key-cape/src/internal/domain/mfa.go
tegwick b6af6c5268
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 34s
Finish KEY-WP-0008: registration handoff and client MFA isolation
Add signed registration/enrollment handoffs, per-request assurance
policy with login-session isolation, and /logout. coulomb-social
stays AAL1 unless acr_values or another client raises the bar.
2026-08-16 01:05:27 +02:00

28 lines
1.1 KiB
Go

package domain
import (
"context"
"errors"
)
// MFAProvider checks MFA requirements and validates MFA tokens.
// KeyCape must NOT implement MFA logic — it delegates entirely to this interface.
type MFAProvider interface {
// CheckMFARequired returns true if MFA is required for the given user.
CheckMFARequired(ctx context.Context, userID string) (bool, error)
// HasEnrolledFactor reports whether the user has at least one active
// factor. Distinct from CheckMFARequired: a provider-wide require-for-all
// policy can demand MFA even when the user has not enrolled yet.
HasEnrolledFactor(ctx context.Context, userID string) (bool, error)
// ValidateMFAToken validates the given OTP token for the user.
// Returns ErrMFAFailed if the token is invalid or expired.
ValidateMFAToken(ctx context.Context, userID, token string) error
}
// ErrMFAFailed is returned when the MFA token is invalid or expired.
var ErrMFAFailed = errors.New("mfa validation failed")
// ErrMFANotEnrolled is returned when the user has no MFA enrollment.
var ErrMFANotEnrolled = errors.New("user has no MFA enrollment")