Class TwoFactorController

java.lang.Object
springboot.bg.harisauto.twofactor.TwoFactorController

@Controller public class TwoFactorController extends Object
TwoFactorController.java - The second step of a password sign-in.

Reached only when TwoFactorAuthenticationSuccessHandler has parked a pending user on the session. The session gains no authority until a correct code is submitted here.

Author:
Kristian Popov
  • Constructor Summary

    Constructors
    Constructor
    Description
    TwoFactorController(TwoFactorService twoFactorService, UserService userService)
    Constructor.
  • Method Summary

    Modifier and Type
    Method
    Description
    org.springframework.web.servlet.ModelAndView
    showVerifyPage(jakarta.servlet.http.HttpSession session)
    Shows the code entry form.
    org.springframework.web.servlet.ModelAndView
    verify(String code, jakarta.servlet.http.HttpSession session, jakarta.servlet.http.HttpServletRequest request, jakarta.servlet.http.HttpServletResponse response)
    Checks the submitted code and, if it is correct, signs the user in.

    Methods inherited from class java.lang.Object

    clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, wait
  • Constructor Details

  • Method Details

    • showVerifyPage

      @GetMapping("/login/verify") public org.springframework.web.servlet.ModelAndView showVerifyPage(jakarta.servlet.http.HttpSession session)
      Shows the code entry form.
      Parameters:
      session - The current session.
      Returns:
      The verification page, or the login page if no sign-in is pending.
    • verify

      @PostMapping("/login/verify") public org.springframework.web.servlet.ModelAndView verify(@RequestParam("code") String code, jakarta.servlet.http.HttpSession session, jakarta.servlet.http.HttpServletRequest request, jakarta.servlet.http.HttpServletResponse response)
      Checks the submitted code and, if it is correct, signs the user in.
      Parameters:
      code - The six-digit code from the email.
      session - The current session.
      request - The current request.
      response - The current response.
      Returns:
      Redirect to the home page on success, back to the form otherwise.