Skip to main content

totp_enroll

Function totp_enroll 

Source
pub fn totp_enroll(
    conn: &Connection,
    user_id: &str,
    issuer: &str,
) -> Result<TotpStatus, String>
Expand description

Phase one of enrollment: mints a secret and returns it with its URI.

The factor is not enabled by this call. Enabling on enrollment locks out any user whose authenticator did not actually take the secret — which, with manual base32 entry and no QR code, is a routine outcome rather than an edge case. totp_confirm is what turns it on, and it requires a working code.

Re-enrolling an already-enabled user replaces the secret and switches the factor back off, so a half-finished re-enrollment cannot leave the account requiring a code nobody can generate.