Class TotpService
Time-based one-time codes (RFC 6238): enrolling a user's authenticator app, and checking the codes it shows.
@Bean
TotpService totp(DataSource dataSource, Config config) {
return new TotpService(JdbcTotpRepository.fromConfig(dataSource, config), "Acme");
}
Enrolment is two steps, so that nobody is locked out by an app that was
never set up: beginEnrollment(String) makes a secret and returns it for the user
to scan, and confirmEnrollment(String, String) takes a code from the app. Only then does
the user have a second factor, and only then does a chain with
http.mfa(...) ask for it.
Codes are six digits over SHA-1 that change every 30 seconds, which is what authenticator apps expect, and one step either side of the current one is accepted to allow for a clock that is off. A code is good once: the step of each accepted code is recorded, and a code of that step or an earlier one is refused afterwards -- including the same code sent twice at once.
-
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionbeginEnrollment(String username) Makes a new secret forusernameand returns what their app needs.booleanconfirmEnrollment(String username, String code) Finishes an enrolment with a code from the user's app.currentCode(String username) The codeusername's app shows now.booleanRemoves the second factor ofusername.booleanWhetherusernamehas a confirmed second factor.voidsetAlgorithm(String algorithm) The hash:Hash.SHA1unless set.voidvoidsetDigits(int digits) The number of digits in a code: 6 unless set, or 8.voidsetPeriodSeconds(int periodSeconds) How long a code lasts; 30 seconds unless set.voidsetTolerance(int tolerance) How many steps either side of the current one are accepted; 1 unless set.booleanChecks a code at sign-in, and uses it up.
-
Constructor Details
-
TotpService
- Parameters:
issuer- the name an authenticator app shows beside the account; it may not contain a colon
-
-
Method Details
-
setDigits
public void setDigits(int digits) The number of digits in a code: 6 unless set, or 8. -
setPeriodSeconds
public void setPeriodSeconds(int periodSeconds) How long a code lasts; 30 seconds unless set. -
setTolerance
public void setTolerance(int tolerance) How many steps either side of the current one are accepted; 1 unless set. Zero accepts the current code only. -
setAlgorithm
-
setClock
-
beginEnrollment
Makes a new secret forusernameand returns what their app needs. Whatever they had before is replaced, and is not a second factor again untilconfirmEnrollment(String, String). -
confirmEnrollment
-
isEnabled
Whetherusernamehas a confirmed second factor. -
verify
-
disable
Removes the second factor ofusername.- Returns:
- whether they had one
-
currentCode
-