do_solve_mfa_challenge.h (2984B)
1 /* 2 This file is part of TALER 3 Copyright (C) 2025 Taler Systems SA 4 5 TALER is free software; you can redistribute it and/or modify it under the 6 terms of the GNU General Public License as published by the Free Software 7 Foundation; either version 3, or (at your option) any later version. 8 9 TALER is distributed in the hope that it will be useful, but WITHOUT ANY 10 WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR 11 A PARTICULAR PURPOSE. See the GNU General Public License for more details. 12 13 You should have received a copy of the GNU General Public License along with 14 TALER; see the file COPYING. If not, see <http://www.gnu.org/licenses/> 15 */ 16 /** 17 * @file src/include/merchant-database/do_do_solve_mfa_challenge.h 18 * @brief implementation of the do_solve_mfa_challenge function for Postgres 19 * @author Christian Grothoff 20 */ 21 #ifndef MERCHANT_DATABASE_DO_SOLVE_MFA_CHALLENGE_H 22 #define MERCHANT_DATABASE_DO_SOLVE_MFA_CHALLENGE_H 23 24 #include <taler/taler_util.h> 25 #include <taler/taler_json_lib.h> 26 #include "merchantdb_lib.h" 27 28 29 struct TALER_MERCHANTDB_PostgresContext; 30 /** 31 * Attempt to solve new multi-factor authorization (MFA) challenge. 32 * Checks the solution against the code in the database and updates 33 * the solution state and (on failure) retry counter depending on 34 * the result. 35 * 36 * Solving a challenge is idempotent: if the challenge was already 37 * confirmed, @a solved is set to true and @a retry_counter is left 38 * unchanged, whatever @a solution says. This does not weaken the 39 * authorization, which is granted by the confirmation already stored 40 * in the database (see TALER_MERCHANTDB_get_mfa_challenge()) and not 41 * by this function; and reaching that state already requires knowing 42 * the @a challenge_id together with the matching @a h_body, which is 43 * exactly the capability that authorizes the operation. Not touching 44 * the retry counter here keeps a client that retries after a lost 45 * response from burning its remaining attempts. 46 * 47 * @param pg database context 48 * @param challenge_id challenge ID to be solved 49 * @param h_body body of the operation the challenge authorizes 50 * @param solution proposed solution to be checked against the actual code 51 * @param[out] solved set to true if the challenge was solved by 52 * @a solution, or was already confirmed before 53 * @param[out] retry_counter set to the number of attempts that remain 54 * for solving the challenge (after this time) 55 * @return database result code 56 */ 57 enum GNUNET_DB_QueryStatus 58 TALER_MERCHANTDB_do_solve_mfa_challenge (struct TALER_MERCHANTDB_PostgresContext *pg, 59 uint64_t challenge_id, 60 const struct TALER_MERCHANT_MFA_BodyHash *h_body, 61 const char *solution, 62 bool *solved, 63 uint32_t *retry_counter); 64 65 #endif