Skip to main content

verify_user_totp

Function verify_user_totp 

Source
pub fn verify_user_totp(
    conn: &Connection,
    user_id: &str,
    code: &str,
) -> Result<bool, String>
Expand description

Verifies a login code and advances the anti-replay high-water mark.

Fails closed: a NULL secret on an enabled account returns false rather than true. That exact inversion is in this project’s bug history — the Phase 5.1 implementation returned Ok(true) for a missing secret, which made “enabled but unconfigured” the same as “authenticated”.

The step is written back before the caller is told the code was good, so a concurrent second attempt with the same code loses the race rather than winning it.