All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 34s
Add signed registration/enrollment handoffs, per-request assurance policy with login-session isolation, and /logout. coulomb-social stays AAL1 unless acr_values or another client raises the bar.
28 lines
1.1 KiB
Go
28 lines
1.1 KiB
Go
package domain
|
|
|
|
import (
|
|
"context"
|
|
"errors"
|
|
)
|
|
|
|
// MFAProvider checks MFA requirements and validates MFA tokens.
|
|
// KeyCape must NOT implement MFA logic — it delegates entirely to this interface.
|
|
type MFAProvider interface {
|
|
// CheckMFARequired returns true if MFA is required for the given user.
|
|
CheckMFARequired(ctx context.Context, userID string) (bool, error)
|
|
|
|
// HasEnrolledFactor reports whether the user has at least one active
|
|
// factor. Distinct from CheckMFARequired: a provider-wide require-for-all
|
|
// policy can demand MFA even when the user has not enrolled yet.
|
|
HasEnrolledFactor(ctx context.Context, userID string) (bool, error)
|
|
|
|
// ValidateMFAToken validates the given OTP token for the user.
|
|
// Returns ErrMFAFailed if the token is invalid or expired.
|
|
ValidateMFAToken(ctx context.Context, userID, token string) error
|
|
}
|
|
|
|
// ErrMFAFailed is returned when the MFA token is invalid or expired.
|
|
var ErrMFAFailed = errors.New("mfa validation failed")
|
|
|
|
// ErrMFANotEnrolled is returned when the user has no MFA enrollment.
|
|
var ErrMFANotEnrolled = errors.New("user has no MFA enrollment")
|