Documentation
¶
Overview ¶
Package types defines the domain models and store contract for the TOTP plugin.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Credential ¶
Credential is a user's TOTP credential state.
Secret is empty until enrollment starts. Enabled is only true after a code generated from the pending secret has been confirmed, so a half-finished setup can never lock a user out.
type DisableRequest ¶
type DisableRequest struct {
Code string `json:"code"`
}
DisableRequest confirms the second factor before removing it.
type EnableRequest ¶
type EnableRequest struct {
Code string `json:"code"`
}
EnableRequest confirms the pending secret.
type EnableResponse ¶
type EnableResponse struct {
RecoveryCodes []string `json:"recovery_codes"`
}
EnableResponse carries the single-use recovery codes. Also used by the regenerate endpoint.
type RegenerateRequest ¶
type RegenerateRequest struct {
Code string `json:"code"`
}
RegenerateRequest asks for fresh recovery codes.
type SetupResponse ¶
SetupResponse is returned by the enrollment endpoint. The secret is shown once; TOTP is inactive until Enable confirms a code.
type StatusResponse ¶
StatusResponse reports enrollment and current-session state.
type Store ¶
type Store interface {
// GetCredential returns the user's TOTP credential. Secret is empty when
// enrollment has not started. Returns a not-found error for unknown users.
GetCredential(ctx context.Context, userID string) (Credential, error)
// SetCredential writes the credential. A nil secret clears the stored
// secret (disable); enabled flips the trusted flag.
SetCredential(ctx context.Context, userID string, secret *string, enabled bool) error
// MarkSessionVerified records that sessionID completed second-factor
// verification for userID at the given time.
MarkSessionVerified(ctx context.Context, sessionID, userID string, at time.Time) error
// IsSessionVerified reports whether sessionID was verified after since.
IsSessionVerified(ctx context.Context, sessionID, userID string, since time.Time) (bool, error)
// DeleteUserSessionVerifications clears every session verification for a
// user (used when TOTP is disabled).
DeleteUserSessionVerifications(ctx context.Context, userID string) error
// DeleteSessionVerification clears one session's verification.
DeleteSessionVerification(ctx context.Context, sessionID string) error
}
Store defines the persistence contract for the TOTP plugin.
Implementations must be safe for concurrent use.
type VerifyRequest ¶
VerifyRequest steps up the current session with a TOTP or recovery code.