mirror of
https://github.com/maybe-finance/maybe.git
synced 2025-07-24 15:49:39 +02:00
Multi-factor authentication (#1817)
* Initial pass * Tests for MFA and locale cleanup * Brakeman * Update two-factor authentication status styling * Update app/models/user.rb Co-authored-by: Zach Gollwitzer <zach@maybe.co> Signed-off-by: Josh Pigford <josh@joshpigford.com> * Refactor MFA verification and session handling in tests --------- Signed-off-by: Josh Pigford <josh@joshpigford.com> Co-authored-by: Zach Gollwitzer <zach@maybe.co>
This commit is contained in:
parent
7ba9063e04
commit
842e37658c
29 changed files with 598 additions and 33 deletions
20
app/helpers/mfa_helper.rb
Normal file
20
app/helpers/mfa_helper.rb
Normal file
|
@ -0,0 +1,20 @@
|
|||
module MfaHelper
|
||||
def generate_mfa_qr_code(provisioning_uri)
|
||||
qr_code = RQRCode::QRCode.new(provisioning_uri).as_svg(
|
||||
color: "141414",
|
||||
module_size: 4,
|
||||
standalone: true,
|
||||
use_path: true,
|
||||
svg_attributes: {
|
||||
width: "228",
|
||||
height: "228",
|
||||
viewBox: "0 0 57 57"
|
||||
}
|
||||
)
|
||||
|
||||
# Whitelist specific SVG attributes and elements that we know are safe
|
||||
sanitize qr_code,
|
||||
tags: %w[svg g path rect],
|
||||
attributes: %w[viewBox height width fill stroke stroke-width d x y class]
|
||||
end
|
||||
end
|
Loading…
Add table
Add a link
Reference in a new issue