namespace App\Http\Controllers;
use App\Exports\BladeExport;
use App\Http\Controllers\Controller;
use App\Models\User;
use Auth;
use DB;
use Excel;
use Hash;
use Illuminate\Http\Request;
use Illuminate\Support\Arr;
use Response;
use Session;
use Spatie\Permission\Models\Role;
class TwofactorController extends Controller
* Display a listing of the resource.
* @return \Illuminate\Http\Response
public function __construct()
public function index(Request $request){
// echo 'hi';die;
$user = Auth::user();
$data = array();
$secret = $this->createSecret();
Session::put('tfa_uid', $user->id);
Session::put('two_factor', $user->enable_tfa);
Session::put('tfa_enabled_secret', $secret);
$url= $this->getQRCodeGoogleUrl($user->email, $secret,$user->account_name);
Session::put('tfa_enabled_secret_url', $url);
if($user->enable_tfa != 1){
$auth_code = array('google_auth_code'=>$secret,'google_authentication_url'=>$url);
$data['enable_tfa'] = $user->enable_tfa;
$data['qrCodeUrl'] = $url;
// echo '<pre>';print_r($user);die;
return view('two_factor.index', compact('data'));
public function saveData(Request $request){
// echo '<pre>';print_r($request->all());die;
$this->validate($request, [
'code' => 'required'
$google_auth_code = Auth::user()->google_auth_code;
$enable_tfa = Auth::user()->enable_tfa;
$user_id = Auth::user()->id;
$checkResult = $this->verifyCode($google_auth_code, $request->code, 2);
if($enable_tfa == 1){
$upd = array('enable_tfa' => 2);
return redirect()->back()->with('success', 'Two factor authentication is disabled');
$upd = array('enable_tfa' =>1);
return redirect()->back()->with('success', 'Two factor authentication is enabled');
return redirect()->back()->with('error', 'Two factor code is not vaild');
// print_r($checkResult);
protected $_codeLength = 6;
public function createSecret($secretLength = 16){
$validChars = $this->_getBase32LookupTable();
$secret = '';
for ($i = 0; $i < $secretLength; $i++) {
$secret .= $validChars[array_rand($validChars)];
return $secret;
public function getCode($secret, $timeSlice = null){
if ($timeSlice === null) {
$timeSlice = floor(time() / 30);
$secretkey = $this->_base32Decode($secret);
// Pack time into binary string
$time = chr(0).chr(0).chr(0).chr(0).pack('N*', $timeSlice);
// Hash it with users secret key
$hm = hash_hmac('SHA1', $time, $secretkey, true);
// Use last nipple of result as index/offset
$offset = ord(substr($hm, -1)) & 0x0F;
// grab 4 bytes of the result
$hashpart = substr($hm, $offset, 4);
// Unpak binary value
$value = unpack('N', $hashpart);
$value = $value[1];
// Only 32 bits
$value = $value & 0x7FFFFFFF;
$modulo = pow(10, $this->_codeLength);
return str_pad($value % $modulo, $this->_codeLength, '0', STR_PAD_LEFT);
public function getQRCodeGoogleUrl($name, $secret, $title = null) {
$urlencoded = urlencode('otpauth://totp/'.$name.'?secret='.$secret.'');
if(isset($title)) {
$urlencoded .= urlencode('&issuer='.urlencode($title));
return 'https://chart.googleapis.com/chart?chs=200x200&chld=M|0&cht=qr&chl='.$urlencoded.'';
public function verifyCode($secret, $code, $discrepancy = 1, $currentTimeSlice = null){
if ($currentTimeSlice === null) {
$currentTimeSlice = floor(time() / 30);
for ($i = -$discrepancy; $i <= $discrepancy; $i++) {
$calculatedCode = $this->getCode($secret, $currentTimeSlice + $i);
if ($calculatedCode == $code ) {
return true;
return false;
public function setCodeLength($length){
$this->_codeLength = $length;
return $this;
protected function _base32Decode($secret){
if (empty($secret)) return '';
$base32chars = $this->_getBase32LookupTable();
$base32charsFlipped = array_flip($base32chars);
$paddingCharCount = substr_count($secret, $base32chars[32]);
$allowedValues = array(6, 4, 3, 1, 0);
if (!in_array($paddingCharCount, $allowedValues)) return false;
for ($i = 0; $i < 4; $i++){
if ($paddingCharCount == $allowedValues[$i] &&
substr($secret, -($allowedValues[$i])) != str_repeat($base32chars[32], $allowedValues[$i])) return false;
$secret = str_replace('=','', $secret);
$secret = str_split($secret);
$binaryString = "";
for ($i = 0; $i < count($secret); $i = $i+8) {
$x = "";
if (!in_array($secret[$i], $base32chars)) return false;
for ($j = 0; $j < 8; $j++) {
$x .= str_pad(base_convert(@$base32charsFlipped[@$secret[$i + $j]], 10, 2), 5, '0', STR_PAD_LEFT);
$eightBits = str_split($x, 8);
for ($z = 0; $z < count($eightBits); $z++) {
$binaryString .= ( ($y = chr(base_convert($eightBits[$z], 2, 10))) || ord($y) == 48 ) ? $y:"";
return $binaryString;
protected function _base32Encode($secret, $padding = true){
if (empty($secret)) return '';
$base32chars = $this->_getBase32LookupTable();
$secret = str_split($secret);
$binaryString = "";
for ($i = 0; $i < count($secret); $i++) {
$binaryString .= str_pad(base_convert(ord($secret[$i]), 10, 2), 8, '0', STR_PAD_LEFT);
$fiveBitBinaryArray = str_split($binaryString, 5);
$base32 = "";
$i = 0;
while ($i < count($fiveBitBinaryArray)) {
$base32 .= $base32chars[base_convert(str_pad($fiveBitBinaryArray[$i], 5, '0'), 2, 10)];
if ($padding && ($x = strlen($binaryString) % 40) != 0) {
if ($x == 8) $base32 .= str_repeat($base32chars[32], 6);
elseif ($x == 16) $base32 .= str_repeat($base32chars[32], 4);
elseif ($x == 24) $base32 .= str_repeat($base32chars[32], 3);
elseif ($x == 32) $base32 .= $base32chars[32];
return $base32;
protected function _getBase32LookupTable(){
return array(
'A', 'B', 'C', 'D', 'E', 'F', 'G', 'H', // 7
'I', 'J', 'K', 'L', 'M', 'N', 'O', 'P', // 15
'Q', 'R', 'S', 'T', 'U', 'V', 'W', 'X', // 23
'Y', 'Z', '2', '3', '4', '5', '6', '7', // 31
'=' // padding char