keystone.auth.plugins.totp module¶
Time-based One-time Password Algorithm (TOTP) auth plugin.
TOTP is an algorithm that computes a one-time password from a shared secret key and the current time.
TOTP is an implementation of a hash-based message authentication code (HMAC). It combines a secret key with the current timestamp using a cryptographic hash function to generate a one-time password. The timestamp typically increases in 30-second intervals, so passwords generated close together in time from the same secret key will be equal.
- class keystone.auth.plugins.totp.TOTP[source]¶
Bases:
AuthMethodHandler
- keystone.auth.plugins.totp.verify_totp_passcode(user_id, passcode)[source]¶
Check
passcodeagainstuser_id’s stored TOTP credential(s).Shared by the TOTP auth plugin and by any other code path that needs to verify a fresh, current TOTP passcode outside of full authentication (e.g. re-verification before a sensitive account action, see keystone.api._shared.mfa_reverification). Enforces the same reject-on-reuse behavior as login (LP#2157347): a passcode accepted here cannot be replayed for login or for another re-verification check.
- Returns:
True if the passcode is valid and not a replay, else False.