Interface RecoveryCodeRepository

All Known Implementing Classes:
InMemoryRecoveryCodeRepository, JdbcRecoveryCodeRepository

public interface RecoveryCodeRepository
Where recovery codes are kept: as hashes, never as the codes.
  • Method Summary

    Modifier and Type
    Method
    Description
    boolean
    consume(String username, String codeHash)
    Uses one code up.
    int
    count(String username)
    How many codes username has left.
    findHashes(String username)
    A snapshot of the user's salted password hashes, for checking a presented code.
    void
    replace(String username, List<String> codeHashes)
    Replaces every code of username with these hashes.
  • Method Details

    • replace

      void replace(String username, List<String> codeHashes)
      Replaces every code of username with these hashes.
    • findHashes

      List<String> findHashes(String username)
      A snapshot of the user's salted password hashes, for checking a presented code. An unknown user has an empty list. Consumption still goes through consume(String, String).
    • consume

      boolean consume(String username, String codeHash)

      Uses one code up.

      The test and the removal are one step: a code is good once, however many requests present it at the same moment.

      Returns:
      whether this call removed it
    • count

      int count(String username)
      How many codes username has left.