pub async fn verify_second_factor(
user: &mut AdminUser,
submitted: &str,
database: Arc<Database>,
) -> Result<MfaOutcome, Error>Expand description
Checks a submission against this operator’s factor, then against their recovery codes.
Order matters. A TOTP check is three HMACs; a recovery check is up to ten PBKDF2 runs and a write. The cheap and overwhelmingly common path goes first, and a submission that cannot be a recovery code by shape never starts the scan at all.
On success the TOTP path claims its time step
(AdminUser::claim_totp_step) and the recovery path spends its code
(AdminRecoveryCode::consume) – in both cases the database, not this
function, is what makes it single-use.