uthmandev/swift2fa 问题修复 & 功能扩展

解决BUG、新增功能、兼容多环境部署,快速响应你的开发需求

邮箱:yvsm@zunyunkeji.com | QQ:316430983 | 微信:yvsm316

uthmandev/swift2fa

Composer 安装命令:

composer require uthmandev/swift2fa

包简介

A secure and easy way to implement Two-Factor Authentication (2FA) with PHP. This library provides an easy-to-use solution for integrating 2FA into your applications, including QR code generation, token verification, and secret key management.

README 文档

README

SWIFT2FA

Easy and Secure 2-Factor Authentication

Latest Release Tests Passed License

Overview

Swift2FA is a secure and easy-to-use PHP library for implementing two-factor authentication. It supports various authentication methods, including:

  • Authenticator apps (Google Authenticator and others)
  • Email authentication via SMTP with PHPMailer
  • SMS-based authentication using services like Twilio

Key Features

  • Simple integration process
  • High-security standards
  • Multiple authentication methods
  • Built-in encryption for secret keys
  • QR code generation
  • Flexible time-step settings
  • Email and SMS delivery options

Installation

composer require uthmandev/swift2fa

Usage Guide

Basic Setup

use Swift2FA\Swift2FA;

$swift2fa = new Swift2FA();

Key Management

  1. Encrypting Keys
// Generate and encrypt a new secret key
$encryptedKey = $swift2fa->encryptKey();
  1. Decrypting Keys
// Decrypt a stored encrypted key
$decryptedKey = $swift2fa->decryptKey($encryptedKey);

TOTP Operations

  1. Generating TOTP
// Generate a time-based one-time password
$totpCode = $swift2fa->generateTOTP($secret, $timeStep = 30, $codeLength = 6);
  1. Validating TOTP
// Validate a user-provided TOTP code
$isValid = $swift2fa->TOTPValidate($userInput, $secret);

QR Code Generation

// Generate a QR code for authenticator apps
$qrCode = $swift2fa->generateQR($userEmail, $decryptedSecret);

Authentication Link Generation

// Generate an otpauth:// link
$authLink = $swift2fa->generatelink($userEmail, $decryptedSecret);

Sending Authentication Codes

  1. Via Email
// Send TOTP via email
$swift2fa->Mail(
    mailType: 'SMTP',
    email: 'user@example.com',
    message: 'Your authentication code is: ' . $totpCode,
    name: 'User Name',
    subject: 'Authentication Code'
);
  1. Via SMS
// Send TOTP via SMS
$swift2fa->SMS(
    phoneNumber: '+1234567890',
    messageBody: 'Your authentication code is: ' . $totpCode,
    name: 'User Name'
);

Configuration

Environment Variables

Create a .env file with the following configurations:

# General Settings
APP_NAME=your_app_name
ENCRYPTION_KEY=your_secure_encryption_key

# Email (SMTP) Settings
HOST=smtp.gmail.com
USER_NAME=your_email@gmail.com
PASSWORD=your_gmail_app_password
PORT=465
SMTP_SECURE=ssl

# SMS (Twilio) Settings
TWILIO_SID=your_twilio_sid
TWILIO_AUTH_TOKEN=your_twilio_auth_token
TWILIO_PHONE_NUMBER=your_twilio_phone_number

Important Notes

  1. Security

    • Store encryption keys securely
    • Restrict access to environment files
    • Use HTTPS for all authentication operations
  2. TOTP Validation

    • Standard time step is 30 seconds
    • Email TOTP might require longer time steps (e.g., 120 seconds)
    • QR codes should be the primary method for adding TOTP to authenticator apps
  3. Authentication Links

    • otpauth:// links won't work in browsers
    • Use QR codes for adding to authenticator apps

Contributing

Contributions are welcome! To contribute:

  1. Fork the repository
  2. Create your feature branch (git checkout -b feature/amazing-feature)
  3. Commit your changes (git commit -m 'Add amazing feature')
  4. Push to the branch (git push origin feature/amazing-feature)
  5. Open a Pull Request

License

This project is licensed under the MIT License - see the LICENSE file for details.

Contact

If you find this project useful, please consider giving it a ⭐ star on GitHub!

uthmandev/swift2fa 适用场景与选型建议

uthmandev/swift2fa 是一款 基于 PHP 开发的 Composer 扩展包,目前已累计 2 次下载、GitHub Stars 达 5, 最近一次更新时间为 2024 年 11 月 25 日, 在 PHP 生态内属于活跃度较高的组件。

它主要适用于以下技术方向: 「php」 「security」 「Authentication」 「qr code」 「2fa」 「Two-factor Authentication」 等业务场景。在实际项目中,围绕这些方向常见需要落地的问题包括:接口对接、性能调优、并发安全、与既有框架(Laravel / ThinkPHP / Yii / Webman 等)的兼容适配,以及生产环境的日志埋点与稳定性保障。

我们在过去多个企业项目中使用过 uthmandev/swift2fa 或与其功能相近的方案,如果你在选型或落地过程中遇到问题,例如 版本兼容、二次改造、私有化封装、与内部系统对接、生产 BUG 排查,欢迎联系我们协助评估。

围绕 uthmandev/swift2fa 我们能提供哪些服务?
定制开发 / 二次开发

基于 uthmandev/swift2fa 在你已有业务上做功能扩展、字段裁剪、UI 适配、与内部账号 / 权限 / 日志系统的深度对接。

BUG 修复 & 性能优化

线上偶发问题、内存泄漏、慢查询、并发异常等排查修复;针对高流量场景做缓存、队列、索引层面的调优。

项目外包 & 长期维护

承接完整的项目从需求 → 设计 → 开发 → 上线 → 长期运维;也可按月提供技术保姆服务。

yvsm@zunyunkeji.com QQ:316430983 微信:yvsm316 西安尊云信息科技 · 专注 PHP / Go / 分布式系统研发

统计信息

  • 总下载量: 2
  • 月度下载量: 0
  • 日度下载量: 0
  • 收藏数: 5
  • 点击次数: 13
  • 依赖项目数: 0
  • 推荐数: 0

GitHub 信息

  • Stars: 5
  • Watchers: 1
  • Forks: 1
  • 开发语言: PHP

其他信息

  • 授权协议: MIT
  • 更新时间: 2024-11-25