using Amazon.AspNetCore.Identity.Cognito; using Amazon.Extensions.CognitoAuthentication; using Microsoft.AspNetCore.Authorization; using Microsoft.AspNetCore.Identity; using Microsoft.AspNetCore.Mvc; using Microsoft.AspNetCore.Mvc.RazorPages; using Microsoft.Extensions.Logging; using System; using System.ComponentModel.DataAnnotations; using System.Threading.Tasks; namespace Samples.Areas.Identity.Pages.Account { [AllowAnonymous] public class LoginWith2faModel : PageModel { private readonly CognitoSignInManager _signInManager; private readonly ILogger _logger; public LoginWith2faModel(SignInManager signInManager, ILogger logger) { _signInManager = signInManager as CognitoSignInManager; _logger = logger; } [BindProperty] public InputModel Input { get; set; } public bool RememberMe { get; set; } public string ReturnUrl { get; set; } public class InputModel { [Required] [StringLength(7, ErrorMessage = "The {0} must be at least {2} and at max {1} characters long.", MinimumLength = 6)] [DataType(DataType.Text)] [Display(Name = "2FA code")] public string TwoFactorCode { get; set; } [Display(Name = "Remember this machine")] public bool RememberMachine { get; set; } } public async Task OnGetAsync(bool rememberMe, string returnUrl = null) { // Ensure the user has gone through the username & password screen first var user = await _signInManager.GetTwoFactorAuthenticationUserAsync(); if (user == null) { throw new InvalidOperationException($"Unable to load two-factor authentication user."); } ReturnUrl = returnUrl; RememberMe = rememberMe; return Page(); } public async Task OnPostAsync(bool rememberMe, string returnUrl = null) { if (!ModelState.IsValid) { return Page(); } returnUrl = returnUrl ?? Url.Content("~/"); var user = await _signInManager.GetTwoFactorAuthenticationUserAsync(); if (user == null) { throw new InvalidOperationException($"Unable to load two-factor authentication user."); } var authenticatorCode = Input.TwoFactorCode.Replace(" ", string.Empty).Replace("-", string.Empty); var result = await _signInManager.RespondToTwoFactorChallengeAsync(authenticatorCode, rememberMe, Input.RememberMachine); if (result.Succeeded) { _logger.LogInformation("User with ID '{UserId}' logged in with 2fa.", user.UserID); return LocalRedirect(returnUrl); } else { _logger.LogWarning("Invalid 2FA code entered for user with ID '{UserId}'.", user.UserID); ModelState.AddModelError(string.Empty, "Invalid 2FA code."); return Page(); } } } }