Class: Supabase::Auth::MFAApi

Inherits:
Object
  • Object
show all
Defined in:
lib/supabase/auth/client.rb

Overview

MFA (Multi-Factor Authentication) API. Access via Client#mfa.

Instance Method Summary collapse

Constructor Details

#initialize(client) ⇒ MFAApi

Returns a new instance of MFAApi.

Parameters:

  • client (Client)

    parent client instance



1109
1110
1111
# File 'lib/supabase/auth/client.rb', line 1109

def initialize(client)
  @client = client
end

Instance Method Details

#challenge(params) ⇒ Types::AuthMFAChallengeResponse

Create an MFA challenge for a factor.

Parameters:

  • params (Hash)

    (:factor_id)

Returns:

Raises:



1144
1145
1146
1147
1148
1149
1150
1151
1152
1153
1154
# File 'lib/supabase/auth/client.rb', line 1144

def challenge(params)
  factor_id = params[:factor_id] || params["factor_id"]
  channel = params[:channel] || params["channel"]

  session = @client.get_session
  raise Errors::AuthSessionMissing unless session

  data = @client._request("POST", "factors/#{factor_id}/challenge",
                          jwt: session.access_token, body: { channel: channel })
  Types::AuthMFAChallengeResponse.from_hash(data)
end

#challenge_and_verify(params) ⇒ Types::AuthMFAVerifyResponse

Challenge and verify in one step.

Parameters:

  • params (Hash)

    (:factor_id, :code, :channel)

Returns:



1185
1186
1187
1188
1189
1190
1191
1192
1193
1194
1195
# File 'lib/supabase/auth/client.rb', line 1185

def challenge_and_verify(params)
  challenge_response = challenge(
    factor_id: params[:factor_id] || params["factor_id"],
    channel: params[:channel] || params["channel"]
  )
  verify(
    factor_id: params[:factor_id] || params["factor_id"],
    challenge_id: challenge_response.id,
    code: params[:code] || params["code"]
  )
end

#enroll(params) ⇒ Types::AuthMFAEnrollResponse

Enroll a new MFA factor.

Parameters:

  • params (Hash)

    (:factor_type, optional :friendly_name, :issuer)

Returns:

Raises:



1116
1117
1118
1119
1120
1121
1122
1123
1124
1125
1126
1127
1128
1129
1130
1131
1132
1133
1134
1135
1136
1137
1138
1139
# File 'lib/supabase/auth/client.rb', line 1116

def enroll(params)
  factor_type = params[:factor_type] || params["factor_type"]
  friendly_name = params[:friendly_name] || params["friendly_name"]

  session = @client.get_session
  raise Errors::AuthSessionMissing unless session

  body = { factor_type: factor_type, friendly_name: friendly_name }

  if factor_type == "phone"
    body[:phone] = params[:phone] || params["phone"]
  else
    body[:issuer] = params[:issuer] || params["issuer"]
  end

  data = @client._request("POST", "factors", jwt: session.access_token, body: body)
  response = Types::AuthMFAEnrollResponse.from_hash(data)

  if factor_type == "totp" && response.totp&.qr_code
    response.totp.qr_code = "data:image/svg+xml;utf-8,#{response.totp.qr_code}"
  end

  response
end

#get_authenticator_assurance_levelTypes::AuthMFAGetAuthenticatorAssuranceLevelResponse

Get the authenticator assurance level from the current session JWT.



1229
1230
1231
1232
1233
1234
1235
1236
1237
1238
1239
1240
1241
1242
1243
1244
1245
1246
1247
1248
1249
1250
1251
1252
1253
1254
# File 'lib/supabase/auth/client.rb', line 1229

def get_authenticator_assurance_level
  session = @client.get_session

  unless session
    return Types::AuthMFAGetAuthenticatorAssuranceLevelResponse.new(
      current_level: nil,
      next_level: nil,
      current_authentication_methods: []
    )
  end

  decoded = Helpers.decode_jwt(session.access_token)
  payload = decoded[:payload]

  aal = payload["aal"]
  amr_entries = (payload["amr"] || []).map { |entry| Types::AMREntry.from_hash(entry) }.compact

  verified_factors = (session.user&.factors || []).select { |f| f.status == "verified" }
  next_level = verified_factors.any? ? "aal2" : aal

  Types::AuthMFAGetAuthenticatorAssuranceLevelResponse.new(
    current_level: aal,
    next_level: next_level,
    current_authentication_methods: amr_entries
  )
end

#list_factorsTypes::AuthMFAListFactorsResponse

List all MFA factors for the current user.

Returns:



1213
1214
1215
1216
1217
1218
1219
1220
1221
1222
1223
1224
1225
# File 'lib/supabase/auth/client.rb', line 1213

def list_factors
  user_response = @client.get_user
  factors = user_response&.user&.factors || []

  totp = factors.select { |f| f.factor_type == "totp" && f.status == "verified" }
  phone = factors.select { |f| f.factor_type == "phone" && f.status == "verified" }

  Types::AuthMFAListFactorsResponse.new(
    all: factors,
    totp: totp,
    phone: phone
  )
end

#unenroll(params) ⇒ Types::AuthMFAUnenrollResponse

Unenroll an MFA factor.

Parameters:

  • params (Hash)

    (:factor_id)

Returns:

Raises:



1200
1201
1202
1203
1204
1205
1206
1207
1208
1209
# File 'lib/supabase/auth/client.rb', line 1200

def unenroll(params)
  factor_id = params[:factor_id] || params["factor_id"]

  session = @client.get_session
  raise Errors::AuthSessionMissing unless session

  data = @client._request("DELETE", "factors/#{factor_id}",
                          jwt: session.access_token)
  Types::AuthMFAUnenrollResponse.from_hash(data)
end

#verify(params) ⇒ Types::AuthMFAVerifyResponse

Verify an MFA challenge.

Parameters:

  • params (Hash)

    (:factor_id, :challenge_id, :code)

Returns:

Raises:



1159
1160
1161
1162
1163
1164
1165
1166
1167
1168
1169
1170
1171
1172
1173
1174
1175
1176
1177
1178
1179
1180
# File 'lib/supabase/auth/client.rb', line 1159

def verify(params)
  factor_id = params[:factor_id] || params["factor_id"]
  challenge_id = params[:challenge_id] || params["challenge_id"]
  code = params[:code] || params["code"]

  session = @client.get_session
  raise Errors::AuthSessionMissing unless session

  body = { factor_id: factor_id, challenge_id: challenge_id, code: code }
  data = @client._request("POST", "factors/#{factor_id}/verify",
                          jwt: session.access_token, body: body)
  response = Types::AuthMFAVerifyResponse.from_hash(data)

  # Save the new session from the verify response
  new_session = Types::Session.from_hash(data)
  if new_session&.access_token
    @client.send(:_save_session, new_session)
    @client.send(:_notify_all_subscribers, "MFA_CHALLENGE_VERIFIED", new_session)
  end

  response
end