mirror of
https://github.com/Icinga/icingaweb2.git
synced 2026-05-21 01:15:26 -04:00
Previously the `RememberMe` object (containing the AES-encrypted password and the decryption key) was serialized directly into the PHP session while waiting for the user to complete the 2FA challenge. Because PHP sessions are written to disk in plaintext, this exposed the key and ciphertext in the same place, sufficient to recover the user's password. Fix by splitting the secret across the session and the database, mirroring the design of the normal (non-2FA) remember-me flow: - Call `persist()` at login time so the AES key goes to the database immediately, never touching the session. - Store only the cookie value string (ciphertext + IV) in the session. The ciphertext is not exploitable without the key. - After a successful 2FA challenge, reconstruct the `RememberMe` object via a new `RememberMe::fromCookieData()` factory that does a DB lookup by IV and restores the canonical expiry from the database row. - Only then send the browser cookie, so the cookie never reaches the browser unless the second factor was verified. Canceled challenges remove the created DB row, while abandoned challenges leave an orphaned DB row which is cleaned up by the existing `RememberMe::removeExpired()` mechanism. `RememberMe::fromCookieData()` sets `$expiresAt` from the database row so the browser cookie issued after 2FA inherits the expiry stored at login time rather than receiving a fresh 30-day window computed at challenge-completion time. The renewal path in `AuthenticationController::loginAction()` is unaffected, because `renew()` constructs a new object via `fromCredentials()`. |
||
|---|---|---|
| .. | ||
| AboutController.php | ||
| AccountController.php | ||
| AnnouncementsController.php | ||
| ApplicationStateController.php | ||
| AuthenticationController.php | ||
| ConfigController.php | ||
| DashboardController.php | ||
| ErrorController.php | ||
| GroupController.php | ||
| HealthController.php | ||
| IframeController.php | ||
| IndexController.php | ||
| LayoutController.php | ||
| ListController.php | ||
| ManageUserDevicesController.php | ||
| MigrationsController.php | ||
| MyDevicesController.php | ||
| NavigationController.php | ||
| RoleController.php | ||
| SearchController.php | ||
| StaticController.php | ||
| TwoFactorController.php | ||
| UserController.php | ||
| UsergroupbackendController.php | ||