confirmTotp static method
POST /auth/factors/totp/confirm: code from the app being enrolled.
Activates the authenticator and rotates the session with the factor
recorded, since the code just proved it.
Implementation
static Future<Response> confirmTotp(Request request) => _guard(() async {
final DVSessionPrincipal? principal = DVSessionPrincipal.current;
if (principal == null) return _unauthenticated();
final DVCredentialGuard? guard = _credentials;
if (guard == null) return _notConfigured();
final DVSecondFactors? factors = _secondFactors;
if (factors == null) return _text(404, 'Not Found');
final _Body body = await _body(request);
final Response? refused = body.refused;
if (refused != null) return refused;
final String? code = body.string('code');
if (code == null) {
return _error(400, 'invalid_request', 'A code is required.');
}
final Response? failed = await _presentFactor(
guard,
request,
principal.userId,
() => factors.confirmTotp(principal.userId, code),
);
if (failed != null) return failed;
// The other half. A no-op for anybody who is not the first owner.
await DVFirstRunOwner.recordSecondFactor(principal.userId);
final _Rotated? rotated =
await _rotate(request, factorPresented: true);
if (rotated == null) return _unauthenticated();
return _deliver(request, rotated.stage, rotated.issued, <String, Object?>{
'factors': await _factorStatus(factors, principal.userId),
}, bearer: rotated.bearer);
});