DVAuthEndpoints class

Handlers for the generated auth routes.

Each runs inside the request's tenant scope. session, sessions, revoke and revokeOthers also run behind the authentication stage and read DVSessionPrincipal.current; the others judge the session they are given themselves, because a session waiting for its second factor -- which the stage refuses -- is the one those endpoints exist to finish or end. CSRF is the generated route's to check, as on every other POST.

Properties

hashCode → int
The hash code for this object.
no setterinherited
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited

Methods

noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
toString() → String
A string representation of this object.
inherited

Operators

operator ==(Object other) → bool
The equality operator.
inherited

Static Properties

accountDirectory → DVAccountDirectory?
The installed provider, when it can describe an account by its id.
no setter
clock ↔ DateTime Function()
The time deletion windows are measured by. A test moves it; nothing else should.
getter/setter pair
deletionGracePeriod → Duration
How long a deleted account waits before it is erased, during which signing in cancels the deletion. Zero erases at once.
no setter
installed → bool
Whether a provider is installed in this process.
no setter

Static Methods

account(Request request) → Future<Response>
GET /auth/account: the signed-in person's account, with an address change still waiting for its code.
beginTotp(Request request) → Future<Response>
POST /auth/factors/totp: starts enrolling an authenticator app and answers its secret and the otpauth:// URI a QR code encodes.
changePassword(Request request) → Future<Response>
POST /auth/account/password: currentPassword, newPassword, and on an account with a second factor a code or recoveryCode unless one was presented on this session within the step-up window.
confirmTotp(Request request) → Future<Response>
POST /auth/factors/totp/confirm: code from the app being enrolled. Activates the authenticator and rotates the session with the factor recorded, since the code just proved it.
defaultEmailVerificationMail(DVEmailVerification v) → DVMailMessage
The mail a verification code goes out in when nothing more specific is installed.
deleteAccount(Request request) → Future<Response>
POST /auth/account/delete: confirm: true, the account's password, and a code or recoveryCode when it has a second factor.
deliversToken(Request request) → bool
Whether the session issued to request goes in the response body rather than a cookie: a client that asked, and is not a browser.
eraseDueDeletions() → Future<int>
Queues an erasure for every deletion whose window has closed, and works them here, answering how many completed.
eraseScheduledAccount(DVAccountErasureJob job) → Future<void>
Runs job: erases the account and removes it, when its deletion is still scheduled and its window has closed.
factors(Request request) → Future<Response>
GET /auth/factors: whether the signed-in person has an authenticator and how many unspent recovery codes. A count, never a code.
install({required DVCredentialGuard credentials, DVSecondFactors? secondFactors, Duration secondFactorWindow = const Duration(minutes: 10), Duration stepUpWindow = const Duration(minutes: 10), Future<void> sendEmailVerification(String email, String code)?, DVPrivacy? privacy, DVAuthTokens? verificationTokens, DVEmailVerificationMail? emailVerificationMail}) → void
Makes these endpoints sign people in through credentials, with secondFactors when accounts may have one.
isBrowser(Request request) → bool
Whether request came from a page in a browser.
recoveryCodes(Request request) → Future<Response>
POST /auth/factors/recovery-codes: a new set of recovery codes, replacing every earlier one, answered this once. Stored only as salted HMACs, so no endpoint can show them again.
registerAccountErasureJob() → void
Registers DVAccountErasureJob's codec and handler with DVQueues.
removeFactor(Request request) → Future<Response>
POST /auth/factors/remove: code from the authenticator, or one recoveryCode, presented in this request. Removes the authenticator and every recovery code, and rotates the session.
requestEmailChange(Request request) → Future<Response>
POST /auth/account/email: email, the address the account should move to. Sends a code to that address and changes nothing.
requireMfa(DVMfa policy) → Response?
The gate a generated route declaring mfa: runs: null when the request's session meets policy, otherwise the refusal to answer with.
revoke(Request request) → Future<Response>
POST /auth/sessions/revoke: id, one of the signed-in person's own sessions. Anything else is 404, so a guessed id says nothing about whether it belongs to somebody.
revokeOthers(Request request) → Future<Response>
POST /auth/sessions/revoke-others: every other live session of the signed-in person on this tenant. Answers how many.
secondFactor(Request request) → Future<Response>
POST /auth/second-factor: code from the account's authenticator, or one recoveryCode, presented with the session the sign-in issued.
session(Request request) → Future<Response>
GET /auth/session: the session this request authenticated with.
sessions(Request request) → Future<Response>
GET /auth/sessions: every live session of the signed-in person on this tenant, newest sign-in first, with this one marked current.
signIn(Request request) → Future<Response>
POST /auth/sign-in: email and password.
signOut(Request request) → Future<Response>
POST /auth/sign-out: revokes the session the request carries, on the server, and clears the cookie. Answers 204 whether or not there was a live session, so a client can always finish signing out.
signUp(Request request) → Future<Response>
POST /auth/sign-up: email, password, optionally name and a bot challenge token.
sourceOf(Request request) → String
Who a velocity limit counts request against: its client address, as DVClientAddress resolves it -- the connection's peer, or the client a trusted proxy reports.
stepUpRequired(DVMfa policy) → Response
The refusal for a session whose second factor is missing or older than policy allows (DV-SESSION-001): RFC 9470's insufficient_user_authentication, with max_age when the policy has a window, so a client asks for a code rather than for a sign-in.
uninstall() → void
Takes the installed provider away, for a test.
useDeletionGracePeriod(Duration grace) → void
Sets deletionGracePeriod: dartvel.auth.deletionGraceDays, installed by the generated server. Survives install.
useGeneratedEmailVerificationMail(DVEmailVerificationMail template) → void
The verification mail the generated server builds from the project -- its name in the subject. Called by the generated server; an emailVerificationMail passed to install wins over it, and it survives install because the application installs its provider without knowing the server did this.
verifyEmailChange(Request request) → Future<Response>
POST /auth/account/email/verify: code, as the new address received it. The address changes now, and the session rotates.

Constants

accountErasureQueue → const String
The queue DVAccountErasureJob runs on.
accountPath → const String
deleteAccountPath → const String
deliveryHeader → const String
Sent as token by a native client that keeps the session token itself. A browser never gets the token in a body, whatever this says.
deviceHeader → const String
What the platform reports the device as, recorded on the session.
emailChangePath → const String
emailVerifyPath → const String
factorsPath → const String
maxBodyBytes → const int
The most a body to these endpoints may be.
passwordPath → const String
paths → const List<String>
Every path these endpoints are served under, below the API base path.
recoveryCodesPath → const String
removeFactorPath → const String
revokeOthersPath → const String
revokePath → const String
secondFactorPath → const String
sessionPath → const String
sessionsPath → const String
signInPath → const String
signOutPath → const String
signUpPath → const String
staleErasureClaim → const Duration
How long an erasure may hold a deletion before a sweep takes it again, for a process that stopped half way through one.
totpConfirmPath → const String
totpPath → const String