Interface: MfaRecord
Defined in: auth/src/stores.ts:312
Per-user MFA state. secret is the base32 TOTP secret; recoveryCodes holds SHA-256 hashes of single-use backup codes (never the plaintext).
Properties
enabled
> enabled: boolean
Defined in: auth/src/stores.ts:314
lastUsedStep?
> optional lastUsedStep?: number
Defined in: auth/src/stores.ts:321
The last TOTP step (counter) accepted for this user. Codes at a step ≤ this are rejected, so an intercepted 6-digit code cannot be replayed within its validity window (RFC 6238 §5.2). Undefined until the first accepted code.
recoveryCodes
> recoveryCodes: string[]
Defined in: auth/src/stores.ts:315
secret
> secret: string
Defined in: auth/src/stores.ts:313