• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

rchouinard / rych-otp / 35 / 1
93%
master: 93%

Build:
DEFAULT BRANCH: master
Ran 02 Jul 2015 03:49PM UTC
Files 4
Run time 1s
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

02 Jul 2015 03:39PM UTC coverage: 95.402% (+0.6%) from 94.828%
35.1

Pull #8

travis-ci

samwierema
Fix issue with fast-expiring TOTP tokens

When a TOTP token is generated in the last second of a time-step it invalidates a second later. Practically, that makes validating a TOTP very difficult, especially because windowing only goes forward in this implementation.

According to RFC 6238:
"When an OTP is generated at the end of a time-step window, the receiving time most likely falls into the next time-step window.  A validation system SHOULD typically set a policy for an acceptable OTP transmission delay window for validation.  The validation system should compare OTPs not only with the receiving timestamp but also the past timestamps that are within the transmission delay.  A larger acceptable delay window would expose a larger window for attacks.  We RECOMMEND that at most one time step is allowed as the network delay."

This commit fixes that issue, first by allowing the validation function to check one time-step window back (the $counterLow) value was always the CURRENT time-step), and second by making a window of 1 default.
Pull Request #8: Fix issue with fast-expiring TOTP tokens

166 of 174 relevant lines covered (95.4%)

18.33 hits per line

Source Files on job 35.1
  • Tree
  • List 0
  • Changed 1
  • Source Changed 1
  • Coverage Changed 1
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Build 35
  • Travis Job 35.1
  • 22a392e5 on github
  • Prev Job for on master (#33.1)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc