keystone.auth.plugins.totp module

Time-based One-time Password Algorithm (TOTP) auth plugin.

TOTP is an algorithm that computes a one-time password from a shared secret key and the current time.

TOTP is an implementation of a hash-based message authentication code (HMAC). It combines a secret key with the current timestamp using a cryptographic hash function to generate a one-time password. The timestamp typically increases in 30-second intervals, so passwords generated close together in time from the same secret key will be equal.

class keystone.auth.plugins.totp.TOTP[source]

Bases: AuthMethodHandler

authenticate(auth_payload)[source]

Try to authenticate using TOTP.

keystone.auth.plugins.totp.verify_totp_passcode(user_id, passcode)[source]

Check passcode against user_id’s stored TOTP credential(s).

Shared by the TOTP auth plugin and by any other code path that needs to verify a fresh, current TOTP passcode outside of full authentication (e.g. re-verification before a sensitive account action, see keystone.api._shared.mfa_reverification). Enforces the same reject-on-reuse behavior as login (LP#2157347): a passcode accepted here cannot be replayed for login or for another re-verification check.

Returns:

True if the passcode is valid and not a replay, else False.