types

package
v2.1.2 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 3, 2026 License: MIT Imports: 2 Imported by: 0

Documentation

Overview

Package types defines the domain models and store contract for the TOTP plugin.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type Credential

type Credential struct {
	UserID  string
	Secret  string
	Enabled bool
}

Credential is a user's TOTP credential state.

Secret is empty until enrollment starts. Enabled is only true after a code generated from the pending secret has been confirmed, so a half-finished setup can never lock a user out.

type DisableRequest

type DisableRequest struct {
	Code string `json:"code"`
}

DisableRequest confirms the second factor before removing it.

type EnableRequest

type EnableRequest struct {
	Code string `json:"code"`
}

EnableRequest confirms the pending secret.

type EnableResponse

type EnableResponse struct {
	RecoveryCodes []string `json:"recovery_codes"`
}

EnableResponse carries the single-use recovery codes. Also used by the regenerate endpoint.

type RegenerateRequest

type RegenerateRequest struct {
	Code string `json:"code"`
}

RegenerateRequest asks for fresh recovery codes.

type SetupResponse

type SetupResponse struct {
	Secret string `json:"secret"`
	URL    string `json:"otpauth_url"`
}

SetupResponse is returned by the enrollment endpoint. The secret is shown once; TOTP is inactive until Enable confirms a code.

type StatusResponse

type StatusResponse struct {
	Enabled  bool `json:"enabled"`
	Verified bool `json:"verified"`
}

StatusResponse reports enrollment and current-session state.

type Store

type Store interface {
	// GetCredential returns the user's TOTP credential. Secret is empty when
	// enrollment has not started. Returns a not-found error for unknown users.
	GetCredential(ctx context.Context, userID string) (Credential, error)

	// SetCredential writes the credential. A nil secret clears the stored
	// secret (disable); enabled flips the trusted flag.
	SetCredential(ctx context.Context, userID string, secret *string, enabled bool) error

	// MarkSessionVerified records that sessionID completed second-factor
	// verification for userID at the given time.
	MarkSessionVerified(ctx context.Context, sessionID, userID string, at time.Time) error

	// IsSessionVerified reports whether sessionID was verified after since.
	IsSessionVerified(ctx context.Context, sessionID, userID string, since time.Time) (bool, error)

	// DeleteUserSessionVerifications clears every session verification for a
	// user (used when TOTP is disabled).
	DeleteUserSessionVerifications(ctx context.Context, userID string) error

	// DeleteSessionVerification clears one session's verification.
	DeleteSessionVerification(ctx context.Context, sessionID string) error
}

Store defines the persistence contract for the TOTP plugin.

Implementations must be safe for concurrent use.

type VerifyRequest

type VerifyRequest struct {
	Code     string `json:"code"`
	Recovery bool   `json:"recovery"`
}

VerifyRequest steps up the current session with a TOTP or recovery code.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL