Class SecondFactorAuthenticationFilter
- All Implemented Interfaces:
SecondFactorPolicy, SecurityFilter
Asks a user who has a second factor for it, between their password being accepted and their being signed in.
It is the chain's SecondFactorPolicy: handed an authentication whose first
factor has passed, it signs nobody in. It notes in the session who is
waiting -- a marker that is not a security context, and that lasts five
minutes unless set otherwise -- and redirects to the page that asks for the
code. Until the code arrives every request of that session is anonymous.
It is also the filter that takes the code, at POST /login/mfa unless
changed, in the field code: a one-time code from the user's authenticator
app, or one of their recovery codes. A right one completes the sign-in
through the chain's SessionSignIn -- the session id changes, the context
is stored, remember-me is issued if it was asked for at the first step, and
the user goes where they were going.
Wrong codes are counted twice: for the user, whatever address and session
they come from, and for the user at the client's network. Too many of
either are answered 429 until time has passed. See MfaConfigurer for the
numbers, and for what the two counts together do and do not promise.
-
Field Summary
Fields -
Method Summary
Modifier and TypeMethodDescriptiondoFilter(HttpServer.Request request, FilterChain chain) The answer torequest; null when nothing under the chain routes it, which the server answers 404.intercept(HttpServer.Request request, Authentication authentication, boolean rememberMe) Decides whetherauthentication, whose first factor has just been accepted, must present a second.booleanrequires(Authentication authentication) Whetherauthenticationis of a user who has a second factor, so that a first factor alone must not make a request theirs.voidsatisfied(HttpServer.Request request, Authentication authentication) A passkey that verified the user signed them in.
-
Field Details
-
PENDING
The session attribute the pending sign-in is kept under.- See Also:
-
-
Method Details
-
intercept
public HttpServer.Response intercept(HttpServer.Request request, Authentication authentication, boolean rememberMe) Description copied from interface:SecondFactorPolicyDecides whetherauthentication, whose first factor has just been accepted, must present a second.- Specified by:
interceptin interfaceSecondFactorPolicy- Parameters:
rememberMe- whether the user asked to be remembered: to be handed back toSessionSignIn.complete(HttpServer.Request, Authentication, boolean, AuthenticationSuccessHandler), since the request that finishes the sign-in is not the one that asked- Returns:
- null to let the sign-in complete now; otherwise the answer to this request -- a redirect to where the second factor is asked for -- with the sign-in left pending
-
requires
Description copied from interface:SecondFactorPolicyWhether
authenticationis of a user who has a second factor, so that a first factor alone must not make a request theirs.SecondFactorPolicy.intercept(HttpServer.Request, Authentication, boolean)is for a sign-in that can stop and ask. This is for the ways of presenting a first factor that cannot: credentials sent with every request, which have no second step to send a code in, and a remember-me cookie, which has nobody at the keyboard. Each asks here and refuses the user when the answer is true; seeMfaConfigurerfor the rule of each mechanism.A policy that does not say is taken to require one of everybody.
- Specified by:
requiresin interfaceSecondFactorPolicy
-
satisfied
A passkey that verified the user signed them in. Whoever ran the count of wrong codes up was not them, or no longer matters: it is forgotten, so their next one-time code is not refused for somebody else's guesses.- Specified by:
satisfiedin interfaceSecondFactorPolicy
-
doFilter
Description copied from interface:SecurityFilterThe answer torequest; null when nothing under the chain routes it, which the server answers 404.- Specified by:
doFilterin interfaceSecurityFilter- Throws:
Exception
-