Skip to main content

verify

Function verify 

Source
pub fn verify(
    secret_b32: &str,
    code: &str,
    last_step: Option<u64>,
    now: u64,
) -> Option<Accepted>
Expand description

Verifies a code against a secret, refusing anything at or before last_step.

§The anti-replay rule is the whole point

A ±1-step skew window means any given code is valid for ninety seconds. Over a network that is ninety seconds in which an observed code can be replayed by whoever saw it — which for a second factor is the exact attack it exists to stop. Refusing a step that has already been accepted reduces that to a single use, and it is why every caller has to store what Accepted::step returns.

last_step of None means the factor has never been used.