DVAuthEndpoints class
Handlers for the generated auth routes.
Each runs inside the request's tenant scope. session, sessions, revoke and revokeOthers also run behind the authentication stage and read DVSessionPrincipal.current; the others judge the session they are given themselves, because a session waiting for its second factor -- which the stage refuses -- is the one those endpoints exist to finish or end. CSRF is the generated route's to check, as on every other POST.
Properties
- hashCode → int
-
The hash code for this object.
no setterinherited
- runtimeType → Type
-
A representation of the runtime type of the object.
no setterinherited
Methods
-
noSuchMethod(
Invocation invocation) → dynamic -
Invoked when a nonexistent method or property is accessed.
inherited
-
toString(
) → String -
A string representation of this object.
inherited
Operators
-
operator ==(
Object other) → bool -
The equality operator.
inherited
Static Properties
- accountDirectory → DVAccountDirectory?
-
The installed provider, when it can describe an account by its id.
no setter
- clock ↔ DateTime Function()
-
The time deletion windows are measured by. A test moves it; nothing
else should.
getter/setter pair
- deletionGracePeriod → Duration
-
How long a deleted account waits before it is erased, during which
signing in cancels the deletion. Zero erases at once.
no setter
- installed → bool
-
Whether a provider is installed in this process.
no setter
Static Methods
-
account(
Request request) → Future< Response> -
GET /auth/account: the signed-in person's account, with an address change still waiting for its code. -
beginTotp(
Request request) → Future< Response> -
POST /auth/factors/totp: starts enrolling an authenticator app and answers its secret and theotpauth://URI a QR code encodes. -
changePassword(
Request request) → Future< Response> -
POST /auth/account/password:currentPassword,newPassword, and on an account with a second factor acodeorrecoveryCodeunless one was presented on this session within the step-up window. -
confirmTotp(
Request request) → Future< Response> -
POST /auth/factors/totp/confirm:codefrom the app being enrolled. Activates the authenticator and rotates the session with the factor recorded, since the code just proved it. -
defaultEmailVerificationMail(
DVEmailVerification v) → DVMailMessage - The mail a verification code goes out in when nothing more specific is installed.
-
deleteAccount(
Request request) → Future< Response> -
POST /auth/account/delete:confirm: true, the account'spassword, and acodeorrecoveryCodewhen it has a second factor. -
deliversToken(
Request request) → bool -
Whether the session issued to
requestgoes in the response body rather than a cookie: a client that asked, and is not a browser. -
eraseDueDeletions(
) → Future< int> - Queues an erasure for every deletion whose window has closed, and works them here, answering how many completed.
-
eraseScheduledAccount(
DVAccountErasureJob job) → Future< void> -
Runs
job: erases the account and removes it, when its deletion is still scheduled and its window has closed. -
factors(
Request request) → Future< Response> -
GET /auth/factors: whether the signed-in person has an authenticator and how many unspent recovery codes. A count, never a code. -
install(
{required DVCredentialGuard credentials, DVSecondFactors? secondFactors, Duration secondFactorWindow = const Duration(minutes: 10), Duration stepUpWindow = const Duration(minutes: 10), Future< void> sendEmailVerification(String email, String code)?, DVPrivacy? privacy, DVAuthTokens? verificationTokens, DVEmailVerificationMail? emailVerificationMail}) → void -
Makes these endpoints sign people in through
credentials, withsecondFactorswhen accounts may have one. -
isBrowser(
Request request) → bool -
Whether
requestcame from a page in a browser. -
recoveryCodes(
Request request) → Future< Response> -
POST /auth/factors/recovery-codes: a new set of recovery codes, replacing every earlier one, answered this once. Stored only as salted HMACs, so no endpoint can show them again. -
registerAccountErasureJob(
) → void -
Registers DVAccountErasureJob's codec and handler with
DVQueues. -
removeFactor(
Request request) → Future< Response> -
POST /auth/factors/remove:codefrom the authenticator, or onerecoveryCode, presented in this request. Removes the authenticator and every recovery code, and rotates the session. -
requestEmailChange(
Request request) → Future< Response> -
POST /auth/account/email:email, the address the account should move to. Sends a code to that address and changes nothing. -
requireMfa(
DVMfa policy) → Response? -
The gate a generated route declaring
mfa:runs: null when the request's session meetspolicy, otherwise the refusal to answer with. -
revoke(
Request request) → Future< Response> -
POST /auth/sessions/revoke:id, one of the signed-in person's own sessions. Anything else is 404, so a guessed id says nothing about whether it belongs to somebody. -
revokeOthers(
Request request) → Future< Response> -
POST /auth/sessions/revoke-others: every other live session of the signed-in person on this tenant. Answers how many. -
secondFactor(
Request request) → Future< Response> -
POST /auth/second-factor:codefrom the account's authenticator, or onerecoveryCode, presented with the session the sign-in issued. -
session(
Request request) → Future< Response> -
GET /auth/session: the session this request authenticated with. -
sessions(
Request request) → Future< Response> -
GET /auth/sessions: every live session of the signed-in person on this tenant, newest sign-in first, with this one marked current. -
signIn(
Request request) → Future< Response> -
POST /auth/sign-in:emailandpassword. -
signOut(
Request request) → Future< Response> -
POST /auth/sign-out: revokes the session the request carries, on the server, and clears the cookie. Answers 204 whether or not there was a live session, so a client can always finish signing out. -
signUp(
Request request) → Future< Response> -
POST /auth/sign-up:email,password, optionallynameand a botchallengetoken. -
sourceOf(
Request request) → String -
Who a velocity limit counts
requestagainst: its client address, as DVClientAddress resolves it -- the connection's peer, or the client a trusted proxy reports. -
stepUpRequired(
DVMfa policy) → Response -
The refusal for a session whose second factor is missing or older than
policyallows (DV-SESSION-001): RFC 9470'sinsufficient_user_authentication, withmax_agewhen the policy has a window, so a client asks for a code rather than for a sign-in. -
uninstall(
) → void - Takes the installed provider away, for a test.
-
useDeletionGracePeriod(
Duration grace) → void -
Sets deletionGracePeriod:
dartvel.auth.deletionGraceDays, installed by the generated server. Survives install. -
useGeneratedEmailVerificationMail(
DVEmailVerificationMail template) → void -
The verification mail the generated server builds from the project --
its name in the subject. Called by the generated server; an
emailVerificationMailpassed to install wins over it, and it survives install because the application installs its provider without knowing the server did this. -
verifyEmailChange(
Request request) → Future< Response> -
POST /auth/account/email/verify:code, as the new address received it. The address changes now, and the session rotates.
Constants
- accountErasureQueue → const String
- The queue DVAccountErasureJob runs on.
- accountPath → const String
- deleteAccountPath → const String
- deliveryHeader → const String
-
Sent as
tokenby a native client that keeps the session token itself. A browser never gets the token in a body, whatever this says. - deviceHeader → const String
- What the platform reports the device as, recorded on the session.
- emailChangePath → const String
- emailVerifyPath → const String
- factorsPath → const String
- maxBodyBytes → const int
- The most a body to these endpoints may be.
- passwordPath → const String
-
paths
→ const List<
String> - Every path these endpoints are served under, below the API base path.
- recoveryCodesPath → const String
- removeFactorPath → const String
- revokeOthersPath → const String
- revokePath → const String
- secondFactorPath → const String
- sessionPath → const String
- sessionsPath → const String
- signInPath → const String
- signOutPath → const String
- signUpPath → const String
- staleErasureClaim → const Duration
- How long an erasure may hold a deletion before a sweep takes it again, for a process that stopped half way through one.
- totpConfirmPath → const String
- totpPath → const String