Проверка цифрового кода в Filament
Давайте примем код перед проверкой. Введённое значение сравнивают с тем, что лежит на модели, на /admin/login.
Правило на поле входа
в getChallengeFormComponents
отклоняет неверный код.
Обновим
PinAuthentication.php:
<?php
namespace App\Filament\Auth;
use App\Models\User;
use Closure;
use Filament\Auth\MultiFactor\Contracts\MultiFactorAuthenticationProvider;
use Filament\Forms\Components\TextInput;
use Illuminate\Contracts\Auth\Authenticatable;
use SensitiveParameter;
class PinAuthentication implements MultiFactorAuthenticationProvider
{
public static function make(): static
{
return app(static::class);
}
public function getId(): string
{
return 'pin';
}
public function getLoginFormLabel(): string
{
return 'PIN';
}
public function isEnabled(Authenticatable $user): bool
{
if (! ($user instanceof User)) {
return false;
}
return (bool) $user->pin_enabled;
}
public function getManagementSchemaComponents(): array
{
return [
TextInput::make('pin_code')
->label('PIN code')
->password()
->numeric()
->required(),
];
}
public function getChallengeFormComponents(Authenticatable $user): array
{
return [
TextInput::make('code')
->label('PIN code')
->required()
->rule(fn (): Closure => function (string $attribute, #[SensitiveParameter] mixed $value, Closure $fail) use ($user): void {
if (! ($user instanceof User)) {
$fail('The PIN code is invalid.');
return;
}
if (! hash_equals((string) $user->pin_code, (string) $value)) {
$fail('The PIN code is invalid.');
}
}),
];
}
}
?>
Пускайте в панель только тот код, который работник задал сам.