Skip to content

basalt / auth/src / MfaRecord

Interface: MfaRecord ​

Defined in: auth/src/stores.ts:312

Per-user MFA state. secret is the base32 TOTP secret; recoveryCodes holds SHA-256 hashes of single-use backup codes (never the plaintext).

Properties ​

enabled ​

> enabled: boolean

Defined in: auth/src/stores.ts:314


lastUsedStep? ​

> optional lastUsedStep?: number

Defined in: auth/src/stores.ts:321

The last TOTP step (counter) accepted for this user. Codes at a step ≤ this are rejected, so an intercepted 6-digit code cannot be replayed within its validity window (RFC 6238 §5.2). Undefined until the first accepted code.


recoveryCodes ​

> recoveryCodes: string[]

Defined in: auth/src/stores.ts:315


secret ​

> secret: string

Defined in: auth/src/stores.ts:313

Released under the MIT License.