Package com.codename1.backend.security.mfa


package com.codename1.backend.security.mfa

A second factor at sign-in: one-time codes from an authenticator app, and the recovery codes that stand in for a lost phone.

http.mfa(...) turns it on for a chain. A user who has enrolled -- see TotpService -- is not signed in by their password alone: the request stays anonymous, and they are sent to a page that asks for the code.

The secret an authenticator app shares with the server is kept by a TotpRepository, in memory or sealed in the server's database; recovery codes are kept as hashes by a RecoveryCodeRepository.