From a02b5fcd14c9a2c6612967a92ba246ea71542613 Mon Sep 17 00:00:00 2001 From: Kyle Spearrin Date: Sat, 28 Jan 2017 22:11:54 -0500 Subject: [PATCH] updated otp library. reduced verification window to RFC standard of 1 --- src/Core/Identity/AuthenticatorTokenProvider.cs | 2 +- src/Core/project.json | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/src/Core/Identity/AuthenticatorTokenProvider.cs b/src/Core/Identity/AuthenticatorTokenProvider.cs index 90102b813c..3b360a2ed8 100644 --- a/src/Core/Identity/AuthenticatorTokenProvider.cs +++ b/src/Core/Identity/AuthenticatorTokenProvider.cs @@ -34,7 +34,7 @@ namespace Bit.Core.Identity var otp = new Totp(Base32Encoding.ToBytes(user.AuthenticatorKey)); long timeStepMatched; - var valid = otp.VerifyTotp(token, out timeStepMatched, new VerificationWindow(2, 2)); + var valid = otp.VerifyTotp(token, out timeStepMatched, new VerificationWindow(1, 1)); return Task.FromResult(valid); } diff --git a/src/Core/project.json b/src/Core/project.json index 03388c68e6..9aca94a679 100644 --- a/src/Core/project.json +++ b/src/Core/project.json @@ -8,7 +8,7 @@ "Sendgrid": "6.3.4", "PushSharp": "4.0.10", "WindowsAzure.Storage": "8.0.0", - "Otp.NET": "1.0.0" + "Otp.NET": "1.0.1" }, "frameworks": {