// consider scrapping this
$token = $this->internalGetData($username);
$token["tokenkey"] = $key;
- $this->internalPutData($username, $token);
+ $this->internalPutData($username, $token);
+
+ // TODO error checking
+ return true;
}
switch($ttype) {
case "HOTP":
error_log("in hotp");
- $st = $tlid;
+ $st = $tlid+1;
$en = $tlid+$this->hotpSkew;
for($i=$st; $i<$en; $i++) {
$stest = $this->oath_hotp($tkey, $i);
$data = $this->internalGetData($user);
$toktype = $data["tokentype"];
$key = $this->helperhex2b32($data["tokenkey"]);
- $counter = $data["tokencounter"];
+
+ // token counter should be one more then current token value, otherwise
+ // it gets confused
+ $counter = $data["tokencounter"]+1;
$toktype = strtolower($toktype);
if($toktype == "hotp") {
$url = "otpauth://$toktype/$user?secret=$key&counter=$counter";