Package com.codename1.backend.security.mfa
package com.codename1.backend.security.mfa
A second factor at sign-in: one-time codes from an authenticator app, and the recovery codes that stand in for a lost phone.
http.mfa(...) turns it on for a chain. A user who has enrolled -- see
TotpService -- is not signed in by
their password alone: the request stays anonymous, and they are sent to a
page that asks for the code.
The secret an authenticator app shares with the server is kept by a
TotpRepository, in memory or sealed in
the server's database; recovery codes are kept as hashes by a
RecoveryCodeRepository.
-
ClassDescriptionRecovery codes kept in this process: gone when it stops.Secrets kept in this process: gone when it stops.Recovery codes kept in the server's database, in the
cn1_mfa_recovery_codetable ofSecuritySchema.Secrets kept in the server's database, in thecn1_mfa_totptable ofSecuritySchema.Where recovery codes are kept: as hashes, never as the codes.Recovery codes: what signs a user in when their authenticator app is gone.What the server keeps of one user's authenticator app.What a user needs to add the server to their authenticator app: shown once, when enrolment begins.Where the secrets of users' authenticator apps are kept.Time-based one-time codes (RFC 6238): enrolling a user's authenticator app, and checking the codes it shows.