totp

package
v1.3.9 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 7, 2026 License: Apache-2.0 Imports: 18 Imported by: 0

Documentation

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func GenerateBackupCodes

func GenerateBackupCodes(count int) ([]string, error)

GenerateBackupCodes creates random backup codes

Types

type AuthProvider

type AuthProvider interface {
	// Generate2FASecret creates a new secret for a user
	Generate2FASecret(userID int, issuer, accountName string) (*sectypes.TwoFactorSecret, error)

	// Validate2FACode verifies a TOTP code
	Validate2FACode(secret string, code string) (bool, error)

	// Enable2FA activates 2FA for a user (store secret in your database)
	Enable2FA(userID int, secret string, backupCodes []string) error

	// Disable2FA deactivates 2FA for a user
	Disable2FA(userID int) error

	// Get2FAStatus checks if user has 2FA enabled
	Get2FAStatus(userID int) (bool, error)

	// Get2FASecret retrieves the user's 2FA secret
	Get2FASecret(userID int) (string, error)

	// GenerateBackupCodes creates backup codes for 2FA
	GenerateBackupCodes(userID int, count int) ([]string, error)

	// ValidateBackupCode checks and consumes a backup code
	ValidateBackupCode(userID int, code string) (bool, error)
}

AuthProvider defines interface for 2FA operations

type Authenticator

type Authenticator struct {
	// contains filtered or unexported fields
}

Authenticator wraps an Authenticator and adds 2FA support

func NewAuthenticator

func NewAuthenticator(baseAuth BaseAuthenticator, provider AuthProvider, config *Config) *Authenticator

NewAuthenticator creates a new 2FA-enabled authenticator

func (*Authenticator) Authenticate

func (t *Authenticator) Authenticate(r *http.Request) (*sectypes.UserContext, error)

Authenticate delegates to base authenticator

func (*Authenticator) Disable2FA

func (t *Authenticator) Disable2FA(userID int) error

Disable2FA removes 2FA from a user account

func (*Authenticator) Enable2FA

func (t *Authenticator) Enable2FA(userID int, secret, verificationCode string) error

Enable2FA completes 2FA setup after user confirms with a valid code

func (*Authenticator) Login

Login authenticates with 2FA support

func (*Authenticator) Logout

Logout delegates to base authenticator

func (*Authenticator) RegenerateBackupCodes

func (t *Authenticator) RegenerateBackupCodes(userID int, count int) ([]string, error)

RegenerateBackupCodes creates new backup codes for a user

func (*Authenticator) Setup2FA

func (t *Authenticator) Setup2FA(userID int, issuer, accountName string) (*sectypes.TwoFactorSecret, error)

Setup2FA initiates 2FA setup for a user

type BaseAuthenticator

type BaseAuthenticator interface {
	Login(ctx context.Context, req sectypes.LoginRequest) (*sectypes.LoginResponse, error)
	Logout(ctx context.Context, req sectypes.LogoutRequest) error
	Authenticate(r *http.Request) (*sectypes.UserContext, error)
}

BaseAuthenticator is the subset of security.Authenticator that Authenticator wraps. It is declared here so totp does not import the core security package.

type Config

type Config struct {
	Algorithm  string // SHA1, SHA256, SHA512
	Digits     int    // Number of digits in code (6 or 8)
	Period     int    // Time step in seconds (default 30)
	SkewWindow int    // Number of time steps to check before/after (default 1)
}

Config holds TOTP configuration

func DefaultConfig

func DefaultConfig() *Config

DefaultConfig returns standard TOTP configuration

type Generator

type Generator struct {
	// contains filtered or unexported fields
}

Generator handles TOTP code generation and validation

func NewGenerator

func NewGenerator(config *Config) *Generator

NewGenerator creates a new TOTP generator with config

func (*Generator) GenerateCode

func (t *Generator) GenerateCode(secret string, timestamp time.Time) (string, error)

GenerateCode creates a TOTP code for a given time

func (*Generator) GenerateQRCodeURL

func (t *Generator) GenerateQRCodeURL(secret, issuer, accountName string) string

GenerateQRCodeURL creates a URL for QR code generation

func (*Generator) GenerateSecret

func (t *Generator) GenerateSecret() (string, error)

GenerateSecret creates a random base32-encoded secret

func (*Generator) ValidateCode

func (t *Generator) ValidateCode(secret, code string) (bool, error)

ValidateCode checks if a code is valid for the secret

type MemoryProvider

type MemoryProvider struct {
	// contains filtered or unexported fields
}

MemoryProvider is an in-memory implementation of AuthProvider for testing/examples

func NewMemoryProvider

func NewMemoryProvider(config *Config) *MemoryProvider

NewMemoryProvider creates a new in-memory 2FA provider

func (*MemoryProvider) Disable2FA

func (m *MemoryProvider) Disable2FA(userID int) error

Disable2FA deactivates 2FA for a user

func (*MemoryProvider) Enable2FA

func (m *MemoryProvider) Enable2FA(userID int, secret string, backupCodes []string) error

Enable2FA activates 2FA for a user

func (*MemoryProvider) Generate2FASecret

func (m *MemoryProvider) Generate2FASecret(userID int, issuer, accountName string) (*sectypes.TwoFactorSecret, error)

Generate2FASecret creates a new secret for a user

func (*MemoryProvider) GenerateBackupCodes

func (m *MemoryProvider) GenerateBackupCodes(userID int, count int) ([]string, error)

GenerateBackupCodes creates backup codes for 2FA

func (*MemoryProvider) Get2FASecret

func (m *MemoryProvider) Get2FASecret(userID int) (string, error)

Get2FASecret retrieves the user's 2FA secret

func (*MemoryProvider) Get2FAStatus

func (m *MemoryProvider) Get2FAStatus(userID int) (bool, error)

Get2FAStatus checks if user has 2FA enabled

func (*MemoryProvider) Validate2FACode

func (m *MemoryProvider) Validate2FACode(secret string, code string) (bool, error)

Validate2FACode verifies a TOTP code

func (*MemoryProvider) ValidateBackupCode

func (m *MemoryProvider) ValidateBackupCode(userID int, code string) (bool, error)

ValidateBackupCode checks and consumes a backup code

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL