'disabled', '$OC_pcemail' => 'Chair Email Address: ' . $OC_configAR['OC_pcemail'], '$OC_confirmmail' => 'Notification Address: ' . $OC_configAR['OC_confirmmail'] ); if (!empty($OC_configAR['OC_chairMFA']) && !isset($mfaAddresses[$OC_configAR['OC_chairMFA']]) && validEmail($OC_configAR['OC_chairMFA'])) { $mfaAddresses[$OC_configAR['OC_chairMFA']] = $OC_configAR['OC_chairMFA']; } // setup mfa? if (isset($_GET['a']) && ($_GET['a'] == 'mfasetup')) { if ( isset($_GET['c']) && (strlen($_GET['c']) == 32) && preg_match("/^SETUP\|\|([^\|]+)\|\|([^\|]+)$/", $OC_configAR['OC_chairMFAcode'], $matches) && ($_GET['c'] == $matches[1]) && isset($mfaAddresses[$matches[2]]) ) { updateConfigSetting('OC_chairMFA', $matches[2]) or err('Unable to configure authentication address'); $OC_configAR['OC_chairMFA'] = $matches[2]; updateConfigSetting('OC_chairMFAcode', ''); print '
Authentication Address Set
'; } else { print 'Authentication Address verification failed
'; } printFooter(); exit; } $e = ""; if (isset($_POST['submit']) && ($_POST['submit'] == "Submit Changes")) { // Check for valid submission if (!validToken('chair')) { warn('Invalid submission'); } if (!oc_password_verify($_POST['currpwd'], $OC_configAR['OC_chair_pwd'])) { $e = 'Current password is incorrect'; } else { // password change? if (isset($_POST['pwd1']) && !empty($_POST['pwd1']) && isset($_POST['pwd2']) && !empty($_POST['pwd2'])) { if ($_POST['pwd1'] != $_POST['pwd2']) { $e = 'New passwords do not match'; } elseif ($_POST['pwd1'] == $OC_configAR['OC_chair_uname']) { $e = 'Password may not match ' . OCC_WORD_CHAIR . ' username'; } elseif (oc_strlen($_POST['pwd1']) < 10) { $e = 'Password must be 10+ characters long'; } else { updateConfigSetting('OC_chair_pwd', oc_password_hash($_POST['pwd1'])) or err('Unable to change password'); print 'Password has been changed
'; } } // auth change? if (isset($_POST['mfa']) && isset($mfaAddresses[$_POST['mfa']]) && ($_POST['mfa'] != $OC_configAR['OC_chairMFA'])) { if ($_POST['mfa'] == '') { updateConfigSetting('OC_chairMFA', '') or err('Unable to remove authentication address'); $OC_configAR['OC_chairMFA'] = ''; } elseif (preg_match("/^\\\$(?:OC_pcemail|OC_confirmmail)$/", $_POST['mfa'])) { $code = oc_idGen(32); $link = OCC_BASE_URL . 'chair/set_password.php?a=mfasetup&c=' . urlencode($code); if (strlen($code) == 32) { ocsql_query("UPDATE `" . OCC_TABLE_CONFIG . "` SET `value`='SETUP||" . safeHTMLstr($code) . '||' . safeHTMLstr($_POST['mfa']) . "' WHERE `module`='OC' AND `setting`='OC_chairMFAcode' LIMIT 1") or err('Unable to set authentication code'); $subject = $OC_configAR['OC_confName'] . ' Multi-Factor Authentication Setup -- action required'; $body = 'Hello, A request has been received to setup multi-factor authentication for the ' . $OC_configAR['OC_confName'] . ' ' . OCC_WORD_CHAIR . ' account. In order to complete the request, please click the link below prior to signing out of the account: ' . $link . ' Thank you '; if (oc_mail($OC_configAR[substr($_POST['mfa'], 1)], $subject, $body)) { print 'An email has been sent to the Authentication Address below.
Click the link in the email prior to signing out.
' . $e . '
'; } print '