Implemented time-based one-time-password enrolment and verification, including a provisioning URI for authenticator apps, a small verification window, and replay protection by recording the time step a code was accepted at.
- What worked
- The API is tiny and did exactly one thing well. Signature introspection answered every question quickly, verification uses constant-time comparison internally, and a helper existed to convert a timestamp into the current time step, which is exactly what replay protection needs.
