Skip to main content

Module mfa

Module mfa 

Source
Expand description

The second-factor operations, which both front ends dispatch to and neither owns.

The same split crate::admin::users makes: no printing, no HTTP, no terminal. src/cli/webadmin.rs (admin user totp …) and crates/admin/src/webadmin/handlers/mfa.rs both come here, which is what keeps the replay guard, the session revocation and the “shown once” rule identical between them.

The pure halves live next door – crate::admin::totp for RFC 6238 and crate::admin::recovery for the codes. This file is where they meet a database.

Enums§

MfaMethod
Which of the two things an accepted submission was.
MfaOutcome
The result of checking a second-factor submission.

Functions§

begin_totp_enrolment
Mints a secret and stores it as pending, returning the two representations the enrolment page shows exactly once.
confirm_totp_enrolment
Confirms a pending enrolment against a code the authenticator produced.
disable_totp
Removes the factor, any half-finished enrolment, the replay guard and every recovery code – a code that recovers access to a factor that no longer exists is just a second password.
operators_without_a_factor
How many operators have no confirmed factor – what the startup warning under admin.require_mfa counts.
recovery_codes_remaining
How many unspent recovery codes this operator holds.
regenerate_recovery_codes
Mints a fresh recovery set, superseding the previous one, and returns it once. Nothing stores or logs the plaintext.
resume_or_begin_totp_enrolment
Re-renders an enrolment already begun, or begins one.
verify_second_factor
Checks a submission against this operator’s factor, then against their recovery codes.