user);
		if ($userObject !== null) {
			foreach ($providers as $providerId) {
				$this->tfManager->tryDisableProviderFor($providerId, $userObject);
			}
			$state = $this->tfRegistry->getProviderStates($userObject);
			return new DataResponse($state);
		}
		return new DataResponse(null, Http::STATUS_NOT_FOUND);
	}

}