feat(enrollment)!: add human-entered confirmation codes - #37
Merged
Merged
Conversation
Add a closed proof-format contract with dedicated HMAC protection for bounded eight-digit codes. Prepare the 8.0.0 release candidate and document migration and operating constraints. BREAKING CHANGE: EnrollmentProperties and EnrollmentDelivery now expose only their canonical constructors, and verification accepts only the configured proof format.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds a closed, configuration-owned proof format for contact enrollment:
OPAQUE_TOKENfor application-owned verification links;DECIMAL_CODEproofs for deliberate manual entry;The configured format governs both generation and verification. There is no cross-format migration fallback or proof-strategy SPI.
Breaking migration
This prepares Vigil
8.0.0because the compatibility-only constructors were removed:EnrollmentPropertiescallers must supplyproofFormatandcodeHmacKey;EnrollmentDeliverycallers must supplyproofFormat.Changing proof format or the decimal-code key invalidates pending proofs. Resend remains bounded by the existing cooldown, attempt, resend, and total-lifetime policy; duplicate start does not reset the lifecycle.
Security and operations
Decimal codes are exactly eight ASCII digits, use approved secure randomness, have a maximum 15-minute TTL, and allow at most five lifecycle-wide attempts. Attempts remain cumulative across resend. The HMAC binds canonical email, context ID/version, trusted audience, purpose, format, and proof, and the dedicated key is excluded from state and string rendering.
The PostgreSQL contract fixture covers exact expiry, resend rotation, cumulative and concurrent attempt exhaustion, concurrent verification, and resend-versus-verify serialization. Hosts remain responsible for a durable atomic production
EnrollmentStore, delivery infrastructure, and abuse controls.Verification
gradlew.bat clean check --no-daemongradlew.bat qualityCheck build publishToMavenLocal --no-daemon --no-configuration-cachegit diff --check8.0.0Closes #36