On a Symfony 5 project, I have a User entity with both fields "password" (hashed) and "smsCode" (plain).
When creating an account, the smsCode is used for authentication at first, until the user later sets a password (and then we use the password when not empty and ignore the smsCode).
What I'm trying to achieve: Authentication through HTTP Basic, but using the smsCode instead of the hashed password.
I managed to make this work using the form login by editing the checkCredentials() function on my LoginFormAuthenticator: I can login through the form using my SMS code instead of my password.
But when I try to authenticate through HTTP Basic, the checkAuthentication() function on DaoAuthenticationProvider.php is called, and this class fetches the password using $user->getPassword(). Is there any way I can overwrite / extend this checkAuthentication() function, so that I can first check the plain smsCode ($user->getSmsCode()) instead of the hashed password ?
#security:
encoders:
App\Entity\User:
algorithm: auto
providers:
# used to reload user from session & other features (e.g. switch_user)
app_user_provider:
entity:
class: App\Entity\User
property: email
firewalls:
dev:
# profiler (dev only)
pattern: ^/(_(profiler|wdt)|css|images|js)/
security: false
main:
anonymous: true
lazy: true
provider: app_user_provider
http_basic: true
guard:
authenticators:
- App\Security\LoginFormAuthenticator
logout:
path: app_logout
I tried to edit my getPassword() function to check the smsCode first :
public function getPassword(): string
{
if (!empty($this->smsCode)) {
return (string) $this->smsCode;
} else {
return (string) $this->password;
}
}
Unfortunately, since the password is hashed, it keeps failing at authentication since it's looking for a hashed version of the smsCode (the function isPasswordValid() in DaoAuthenticationProvider.php)
(The authentication works perfectly when giving the password instead of SMS code by the way)