4
0

totp.ts 806 B

1234567891011121314151617
  1. import { createOTP } from '@better-auth/utils/otp'
  2. import { symmetricDecrypt } from 'better-auth/crypto'
  3. /**
  4. * The six digits an authenticator app would show right now, from the secret
  5. * better-auth stored when 2FA was enabled.
  6. *
  7. * The secret is kept encrypted with the auth secret, the same one the test
  8. * server was started with, so the test can read it back the way the server
  9. * does and stand in for the phone. The QR code on the screen carries the
  10. * same secret, but a picture is no use to a test.
  11. */
  12. export async function currentTotpCode(storedSecret: string): Promise<string> {
  13. const key = process.env.BETTER_AUTH_SECRET ?? 'e2e-secret-not-for-production'
  14. const secret = await symmetricDecrypt({ key, data: storedSecret })
  15. return createOTP(secret, { digits: 6, period: 30 }).totp()
  16. }