05/19 Enhance codes 5

This commit is contained in:
2026-05-19 11:19:20 -04:00
parent 8ea6c8f647
commit 1a51fbb673
3 changed files with 5 additions and 3 deletions
+3
View File
@@ -282,6 +282,9 @@ def mfa_enable():
if not pyotp.TOTP(secret).verify(totp_code, valid_window=1):
return jsonify({'error': 'Invalid verification code'}), 400
# Encrypt the secret before replay check so totp_secret_enc/totp_iv are defined.
totp_secret_enc, totp_iv = encrypt_totp_secret(secret)
# Prevent replay: reject a code that was already consumed within the valid window.
# user.id is not yet persisted (MFA not enabled), so use g.current_user_id directly.
if is_totp_code_used(g.current_user_id, totp_code):
+1 -2
View File
@@ -39,7 +39,6 @@ from webauthn.helpers.structs import (
from webauthn.helpers.exceptions import (
InvalidCBORData,
InvalidRegistrationResponse,
InvalidAuthenticationResponse,
)
from flask import Blueprint, request, jsonify, g, session, current_app
@@ -402,4 +401,4 @@ def delete_credential(cred_id):
ip_address=client_ip(),
)
db.session.commit()
return jsonify({'message': 'Passkey removed'}), 200
return jsonify({'message': 'Passkey removed'}), 200