Class InMemoryTotpRepository

java.lang.Object
com.codename1.backend.security.mfa.InMemoryTotpRepository
All Implemented Interfaces:
TotpRepository

public final class InMemoryTotpRepository extends Object implements TotpRepository
Secrets kept in this process: gone when it stops. For development and tests; see JdbcTotpRepository otherwise.
  • Constructor Summary

    Constructors
    Constructor
    Description
     
  • Method Summary

    Modifier and Type
    Method
    Description
    boolean
    advance(String username, byte[] expectedSecret, long step)
    Consumes a sign-in code only if the confirmed credential still has the verified secret and its last accepted step is lower.
    boolean
    advance(String username, long step)
    Records that a code of time step step was accepted, if no code of that step or a later one has been.
    boolean
    confirm(String username)
    Marks the credential confirmed, if it is there and was not.
    boolean
    confirm(String username, byte[] expectedSecret, long step)
    Confirms and consumes a code only if the current, unconfirmed credential still has the secret that was verified.
    boolean
    delete(String username)
    Forgets the credential.
    find(String username)
    The credential of username, or null.
    void
    save(String username, byte[] secret)
    Stores a new, unconfirmed secret for username, replacing any other.

    Methods inherited from class Object

    clone, equals, getClass, hashCode, notify, notifyAll, toString, wait, wait, wait
  • Constructor Details

    • InMemoryTotpRepository

      public InMemoryTotpRepository()
  • Method Details

    • save

      public void save(String username, byte[] secret)
      Description copied from interface: TotpRepository
      Stores a new, unconfirmed secret for username, replacing any other.
      Specified by:
      save in interface TotpRepository
    • find

      public TotpCredential find(String username)
      Description copied from interface: TotpRepository
      The credential of username, or null.
      Specified by:
      find in interface TotpRepository
    • confirm

      public boolean confirm(String username)
      Description copied from interface: TotpRepository
      Marks the credential confirmed, if it is there and was not.
      Specified by:
      confirm in interface TotpRepository
      Returns:
      whether this call confirmed it
    • advance

      public boolean advance(String username, long step)
      Description copied from interface: TotpRepository

      Records that a code of time step step was accepted, if no code of that step or a later one has been.

      The test and the change are one step, which is what makes a code good once: of two requests presenting the same code at the same moment, on one server or two, exactly one is told true.

      Specified by:
      advance in interface TotpRepository
      Returns:
      whether this call recorded it
    • confirm

      public boolean confirm(String username, byte[] expectedSecret, long step)
      Description copied from interface: TotpRepository
      Confirms and consumes a code only if the current, unconfirmed credential still has the secret that was verified. The comparison and both changes must be atomic, including across servers sharing a database.
      Specified by:
      confirm in interface TotpRepository
    • advance

      public boolean advance(String username, byte[] expectedSecret, long step)
      Description copied from interface: TotpRepository
      Consumes a sign-in code only if the confirmed credential still has the verified secret and its last accepted step is lower. This is one atomic change.
      Specified by:
      advance in interface TotpRepository
    • delete

      public boolean delete(String username)
      Description copied from interface: TotpRepository
      Forgets the credential.
      Specified by:
      delete in interface TotpRepository
      Returns:
      whether there was one