Interface TotpRepository

All Known Implementing Classes:
InMemoryTotpRepository, JdbcTotpRepository

public interface TotpRepository

Where the secrets of users' authenticator apps are kept. A user has one; names are compared without regard to the case of A to Z.

TotpService uses the secret-bound overloads of confirm and advance. Custom stores must implement their atomic comparison and update; the defaults refuse the operation rather than fall back to an unbound update.

  • Method Summary

    Modifier and Type
    Method
    Description
    default boolean
    advance(String username, byte[] expectedSecret, long step)
    Consumes a sign-in code only if the confirmed credential still has the verified secret and its last accepted step is lower.
    boolean
    advance(String username, long step)
    Records that a code of time step step was accepted, if no code of that step or a later one has been.
    boolean
    confirm(String username)
    Marks the credential confirmed, if it is there and was not.
    default boolean
    confirm(String username, byte[] expectedSecret, long step)
    Confirms and consumes a code only if the current, unconfirmed credential still has the secret that was verified.
    boolean
    delete(String username)
    Forgets the credential.
    find(String username)
    The credential of username, or null.
    void
    save(String username, byte[] secret)
    Stores a new, unconfirmed secret for username, replacing any other.
  • Method Details

    • save

      void save(String username, byte[] secret)
      Stores a new, unconfirmed secret for username, replacing any other.
    • find

      TotpCredential find(String username)
      The credential of username, or null.
    • confirm

      boolean confirm(String username)
      Marks the credential confirmed, if it is there and was not.
      Returns:
      whether this call confirmed it
    • advance

      boolean advance(String username, long step)

      Records that a code of time step step was accepted, if no code of that step or a later one has been.

      The test and the change are one step, which is what makes a code good once: of two requests presenting the same code at the same moment, on one server or two, exactly one is told true.

      Returns:
      whether this call recorded it
    • confirm

      default boolean confirm(String username, byte[] expectedSecret, long step)
      Confirms and consumes a code only if the current, unconfirmed credential still has the secret that was verified. The comparison and both changes must be atomic, including across servers sharing a database.
    • advance

      default boolean advance(String username, byte[] expectedSecret, long step)
      Consumes a sign-in code only if the confirmed credential still has the verified secret and its last accepted step is lower. This is one atomic change.
    • delete

      boolean delete(String username)
      Forgets the credential.
      Returns:
      whether there was one