Class InMemoryTotpRepository
java.lang.Object
com.codename1.backend.security.mfa.InMemoryTotpRepository
- All Implemented Interfaces:
TotpRepository
Secrets kept in this process: gone when it stops. For development and
tests; see
JdbcTotpRepository otherwise.-
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionbooleanConsumes a sign-in code only if the confirmed credential still has the verified secret and its last accepted step is lower.booleanRecords that a code of time stepstepwas accepted, if no code of that step or a later one has been.booleanMarks the credential confirmed, if it is there and was not.booleanConfirms and consumes a code only if the current, unconfirmed credential still has the secret that was verified.booleanForgets the credential.The credential ofusername, or null.voidStores a new, unconfirmed secret forusername, replacing any other.
-
Constructor Details
-
InMemoryTotpRepository
public InMemoryTotpRepository()
-
-
Method Details
-
save
Description copied from interface:TotpRepositoryStores a new, unconfirmed secret forusername, replacing any other.- Specified by:
savein interfaceTotpRepository
-
find
Description copied from interface:TotpRepositoryThe credential ofusername, or null.- Specified by:
findin interfaceTotpRepository
-
confirm
Description copied from interface:TotpRepositoryMarks the credential confirmed, if it is there and was not.- Specified by:
confirmin interfaceTotpRepository- Returns:
- whether this call confirmed it
-
advance
Description copied from interface:TotpRepositoryRecords that a code of time step
stepwas accepted, if no code of that step or a later one has been.The test and the change are one step, which is what makes a code good once: of two requests presenting the same code at the same moment, on one server or two, exactly one is told true.
- Specified by:
advancein interfaceTotpRepository- Returns:
- whether this call recorded it
-
confirm
Description copied from interface:TotpRepositoryConfirms and consumes a code only if the current, unconfirmed credential still has the secret that was verified. The comparison and both changes must be atomic, including across servers sharing a database.- Specified by:
confirmin interfaceTotpRepository
-
advance
Description copied from interface:TotpRepositoryConsumes a sign-in code only if the confirmed credential still has the verified secret and its last accepted step is lower. This is one atomic change.- Specified by:
advancein interfaceTotpRepository
-
delete
Description copied from interface:TotpRepositoryForgets the credential.- Specified by:
deletein interfaceTotpRepository- Returns:
- whether there was one
-