Class RecoveryCodeService
java.lang.Object
com.codename1.backend.security.mfa.RecoveryCodeService
Recovery codes: what signs a user in when their authenticator app is gone.
generate(String) makes ten, to be shown to the user once and never again -- the
server keeps a salted PBKDF2 password hash of each and cannot show them a second time. Each
works once, in place of a one-time code at sign-in. Generating again
replaces whatever was left.
-
Field Summary
Fields -
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionbooleanUses a code up.MakesCOUNTnew codes forusername, replacing any they had.static booleanisCodeShaped(String code) Whethercodeis written as a recovery code is: ten letters and digits, with or without the dash.intHow many codesusernamehas left.
-
Field Details
-
COUNT
-
-
Constructor Details
-
RecoveryCodeService
-
-
Method Details
-
generate
-
consume
Uses a code up. At most four verifications run in this process, and at most one per username (case insensitive). A busy verifier returns false immediately; it does not consume a code or queue password-hashing work.- Returns:
- whether
codewas one ofusername's unused codes
-
isCodeShaped
Whethercodeis written as a recovery code is: ten letters and digits, with or without the dash. It says nothing about whether anybody has that code -- only that it is not something else, such as the digits of a one-time code. -
remaining
How many codesusernamehas left.
-