Skip to content

feat(Authenticator): add ITotpService project#417

Merged
ArgoZhang merged 10 commits intomasterfrom
dev-authenticator
Apr 27, 2025
Merged

feat(Authenticator): add ITotpService project#417
ArgoZhang merged 10 commits intomasterfrom
dev-authenticator

Conversation

@ArgoZhang
Copy link
Copy Markdown
Member

@ArgoZhang ArgoZhang commented Apr 27, 2025

Link issues

fixes #416

Summary By Copilot

Regression?

  • Yes
  • No

Risk

  • High
  • Medium
  • Low

Verification

  • Manual (required)
  • Automated

Packaging changes reviewed?

  • Yes
  • No
  • N/A

☑️ Self Check before Merge

⚠️ Please check all items below before review. ⚠️

  • Doc is updated/provided or not needed
  • Demo is updated/provided or not needed
  • Merge the latest code from the main branch

Summary by Sourcery

Add a Time-based One-Time Password (TOTP) service.

New Features:

  • Introduce ITotpService and its default implementation DefaultTotpService.
  • Provide an extension method AddBootstrapBlazorTotpService for service registration.
  • Implement TOTP generation, verification, and secret key management using the OtpNet library.

@bb-auto bb-auto Bot added the enhancement New feature or request label Apr 27, 2025
@sourcery-ai
Copy link
Copy Markdown

sourcery-ai Bot commented Apr 27, 2025

Reviewer's Guide by Sourcery

This pull request adds a new project BootstrapBlazor.Authenticator to provide TOTP/HOTP service functionality. It includes a default service implementation using the OtpNet library and an extension method to register the service in the dependency injection container.

No diagrams generated as the changes look simple and do not need a visual representation.

File-Level Changes

Change Details Files
Add new Authenticator project and integrate it into the solution.
  • Add new project file for the Authenticator component.
  • Update the solution file to include the new project.
src/components/BootstrapBlazor.Authenticator/BootstrapBlazor.Authenticator.csproj
BootstrapBlazor.Extensions.sln
Implement the default TOTP/HOTP service.
  • Add the default service class implementing ITotpService.
  • Implement methods for OTP generation, verification, and key management using the OtpNet library.
  • Add a nested class to wrap the OtpNet Totp instance.
src/components/BootstrapBlazor.Authenticator/Services/DefaultTotpService.cs
Provide extension methods for service registration and type mapping.
  • Add a service collection extension class with a method to register the TOTP service.
  • Add an extension class with helper methods for converting OTP related enums.
src/components/BootstrapBlazor.Authenticator/Extensions/ServiceCollectionExtension.cs
src/components/BootstrapBlazor.Authenticator/Extensions/OTPExtensions.cs

Assessment against linked issues

Issue Objective Addressed Explanation

Possibly linked issues


Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@bb-auto bb-auto Bot added this to the v9.2.0 milestone Apr 27, 2025
@ArgoZhang ArgoZhang merged commit b9c66b3 into master Apr 27, 2025
1 check passed
@ArgoZhang ArgoZhang deleted the dev-authenticator branch April 27, 2025 07:51
Copy link
Copy Markdown

@sourcery-ai sourcery-ai Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey @ArgoZhang - I've reviewed your changes - here's some feedback:

Overall Comments:

  • Consider removing the default/fallback hardcoded secret key ('OMM2LVLFX6QJHMYI') to ensure explicit configuration and avoid potential security risks.
  • The Verify and GetRemainingSeconds methods in DefaultTotpService rely on state (Instance) set by Compute; consider making the service stateless or clarifying the intended usage pattern, especially given its Singleton registration.
Here's what I looked at during the review
  • 🟡 General issues: 2 issues found
  • 🟢 Security: all looks good
  • 🟢 Testing: all looks good
  • 🟢 Complexity: all looks good
  • 🟢 Documentation: all looks good

Sourcery is free for open source - if you like our reviews please consider sharing them ✨
Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.

var mode = options.Algorithm.ToMode();
var uri = new OtpUri(type, options.SecretKey, options.UserName, options.IssuerName, mode, options.Digits, options.Period, options.Counter);
return uri.ToString();
}
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

question (bug_risk): Consider thread-safety concerns with the mutable Instance property.

The Instance property is updated in the Compute method and then used in GetRemainingSeconds and Verify. In concurrent scenarios, this mutable field could lead to race conditions or unexpected behavior. It might be worthwhile to review thread-safety or consider a stateless approach.

return Base32Encoding.ToBytes(input);
}

public bool Verify(string code, DateTime? timestamp = null)
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

suggestion (bug_risk): Consistent use of configured secret key in Verify method.

Similar to GetRemainingSeconds, if Instance is null, Verify creates a Totp using a hard-coded secret. It might be beneficial to ensure that verification uses the same configuration from OtpOptions to avoid unexpected results.

Suggested implementation:

var instance = new Totp(GetSecretKeyBytes(OtpOptions.Secret));
return timestamp == null ? instance.RemainingSeconds() : instance.RemainingSeconds(timestamp.Value);

Ensure that the DefaultTotpService class has the OtpOptions (or similarly named options object) properly injected and that the property containing the secret key is named "Secret". If your property name is different, please update the field accordingly.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat(Authenticator): add ITotpService project

1 participant