Expand description
The second-factor operations, which both front ends dispatch to and neither owns.
The same split crate::admin::users makes: no printing, no HTTP, no
terminal. src/cli/webadmin.rs (admin user totp …) and
crates/admin/src/webadmin/handlers/mfa.rs both come here, which is what keeps the replay
guard, the session revocation and the “shown once” rule identical between
them.
The pure halves live next door – crate::admin::totp for RFC 6238 and
crate::admin::recovery for the codes. This file is where they meet a
database.
Enums§
- MfaMethod
- Which of the two things an accepted submission was.
- MfaOutcome
- The result of checking a second-factor submission.
Functions§
- begin_
totp_ enrolment - Mints a secret and stores it as pending, returning the two representations the enrolment page shows exactly once.
- confirm_
totp_ enrolment - Confirms a pending enrolment against a code the authenticator produced.
- disable_
totp - Removes the factor, any half-finished enrolment, the replay guard and every recovery code – a code that recovers access to a factor that no longer exists is just a second password.
- operators_
without_ a_ factor - How many operators have no confirmed factor – what the startup warning
under
admin.require_mfacounts. - recovery_
codes_ remaining - How many unspent recovery codes this operator holds.
- regenerate_
recovery_ codes - Mints a fresh recovery set, superseding the previous one, and returns it once. Nothing stores or logs the plaintext.
- resume_
or_ begin_ totp_ enrolment - Re-renders an enrolment already begun, or begins one.
- verify_
second_ factor - Checks a submission against this operator’s factor, then against their recovery codes.