Extends security of drupal websites with 2-step phone code authentication using Android app Drulapp. This is done by splitting login screen in to two pages, one for login credentials and another for submitting code generated on phone. Code generation and Authentication is based on rfc6238 which will be valid for 30 seconds. (with one past "time step window". see the link for why it is needed).
Features
- Partially works offline. This is done by setting validity in days(just like Drupal core's cache validity). After validity expired Drulapp app must connect to website to get the updated buttons.
- All device id and user related information are hashed using Sha256 and Hex encoded.
- more details ....
sandbox project page:
https://www.drupal.org/sandbox/nithinkolekar/2856406
git clone command:
git clone --branch 7.x-1.x https://git.drupal.org/sandbox/nithinkolekar/2856406.git drulapp
code repository :
http://drupalcode.org/sandbox-nithinkolekar-2856406
For reviewers:
addition to the code review you must install above mentioned app(currently only android) to test complete functional task of this module.
Comments
Comment #2
jeetendrakumar commentedPlease fix following errors:
https://pareview.sh/node/1265
Comment #3
nithinkolekar commentedCorrected errors and added missing CSS file.
Comment #4
PA robot commentedThere are some errors reported by automated review tools, did you already check them? See http://pareview.sh/pareview/httpsgitdrupalorgsandboxnithinkolekar2856406git
We are currently quite busy with all the project applications and we prefer projects with a review bonus. Please help reviewing and put yourself on the high priority list, then we will take a look at your project right away :-)
Also, you should get your friends, colleagues or other community members involved to review this application. Let them go through the review checklist and post a comment that sets this issue to "needs work" (they found some problems with the project) or "reviewed & tested by the community" (they found no major flaws).
I'm a robot and this is an automated message from Project Applications Scraper.
Comment #5
nithinkolekar commentedAll errors and warning codes are corrected. Though some of the warning messages like param type is not necessary for d7, for ex
@param $accountas per the code in d7 core's user.module.Comment #6
khurram_awan commentedHello Mate,
Looks like you readme.txt is empty. please read Readme documentation and add readme.txt accordingly.
Thanks,
Khurram
Comment #7
yogesh kushwaha commentedHi nithinkolekar,
Below are my manual review
'page arguments' => array()line into yourhook_menuarray.Comment #8
PA robot commentedClosing due to lack of activity. If you are still working on this application, you should fix all known problems and then set the status to "Needs review". (See also the project application workflow).
I'm a robot and this is an automated message from Project Applications Scraper.
Comment #9
nithinkolekar commentedComment #10
joao sausen commentedModule looks good, but you don't need the drulapp.api.php file since there is nothing there. Also there is this $data['error_code'] = t("101"); on drulapp.pages.inc, you probably dont want that in a t().
Comment #11
lingros commentedAutomated Review
Without any issues.
Manual Review
The starred items (*) are fairly big issues and warrant going back to Needs Work. Items marked with a plus sign (+) are important and should be addressed before a stable project release. The rest of the comments in the code walkthrough are recommendations.
This review uses the Project Application Review Template.
Comment #12
lucif3rum commentedI have manually reviewed this project and see a few duplicate functions and also the readme file could be done better.
Comment #13
nithinkolekar commentedreviewer doesn't know anything about what that link is for . There are several blindfolded reviews in this project applications section by developers who desperately need to get their own project approved :(.
DA should add another status "Coding standard passed & Manual code review pending" (MCRP). So that only experienced user with security code review can further test the source code for any security vulnerability.
Comment #17
ajaygupta1139 commentedManual review :
Comment #18
avpadernoI am changing status basing on the last comment. To the reviewers: Please change the status value, when you are reporting something that needs to be corrected.
Comment #19
avpadernoIf you are still working on this application, you should fix all known problems and set the status to Needs review. (See also the project application workflow.)
Please don't change status of this application if you aren't sure you have time to dedicate to this application, or it will be closed again as won't fix.
I am closing this application due to lack of activity.