Skip to main content

totp_confirm

Function totp_confirm 

Source
pub fn totp_confirm(
    conn: &Connection,
    user_id: &str,
    code: &str,
) -> Result<bool, String>
Expand description

Phase two: enables the factor once the user proves their authenticator works.

The confirming code’s step is recorded, so the very code used to enable the factor cannot then be replayed to log in with it.

confirm obeys the same anti-replay mark as verify, and never moves it backwards. Passing None here — which the first version did — makes this a second oracle where one code works twice, and worse: re-confirming with a code from an earlier step wrote that lower step back, re-opening every step in between for replay on the login path. Enrollment is what clears the mark, and it does so deliberately (see totp_enroll).