Compare commits
30 Commits
f4385d172e
...
develop
| Author | SHA1 | Date | |
|---|---|---|---|
|
849a0d022f
|
|||
|
99ef6f2085
|
|||
|
a2051dbd85
|
|||
|
767665180a
|
|||
|
8b0f24c6b4
|
|||
|
baf897e9e3
|
|||
|
e43fc4de86
|
|||
|
733d633753
|
|||
|
f5f073168d
|
|||
|
59f7d925a3
|
|||
|
d2b901a6ff
|
|||
|
f85e22311d
|
|||
|
37bbe35482
|
|||
|
8870703608
|
|||
|
25e6fcdeab
|
|||
|
62cbe2de3b
|
|||
|
52f0ab0661
|
|||
|
e5bb1f5a44
|
|||
|
62d5438b3b
|
|||
|
aa686cd81e
|
|||
|
2804576658
|
|||
|
49acfddde7
|
|||
|
498a5b5826
|
|||
| e8999ae4e4 | |||
|
bb5cd2878b
|
|||
|
8b9a7ec26e
|
|||
|
acc080b65e
|
|||
|
f32ebaf416
|
|||
|
633263c541
|
|||
|
ba1c983094
|
@@ -1,36 +0,0 @@
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
|
||||
env:
|
||||
GIT__TOKEN: ${{ secrets.TOKEN }}
|
||||
|
||||
jobs:
|
||||
publish:
|
||||
runs-on: linux
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
- uses: actions/cache/restore@v4
|
||||
with:
|
||||
key: gradle
|
||||
path: |
|
||||
~/.gradle/caches/
|
||||
~/.gradle/wrapper/
|
||||
~/.konan/
|
||||
|
||||
- uses: actions/setup-java@v4
|
||||
with:
|
||||
java-version: '24'
|
||||
distribution: 'temurin'
|
||||
|
||||
- run: ./gradlew publish
|
||||
|
||||
- uses: actions/cache/save@v4
|
||||
with:
|
||||
key: gradle
|
||||
path: |
|
||||
~/.gradle/caches/
|
||||
~/.gradle/wrapper/
|
||||
~/.konan/
|
||||
47
.gitea/workflows/publish.yaml
Normal file
47
.gitea/workflows/publish.yaml
Normal file
@@ -0,0 +1,47 @@
|
||||
on:
|
||||
push:
|
||||
branches: [ main ]
|
||||
|
||||
jobs:
|
||||
publish:
|
||||
runs-on: linux
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Setup Java
|
||||
uses: actions/setup-java@v4
|
||||
with:
|
||||
java-version: '24'
|
||||
distribution: 'temurin'
|
||||
|
||||
- name: Cache Gradle
|
||||
uses: actions/cache@v4
|
||||
with:
|
||||
key: gradle-${{ hashFiles('**/libs.versions.toml') }}
|
||||
restore-keys: gradle
|
||||
path: |
|
||||
~/.gradle/caches/
|
||||
~/.gradle/wrapper/
|
||||
|
||||
- name: Cache Konan
|
||||
uses: actions/cache@v4
|
||||
with:
|
||||
key: konan-${{ hashFiles('**/libs.versions.toml') }}
|
||||
restore-keys: konan
|
||||
path: |
|
||||
~/.konan/
|
||||
|
||||
- name: Cache Node
|
||||
uses: actions/cache@v4
|
||||
with:
|
||||
key: node-${{ hashFiles('**/libs.versions.toml') }}
|
||||
restore-keys: node
|
||||
path: |
|
||||
~/.gradle/nodejs
|
||||
~/.gradle/yarn
|
||||
|
||||
- name: Publish
|
||||
run: ./gradlew publish
|
||||
env:
|
||||
INFENDRO__TOKEN: ${{ secrets.TOKEN }}
|
||||
28
.gitea/workflows/test.yaml
Normal file
28
.gitea/workflows/test.yaml
Normal file
@@ -0,0 +1,28 @@
|
||||
on:
|
||||
pull_request:
|
||||
branches: [ main ]
|
||||
|
||||
jobs:
|
||||
test:
|
||||
runs-on: linux
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Setup Java
|
||||
uses: actions/setup-java@v4
|
||||
with:
|
||||
java-version: '24'
|
||||
distribution: 'temurin'
|
||||
|
||||
- name: Cache Gradle
|
||||
uses: actions/cache@v4
|
||||
with:
|
||||
key: gradle-${{ hashFiles('**/libs.versions.toml') }}
|
||||
restore-keys: gradle
|
||||
path: |
|
||||
~/.gradle/caches/
|
||||
~/.gradle/wrapper/
|
||||
|
||||
- name: Test
|
||||
run: ./gradlew jvmTest
|
||||
40
README.md
Normal file
40
README.md
Normal file
@@ -0,0 +1,40 @@
|
||||
# otp.kt
|
||||
|
||||
`otp.kt` is a Kotlin Multiplatform library that provides common [One-Time Password](https://en.wikipedia.org/wiki/One-time_password) algorithms.
|
||||
|
||||
Supported algorithms:
|
||||
- HOTP
|
||||
- TOTP
|
||||
|
||||
## Installation
|
||||
|
||||
Add the following to your `build.gradle.kts`.
|
||||
|
||||
```kotlin
|
||||
repositories {
|
||||
maven("https://git.infendro.com/api/packages/Infendro/maven")
|
||||
}
|
||||
|
||||
dependencies {
|
||||
implementation("com.infendro:otp:1.3.1")
|
||||
}
|
||||
```
|
||||
|
||||
## Usage
|
||||
|
||||
```kotlin
|
||||
fun main() {
|
||||
// create TOTP instance
|
||||
val totp = TOTP(
|
||||
function = SHA1(),
|
||||
length = 6,
|
||||
period = 30.seconds,
|
||||
)
|
||||
|
||||
// generate and verify OTP
|
||||
val secret = "...".encodeToByteArray()
|
||||
val time = System.now()
|
||||
val otp = totp.generate(secret, time)
|
||||
totp.verify(secret, time, otp)
|
||||
}
|
||||
```
|
||||
@@ -1,56 +1,43 @@
|
||||
group = "com.infendro"
|
||||
version = "1.1.0"
|
||||
@file:OptIn(ExperimentalWasmDsl::class)
|
||||
|
||||
repositories {
|
||||
maven("https://git.infendro.com/api/packages/Infendro/maven")
|
||||
mavenCentral()
|
||||
}
|
||||
import com.infendro.plugin.infendro
|
||||
import com.infendro.plugin.token
|
||||
import org.jetbrains.kotlin.gradle.ExperimentalWasmDsl
|
||||
|
||||
group = "com.infendro"
|
||||
version = "1.3.1"
|
||||
|
||||
plugins {
|
||||
alias(libs.plugins.infendro)
|
||||
alias(libs.plugins.multiplatform)
|
||||
id("maven-publish")
|
||||
}
|
||||
|
||||
kotlin {
|
||||
jvm()
|
||||
js {
|
||||
nodejs()
|
||||
}
|
||||
linuxX64()
|
||||
linuxArm64()
|
||||
mingwX64()
|
||||
macosX64()
|
||||
macosArm64()
|
||||
js { nodejs() }
|
||||
wasmJs { nodejs() }
|
||||
wasmWasi { nodejs() }
|
||||
|
||||
repositories {
|
||||
infendro()
|
||||
mavenCentral()
|
||||
}
|
||||
|
||||
sourceSets {
|
||||
commonMain.dependencies {
|
||||
implementation(libs.bytes)
|
||||
implementation(libs.hash)
|
||||
implementation(libs.mac)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
publishing {
|
||||
repositories {
|
||||
maven {
|
||||
url = uri("https://git.infendro.com/api/packages/Infendro/maven")
|
||||
authentication.create("header", HttpHeaderAuthentication::class)
|
||||
credentials(HttpHeaderCredentials::class) {
|
||||
val token = secret("git.token") ?: throw GradleException()
|
||||
|
||||
name = "Authorization"
|
||||
value = "token $token"
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
fun secret(
|
||||
key: String,
|
||||
): String? {
|
||||
val property = key
|
||||
val environment = key
|
||||
.uppercase()
|
||||
.replace(".", "__")
|
||||
|
||||
val prop = properties[property] as String?
|
||||
val env = System.getenv(environment)
|
||||
|
||||
return prop ?: env
|
||||
publishing.repositories {
|
||||
infendro(token)
|
||||
}
|
||||
|
||||
@@ -1,11 +1,15 @@
|
||||
[versions]
|
||||
kotlin = "2.1.20"
|
||||
hash = "1.1.0"
|
||||
mac = "1.1.0"
|
||||
infendro = "1.1.0"
|
||||
kotlin = "2.3.0"
|
||||
bytes = "1.4.2"
|
||||
hash = "1.7.0"
|
||||
mac = "1.5.0"
|
||||
|
||||
[plugins]
|
||||
infendro = { id = "com.infendro.plugin", version.ref = "infendro" }
|
||||
multiplatform = { id = "org.jetbrains.kotlin.multiplatform", version.ref = "kotlin" }
|
||||
|
||||
[libraries]
|
||||
bytes = { module = "com.infendro:bytes", version.ref = "bytes" }
|
||||
hash = { module = "com.infendro:hash", version.ref = "hash" }
|
||||
mac = { module = "com.infendro:mac", version.ref = "mac" }
|
||||
|
||||
BIN
gradle/wrapper/gradle-wrapper.jar
vendored
BIN
gradle/wrapper/gradle-wrapper.jar
vendored
Binary file not shown.
2
gradle/wrapper/gradle-wrapper.properties
vendored
2
gradle/wrapper/gradle-wrapper.properties
vendored
@@ -1,6 +1,6 @@
|
||||
distributionBase=GRADLE_USER_HOME
|
||||
distributionPath=wrapper/dists
|
||||
distributionUrl=https\://services.gradle.org/distributions/gradle-8.5-bin.zip
|
||||
distributionUrl=https\://services.gradle.org/distributions/gradle-8.14-bin.zip
|
||||
networkTimeout=10000
|
||||
validateDistributionUrl=true
|
||||
zipStoreBase=GRADLE_USER_HOME
|
||||
|
||||
12
gradlew
vendored
12
gradlew
vendored
@@ -15,6 +15,8 @@
|
||||
# See the License for the specific language governing permissions and
|
||||
# limitations under the License.
|
||||
#
|
||||
# SPDX-License-Identifier: Apache-2.0
|
||||
#
|
||||
|
||||
##############################################################################
|
||||
#
|
||||
@@ -55,7 +57,7 @@
|
||||
# Darwin, MinGW, and NonStop.
|
||||
#
|
||||
# (3) This script is generated from the Groovy template
|
||||
# https://github.com/gradle/gradle/blob/HEAD/subprojects/plugins/src/main/resources/org/gradle/api/internal/plugins/unixStartScript.txt
|
||||
# https://github.com/gradle/gradle/blob/HEAD/platforms/jvm/plugins-application/src/main/resources/org/gradle/api/internal/plugins/unixStartScript.txt
|
||||
# within the Gradle project.
|
||||
#
|
||||
# You can find Gradle at https://github.com/gradle/gradle/.
|
||||
@@ -84,7 +86,7 @@ done
|
||||
# shellcheck disable=SC2034
|
||||
APP_BASE_NAME=${0##*/}
|
||||
# Discard cd standard output in case $CDPATH is set (https://github.com/gradle/gradle/issues/25036)
|
||||
APP_HOME=$( cd "${APP_HOME:-./}" > /dev/null && pwd -P ) || exit
|
||||
APP_HOME=$( cd -P "${APP_HOME:-./}" > /dev/null && printf '%s\n' "$PWD" ) || exit
|
||||
|
||||
# Use the maximum available, or set MAX_FD != -1 to use that value.
|
||||
MAX_FD=maximum
|
||||
@@ -112,7 +114,7 @@ case "$( uname )" in #(
|
||||
NONSTOP* ) nonstop=true ;;
|
||||
esac
|
||||
|
||||
CLASSPATH=$APP_HOME/gradle/wrapper/gradle-wrapper.jar
|
||||
CLASSPATH="\\\"\\\""
|
||||
|
||||
|
||||
# Determine the Java command to use to start the JVM.
|
||||
@@ -203,7 +205,7 @@ fi
|
||||
DEFAULT_JVM_OPTS='"-Xmx64m" "-Xms64m"'
|
||||
|
||||
# Collect all arguments for the java command:
|
||||
# * DEFAULT_JVM_OPTS, JAVA_OPTS, JAVA_OPTS, and optsEnvironmentVar are not allowed to contain shell fragments,
|
||||
# * DEFAULT_JVM_OPTS, JAVA_OPTS, and optsEnvironmentVar are not allowed to contain shell fragments,
|
||||
# and any embedded shellness will be escaped.
|
||||
# * For example: A user cannot expect ${Hostname} to be expanded, as it is an environment variable and will be
|
||||
# treated as '${Hostname}' itself on the command line.
|
||||
@@ -211,7 +213,7 @@ DEFAULT_JVM_OPTS='"-Xmx64m" "-Xms64m"'
|
||||
set -- \
|
||||
"-Dorg.gradle.appname=$APP_BASE_NAME" \
|
||||
-classpath "$CLASSPATH" \
|
||||
org.gradle.wrapper.GradleWrapperMain \
|
||||
-jar "$APP_HOME/gradle/wrapper/gradle-wrapper.jar" \
|
||||
"$@"
|
||||
|
||||
# Stop when "xargs" is not available.
|
||||
|
||||
26
gradlew.bat
vendored
26
gradlew.bat
vendored
@@ -13,6 +13,8 @@
|
||||
@rem See the License for the specific language governing permissions and
|
||||
@rem limitations under the License.
|
||||
@rem
|
||||
@rem SPDX-License-Identifier: Apache-2.0
|
||||
@rem
|
||||
|
||||
@if "%DEBUG%"=="" @echo off
|
||||
@rem ##########################################################################
|
||||
@@ -43,11 +45,11 @@ set JAVA_EXE=java.exe
|
||||
%JAVA_EXE% -version >NUL 2>&1
|
||||
if %ERRORLEVEL% equ 0 goto execute
|
||||
|
||||
echo.
|
||||
echo ERROR: JAVA_HOME is not set and no 'java' command could be found in your PATH.
|
||||
echo.
|
||||
echo Please set the JAVA_HOME variable in your environment to match the
|
||||
echo location of your Java installation.
|
||||
echo. 1>&2
|
||||
echo ERROR: JAVA_HOME is not set and no 'java' command could be found in your PATH. 1>&2
|
||||
echo. 1>&2
|
||||
echo Please set the JAVA_HOME variable in your environment to match the 1>&2
|
||||
echo location of your Java installation. 1>&2
|
||||
|
||||
goto fail
|
||||
|
||||
@@ -57,22 +59,22 @@ set JAVA_EXE=%JAVA_HOME%/bin/java.exe
|
||||
|
||||
if exist "%JAVA_EXE%" goto execute
|
||||
|
||||
echo.
|
||||
echo ERROR: JAVA_HOME is set to an invalid directory: %JAVA_HOME%
|
||||
echo.
|
||||
echo Please set the JAVA_HOME variable in your environment to match the
|
||||
echo location of your Java installation.
|
||||
echo. 1>&2
|
||||
echo ERROR: JAVA_HOME is set to an invalid directory: %JAVA_HOME% 1>&2
|
||||
echo. 1>&2
|
||||
echo Please set the JAVA_HOME variable in your environment to match the 1>&2
|
||||
echo location of your Java installation. 1>&2
|
||||
|
||||
goto fail
|
||||
|
||||
:execute
|
||||
@rem Setup the command line
|
||||
|
||||
set CLASSPATH=%APP_HOME%\gradle\wrapper\gradle-wrapper.jar
|
||||
set CLASSPATH=
|
||||
|
||||
|
||||
@rem Execute Gradle
|
||||
"%JAVA_EXE%" %DEFAULT_JVM_OPTS% %JAVA_OPTS% %GRADLE_OPTS% "-Dorg.gradle.appname=%APP_BASE_NAME%" -classpath "%CLASSPATH%" org.gradle.wrapper.GradleWrapperMain %*
|
||||
"%JAVA_EXE%" %DEFAULT_JVM_OPTS% %JAVA_OPTS% %GRADLE_OPTS% "-Dorg.gradle.appname=%APP_BASE_NAME%" -classpath "%CLASSPATH%" -jar "%APP_HOME%\gradle\wrapper\gradle-wrapper.jar" %*
|
||||
|
||||
:end
|
||||
@rem End local scope for the variables with windows NT shell
|
||||
|
||||
@@ -1 +1,6 @@
|
||||
rootProject.name = "otp"
|
||||
|
||||
pluginManagement.repositories {
|
||||
maven("https://git.infendro.com/api/packages/Infendro/maven")
|
||||
mavenCentral()
|
||||
}
|
||||
|
||||
@@ -1,58 +1,32 @@
|
||||
package com.infendro.otp
|
||||
|
||||
import com.infendro.bytes.bytearray.toInt
|
||||
import com.infendro.bytes.long.toByteArray
|
||||
import com.infendro.hash.HashFunction
|
||||
import com.infendro.hash.SHA1
|
||||
import com.infendro.hash.sha1.SHA1
|
||||
import com.infendro.mac.HMAC
|
||||
import com.infendro.otp.util.toByteArray
|
||||
import com.infendro.otp.util.toInt
|
||||
import com.infendro.otp.util.pow
|
||||
import kotlin.experimental.and
|
||||
import kotlin.math.pow
|
||||
|
||||
class HOTP(
|
||||
val function: HashFunction = SHA1,
|
||||
val function: HashFunction = SHA1(),
|
||||
val length: Int = 6,
|
||||
) {
|
||||
fun verify(
|
||||
secret: ByteArray,
|
||||
counter: Long,
|
||||
otp: String,
|
||||
): Boolean {
|
||||
private val hmac = HMAC(function)
|
||||
|
||||
fun generate(secret: ByteArray, counter: Long): String {
|
||||
require(counter >= 0)
|
||||
return otp(secret, counter)
|
||||
}
|
||||
|
||||
fun verify(secret: ByteArray, counter: Long, otp: String): Boolean {
|
||||
return generate(secret, counter) == otp
|
||||
}
|
||||
|
||||
fun generate(
|
||||
secret: ByteArray,
|
||||
counter: Long,
|
||||
): String {
|
||||
if (counter < 0)
|
||||
throw Exception()
|
||||
|
||||
val hash = generateHash(
|
||||
secret,
|
||||
counter.toByteArray()
|
||||
)
|
||||
return otp(hash)
|
||||
}
|
||||
|
||||
private fun generateHash(
|
||||
secret: ByteArray,
|
||||
value: ByteArray,
|
||||
): ByteArray {
|
||||
return HMAC(function).hash(secret, value)
|
||||
}
|
||||
|
||||
private fun otp(
|
||||
hash: ByteArray,
|
||||
): String {
|
||||
private fun otp(secret: ByteArray, counter: Long): String {
|
||||
val hash = hmac.hash(secret, counter.toByteArray())
|
||||
val offset = (hash.last() and 0xF).toInt()
|
||||
|
||||
var truncatedHash = hash
|
||||
.drop(offset)
|
||||
.take(4)
|
||||
.toInt() and 0x7FFFFFFF
|
||||
truncatedHash %= 10.0.pow(length).toInt()
|
||||
|
||||
return truncatedHash.toString()
|
||||
.padStart(length, '0')
|
||||
val otp = (hash.toInt(offset) and 0x7FFFFFFF) % 10.pow(length)
|
||||
return "$otp".padStart(length, '0')
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,25 +0,0 @@
|
||||
package com.infendro.otp
|
||||
|
||||
import com.infendro.hash.*
|
||||
import kotlin.random.Random
|
||||
|
||||
object SecretGenerator {
|
||||
private val random = Random.Default
|
||||
|
||||
fun generate(
|
||||
algorithm: HashFunction = SHA1,
|
||||
): ByteArray {
|
||||
val bytes = when (algorithm) {
|
||||
MD5 -> 16
|
||||
SHA1 -> 20
|
||||
SHA224 -> 28
|
||||
SHA256 -> 32
|
||||
SHA384 -> 48
|
||||
SHA512 -> 64
|
||||
}
|
||||
|
||||
return ByteArray(bytes).also {
|
||||
random.nextBytes(it)
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -1,41 +1,27 @@
|
||||
package com.infendro.otp
|
||||
|
||||
import com.infendro.hash.HashFunction
|
||||
import com.infendro.hash.SHA1
|
||||
import com.infendro.hash.sha1.SHA1
|
||||
import kotlin.time.Duration
|
||||
import kotlin.time.Duration.Companion.seconds
|
||||
import kotlin.time.ExperimentalTime
|
||||
import kotlin.time.Instant
|
||||
|
||||
@ExperimentalTime
|
||||
class TOTP(
|
||||
function: HashFunction = SHA1,
|
||||
length: Int = 6,
|
||||
val function: HashFunction = SHA1(),
|
||||
val length: Int = 6,
|
||||
val period: Duration = 30.seconds,
|
||||
) {
|
||||
val hotp = HOTP(function, length)
|
||||
private val hotp = HOTP(function, length)
|
||||
|
||||
fun verify(
|
||||
secret: ByteArray,
|
||||
instant: Instant,
|
||||
otp: String,
|
||||
): Boolean {
|
||||
fun generate(secret: ByteArray, instant: Instant): String {
|
||||
return hotp.generate(secret, counter(instant))
|
||||
}
|
||||
|
||||
fun verify(secret: ByteArray, instant: Instant, otp: String): Boolean {
|
||||
return generate(secret, instant) == otp
|
||||
}
|
||||
|
||||
fun generate(
|
||||
secret: ByteArray,
|
||||
instant: Instant,
|
||||
): String {
|
||||
return hotp.generate(
|
||||
secret,
|
||||
counter(instant)
|
||||
)
|
||||
}
|
||||
|
||||
private fun counter(
|
||||
instant: Instant,
|
||||
): Long {
|
||||
private fun counter(instant: Instant): Long {
|
||||
val ms = instant.toEpochMilliseconds()
|
||||
val d = period.inWholeMilliseconds
|
||||
return ms / d
|
||||
|
||||
@@ -1,20 +0,0 @@
|
||||
package com.infendro.otp.util
|
||||
|
||||
internal fun Long.toByteArray(): ByteArray {
|
||||
return ByteArray(8) { i ->
|
||||
val offset = (7 - i) * 8
|
||||
(this shr offset).toByte()
|
||||
}
|
||||
}
|
||||
|
||||
internal fun ByteArray.toInt(): Int {
|
||||
if (size != 4) throw Exception()
|
||||
|
||||
return fold(0) { acc, byte ->
|
||||
(acc shl 8) or (byte.toInt() and 0xFF)
|
||||
}
|
||||
}
|
||||
|
||||
internal fun Collection<Byte>.toInt(): Int {
|
||||
return toByteArray().toInt()
|
||||
}
|
||||
6
src/commonMain/kotlin/com/infendro/otp/util/Math.kt
Normal file
6
src/commonMain/kotlin/com/infendro/otp/util/Math.kt
Normal file
@@ -0,0 +1,6 @@
|
||||
package com.infendro.otp.util
|
||||
|
||||
import kotlin.math.pow
|
||||
|
||||
internal fun Int.pow(x: Int): Int =
|
||||
this.toDouble().pow(x).toInt()
|
||||
Reference in New Issue
Block a user