Skip to main content

verify_second_factor

Function verify_second_factor 

Source
pub async fn verify_second_factor(
    user: &mut AdminUser,
    submitted: &str,
    database: Arc<Database>,
) -> Result<MfaOutcome, Error>
Expand description

Checks a submission against this operator’s factor, then against their recovery codes.

Order matters. A TOTP check is three HMACs; a recovery check is up to ten PBKDF2 runs and a write. The cheap and overwhelmingly common path goes first, and a submission that cannot be a recovery code by shape never starts the scan at all.

On success the TOTP path claims its time step (AdminUser::claim_totp_step) and the recovery path spends its code (AdminRecoveryCode::consume) – in both cases the database, not this function, is what makes it single-use.