Coverage for gws-app/gws/plugin/auth_mfa/__init__.py: 100%

0 statements  

« prev     ^ index     » next       coverage.py v7.16.2, created at 2026-10-05 13:35 +0200

1"""Multi-factor authentication adapters. 

2 

3A multi-factor adapter adds a second login step after a provider has 

4authenticated the user. Adapters are configured in ``auth.mfa``. A user is 

5assigned to an adapter by the ``mfaUid`` attribute of the user record, which 

6must match the ``uid`` of the adapter. The second step is run by the web 

7authentication method (``gws.plugin.auth_method.web``). The transaction life 

8cycle (life time, verification attempts, restarts) and the TOTP helpers are 

9implemented in the base class ``gws.base.auth.mfa``. 

10 

11Subpackages 

12----------- 

13 

14- ``email`` - sends a one-time code to the email address of the user. 

15- ``totp`` - checks time-based one-time passwords from an authenticator app, 

16 using the ``mfaSecret`` of the user. 

17 

18Example:: 

19 

20 auth.mfa+ { 

21 type "totp" 

22 uid "AUTH_MFA_TOTP" 

23 } 

24 

25A user record of the ``file`` provider that uses this adapter:: 

26 

27 { 

28 "login": "user_1", 

29 "password": "...", 

30 "mfaUid": "AUTH_MFA_TOTP", 

31 "mfaSecret": "..." 

32 } 

33"""