Class SecondFactorAuthenticationFilter

java.lang.Object
com.codename1.backend.security.SecondFactorAuthenticationFilter
All Implemented Interfaces:
SecondFactorPolicy, SecurityFilter

public final class SecondFactorAuthenticationFilter extends Object implements SecurityFilter, SecondFactorPolicy

Asks a user who has a second factor for it, between their password being accepted and their being signed in.

It is the chain's SecondFactorPolicy: handed an authentication whose first factor has passed, it signs nobody in. It notes in the session who is waiting -- a marker that is not a security context, and that lasts five minutes unless set otherwise -- and redirects to the page that asks for the code. Until the code arrives every request of that session is anonymous.

It is also the filter that takes the code, at POST /login/mfa unless changed, in the field code: a one-time code from the user's authenticator app, or one of their recovery codes. A right one completes the sign-in through the chain's SessionSignIn -- the session id changes, the context is stored, remember-me is issued if it was asked for at the first step, and the user goes where they were going.

Wrong codes are counted twice: for the user, whatever address and session they come from, and for the user at the client's network. Too many of either are answered 429 until time has passed. See MfaConfigurer for the numbers, and for what the two counts together do and do not promise.