Class TwoFactorService

java.lang.Object
springboot.bg.harisauto.twofactor.TwoFactorService

@Service public class TwoFactorService extends Object
TwoFactorService.java - Issues and verifies the one-time codes used at sign-in.
Author:
Kristian Popov
  • Constructor Details

  • Method Details

    • issueCode

      @Transactional public void issueCode(User user)
      Issues a fresh code for a user and emails it.

      Any earlier code is deleted first, so only the most recent one can ever be used.

      Parameters:
      user - The user signing in.
    • verify

      @Transactional public TwoFactorService.VerificationResult verify(UUID userId, String submittedCode)
      Checks a submitted code.

      A wrong code counts against the attempt limit; reaching the limit discards the code entirely, so guessing forces the user to start sign-in again rather than continue against the same secret.

      Parameters:
      userId - The user being verified.
      submittedCode - The code entered.
      Returns:
      The outcome of the check.