Documentation
¶
Overview ¶
Package totp is the time-based one-time code an authenticator app shows (RFC 6238), computed from the seed the provider's QR code carries (#2065). A stored secret of kind totp holds the seed; the api gateway fills {{totp:<name>}} with the code for the moment the request is sent.
It knows nothing about storage or who may use a code: it reads the seed and its parameters out of what an administrator pastes, and computes a code for a period.
Index ¶
Constants ¶
const ( AlgorithmSHA1 = "SHA1" AlgorithmSHA256 = "SHA256" AlgorithmSHA512 = "SHA512" )
The algorithms a code may be computed with.
const ( DefaultDigits = 6 DefaultPeriod = 30 )
The defaults a bare seed takes, which are an otpauth URI's when it names none: SHA1, six digits, thirty seconds.
const MaxPeriod = 300
MaxPeriod bounds the period an otpauth URI may name.
const MinSeedBytes = 10
MinSeedBytes is the shortest seed accepted: 80 bits, the shortest any provider issues. RFC 4226 recommends 160.
Variables ¶
var ErrInvalid = errors.New("invalid authenticator seed")
ErrInvalid is wrapped by every refusal of what was pasted.
Functions ¶
Types ¶
type Params ¶
type Params struct {
Algorithm string `json:"algorithm" example:"SHA1"`
Digits int `json:"digits" example:"6"`
Period int `json:"period" example:"30"`
}
Params are what a code is computed with besides the seed.
func Parse ¶
Parse reads an authenticator seed as an administrator pastes it: the otpauth://totp/... URI the provider's QR code encodes, or the bare base32 seed. It returns the seed in canonical base32 (upper case, no padding or spaces), which is what is stored, and the code's parameters. Every refusal names what is wrong.