Лимит попыток кода в Filament
Давайте ограничим число попыток. После нескольких ошибок подряд провайдер перестаёт принимать код на /admin/login.
Счётчик неверных вводов
храним в кеше по ключу
аккаунта. Правило в
PinAuthentication.php
смотрит лимит перед
сравнением кода:
<?php
namespace App\Filament\Auth;
use App\Models\User;
use Closure;
use Filament\Auth\MultiFactor\Contracts\MultiFactorAuthenticationProvider;
use Filament\Forms\Components\TextInput;
use Illuminate\Contracts\Auth\Authenticatable;
use Illuminate\Support\Facades\Cache;
use SensitiveParameter;
class PinAuthentication implements MultiFactorAuthenticationProvider
{
protected int $maxAttempts = 5;
public static function make(): static
{
return app(static::class);
}
public function getId(): string
{
return 'pin';
}
public function getLoginFormLabel(): string
{
return 'PIN';
}
public function isEnabled(Authenticatable $user): bool
{
if (! ($user instanceof User)) {
return false;
}
return (bool) $user->pin_enabled;
}
public function getManagementSchemaComponents(): array
{
return [
TextInput::make('pin_code')
->label('PIN code')
->password()
->numeric()
->required(),
];
}
public function getChallengeFormComponents(Authenticatable $user): array
{
return [
TextInput::make('code')
->label('PIN code')
->required()
->rule(fn (): Closure => function (string $attribute, #[SensitiveParameter] mixed $value, Closure $fail) use ($user): void {
if (! ($user instanceof User)) {
$fail('The PIN code is invalid.');
return;
}
$key = 'pin-mfa-failures:' . $user->getAuthIdentifier();
if ((int) Cache::get($key, 0) >= $this->maxAttempts) {
$fail('Too many attempts.');
return;
}
if (! hash_equals((string) $user->pin_code, (string) $value)) {
Cache::put($key, (int) Cache::get($key, 0) + 1, now()->addMinutes(15));
$fail('The PIN code is invalid.');
return;
}
Cache::forget($key);
}),
];
}
}
?>
Остановите вход после нескольких неверных кодов подряд.