Interface SecondFactorPolicy
- All Known Implementing Classes:
SecondFactorAuthenticationFilter
Stands between a user passing their first factor and being signed in.
Every way of signing in that ends in a session -- the form login, a passkey,
and a sign-in through another identity provider -- hands the authentication
it established to the chain's SessionSignIn rather than storing it. When the
chain has a policy, the policy is asked first, and may take the request
over: http.mfa(...) installs the one that asks for a one-time code.
A policy that takes a request over must leave it anonymous. Nothing has
been stored for the user at this point -- no security context, no changed
session id -- and the policy keeps only what it needs to finish later, by
calling SessionSignIn.complete(HttpServer.Request, Authentication, boolean, AuthenticationSuccessHandler) once the second factor is in.
-
Method Summary
Modifier and TypeMethodDescriptionintercept(HttpServer.Request request, Authentication authentication, boolean rememberMe) Decides whetherauthentication, whose first factor has just been accepted, must present a second.default booleanrequires(Authentication authentication) Whetherauthenticationis of a user who has a second factor, so that a first factor alone must not make a request theirs.default voidsatisfied(HttpServer.Request request, Authentication authentication) Told thatauthenticationsigned in with two factors presented in one step -- a passkey whose authenticator verified the user -- so thatintercept(HttpServer.Request, Authentication, boolean)was not asked.
-
Method Details
-
intercept
HttpServer.Response intercept(HttpServer.Request request, Authentication authentication, boolean rememberMe) throws Exception Decides whetherauthentication, whose first factor has just been accepted, must present a second.- Parameters:
rememberMe- whether the user asked to be remembered: to be handed back toSessionSignIn.complete(HttpServer.Request, Authentication, boolean, AuthenticationSuccessHandler), since the request that finishes the sign-in is not the one that asked- Returns:
- null to let the sign-in complete now; otherwise the answer to this request -- a redirect to where the second factor is asked for -- with the sign-in left pending
- Throws:
Exception
-
requires
Whether
authenticationis of a user who has a second factor, so that a first factor alone must not make a request theirs.intercept(HttpServer.Request, Authentication, boolean)is for a sign-in that can stop and ask. This is for the ways of presenting a first factor that cannot: credentials sent with every request, which have no second step to send a code in, and a remember-me cookie, which has nobody at the keyboard. Each asks here and refuses the user when the answer is true; seeMfaConfigurerfor the rule of each mechanism.A policy that does not say is taken to require one of everybody.
-
satisfied
Told that
authenticationsigned in with two factors presented in one step -- a passkey whose authenticator verified the user -- so thatintercept(HttpServer.Request, Authentication, boolean)was not asked.A policy that counts wrong attempts at its own second factor forgets them here: the user has just proved both factors another way, and whatever was counted against them was not theirs. Nothing unless the policy says more.
-