import { encodeCrock } from "@gnu-taler/taler-util"; import { h, VNode } from "preact"; import { useMemo, useState } from "preact/hooks"; import { TextInput } from "../../../components/fields/TextInput.js"; import { QR } from "../../../components/QR.js"; import { AnastasisClientFrame } from "../index.js"; import { AuthMethodSetupProps } from "./index.js"; import { base32enc, computeTOTPandCheck } from "./totp.js"; /** * This is hard-coded in the protocol for TOTP auth. */ const ANASTASIS_TOTP_DIGITS = 8; export function AuthMethodTotpSetup({ addAuthMethod, cancel, configured, }: AuthMethodSetupProps): VNode { const [name, setName] = useState("anastasis"); const [test, setTest] = useState(""); const secretKey = useMemo(() => { const array = new Uint8Array(32); return window.crypto.getRandomValues(array); }, []); const secret32 = base32enc(secretKey); const totpURL = `otpauth://totp/${name}?digits=${ANASTASIS_TOTP_DIGITS}&secret=${secret32}`; const addTotpAuth = (): void => addAuthMethod({ authentication_method: { type: "totp", instructions: `Enter ${ANASTASIS_TOTP_DIGITS} digits code for "${name}"`, challenge: encodeCrock(secretKey), }, }); const testCodeMatches = computeTOTPandCheck(secretKey, 8, parseInt(test, 10)); const errors = !name ? "The TOTP name is missing" : !testCodeMatches ? "The test code doesnt match" : undefined; function goNextIfNoErrors(): void { if (!errors) addTotpAuth(); } return (

For Time-based One-Time Password (TOTP) authentication, you need to set a name for the TOTP secret. Then, you must scan the generated QR code with your TOTP App to import the TOTP secret into your TOTP App.

Confirm that your TOTP App works by entering the current 8-digit TOTP code here:

We note that Google's implementation of TOTP is incomplete and will not work. We recommend using FreeOTP+.
{configured.length > 0 && (
Your TOTP numbers:
{configured.map((c, i) => { return (

{c.instructions}

); })}
)}
); }