Search by

componenta / auth-otp

Shelamkoff

Bound one-time-code authentication challenges for Componenta Auth 3

Package info

github.com/componenta/auth-otp

pkg:composer/componenta/auth-otp

Statistics

Installs: 4

Dependents: 0

Suggesters: 0

Stars: 0

Open Issues: 0

v1.0.0 2026-09-27 22:33 UTC

This package is auto-updated.

Last update: 2026-09-27 22:46:47 UTC


README

Generic one-time-code challenges for Componenta Auth 3.

OTP is a proof mechanism, not an email-login package. Purpose and channel are bounded extensible identifiers. Browser login binds the challenge to a short-lived pre-authentication transaction; reauthentication binds it to the current public AuthSession UUID.

Security properties:

  • CSPRNG 6-8 digit codes;
  • HMAC-SHA-256 verifier with challenge/purpose domain separation;
  • plaintext code is never persisted;
  • single-use atomic verification;
  • per-challenge attempt limit;
  • aggregate subject+purpose failure budget survives resend/new challenge;
  • resend cooldown;
  • generic public invalid-code denial;
  • channel-specific evidence never upgrades itself to MFA/phishing resistance.