Interface TotpRepository
- All Known Implementing Classes:
InMemoryTotpRepository, JdbcTotpRepository
public interface TotpRepository
Where the secrets of users' authenticator apps are kept. A user has one;
names are compared without regard to the case of A to Z.
TotpService uses the secret-bound overloads of confirm and advance.
Custom stores must implement their atomic comparison and update; the defaults
refuse the operation rather than fall back to an unbound update.
-
Method Summary
Modifier and TypeMethodDescriptiondefault booleanConsumes a sign-in code only if the confirmed credential still has the verified secret and its last accepted step is lower.booleanRecords that a code of time stepstepwas accepted, if no code of that step or a later one has been.booleanMarks the credential confirmed, if it is there and was not.default booleanConfirms and consumes a code only if the current, unconfirmed credential still has the secret that was verified.booleanForgets the credential.The credential ofusername, or null.voidStores a new, unconfirmed secret forusername, replacing any other.
-
Method Details
-
save
Stores a new, unconfirmed secret forusername, replacing any other. -
find
The credential ofusername, or null. -
confirm
Marks the credential confirmed, if it is there and was not.- Returns:
- whether this call confirmed it
-
advance
Records that a code of time step
stepwas accepted, if no code of that step or a later one has been.The test and the change are one step, which is what makes a code good once: of two requests presenting the same code at the same moment, on one server or two, exactly one is told true.
- Returns:
- whether this call recorded it
-
confirm
Confirms and consumes a code only if the current, unconfirmed credential still has the secret that was verified. The comparison and both changes must be atomic, including across servers sharing a database. -
advance
Consumes a sign-in code only if the confirmed credential still has the verified secret and its last accepted step is lower. This is one atomic change. -
delete
-