Coverage for gws-app/gws/plugin/auth_mfa/__init__.py: 100%
0 statements
« prev ^ index » next coverage.py v7.16.2, created at 2026-10-05 13:35 +0200
« prev ^ index » next coverage.py v7.16.2, created at 2026-10-05 13:35 +0200
1"""Multi-factor authentication adapters.
3A multi-factor adapter adds a second login step after a provider has
4authenticated the user. Adapters are configured in ``auth.mfa``. A user is
5assigned to an adapter by the ``mfaUid`` attribute of the user record, which
6must match the ``uid`` of the adapter. The second step is run by the web
7authentication method (``gws.plugin.auth_method.web``). The transaction life
8cycle (life time, verification attempts, restarts) and the TOTP helpers are
9implemented in the base class ``gws.base.auth.mfa``.
11Subpackages
12-----------
14- ``email`` - sends a one-time code to the email address of the user.
15- ``totp`` - checks time-based one-time passwords from an authenticator app,
16 using the ``mfaSecret`` of the user.
18Example::
20 auth.mfa+ {
21 type "totp"
22 uid "AUTH_MFA_TOTP"
23 }
25A user record of the ``file`` provider that uses this adapter::
27 {
28 "login": "user_1",
29 "password": "...",
30 "mfaUid": "AUTH_MFA_TOTP",
31 "mfaSecret": "..."
32 }
33"""