Search by

componenta / auth-totp

Shelamkoff

Encrypted TOTP enrollment and reauthentication for Componenta Auth 3

Package info

github.com/componenta/auth-totp

pkg:composer/componenta/auth-totp

Statistics

Installs: 2

Dependents: 0

Suggesters: 0

Stars: 0

Open Issues: 0

v1.0.0 2026-09-27 22:33 UTC

This package is auto-updated.

Last update: 2026-09-27 22:47:03 UTC


README

Encrypted TOTP enrollment and reauthentication for Componenta Auth 3.

The package uses spomky-labs/otphp for RFC 6238 verification and libsodium XChaCha20-Poly1305 for secret encryption at rest.

Security properties:

  • raw TOTP secrets are returned only during enrollment and are never stored;
  • database rows contain authenticated ciphertext + nonce + key id;
  • accepted time steps are persisted and cannot be replayed;
  • enrollment must be confirmed with a valid code before the credential becomes active;
  • pending enrollment secrets expire after a bounded server-side TTL (10 minutes by default);
  • TOTP evidence adds a possession factor but never claims phishing resistance;
  • successful reauthentication rotates the active SessionCredential.