Skip to main content

PENDING_MFA_TTL

Constant PENDING_MFA_TTL 

Source
pub const PENDING_MFA_TTL: Duration;
Expand description

How long a half-authenticated session may sit unfinished.

Deliberately not admin.session_ttl_seconds and deliberately not a configuration key. A pending_mfa row is a password that has been accepted and nothing more; it should not outlive the tab that created it. Five minutes is longer than reading a code off a phone and shorter than walking away from the keyboard – a UI timing constant, not a policy an operator tunes.

It is also the only per-session bound on code guessing: within it an attacker holding a correct password gets admin.login_max_attempts tries from one address, and then the row is gone regardless.