a tiny-mfa implementation written in go
4.2K
a tinymfa implementation written in go. See https://tinymfa.parzival.link for more information.
Our repository on github: https://github.com/ghmer/go-tiny-mfa.
Find a docker repository at https://hub.docker.com/r/tinymfa/go-tiny-mfa
Checkout our postman collection: https://tinymfa.parzival.link/tinymfa.postman_collection.json
Attention This is a hobby project to get more used to go-programming. It is not intended to be used in a production environment without making further security related steps.
tinymfa can be configured to validate access to its resources. Once activated, tinymfa checks for presence of the http header key 'tiny-mfa-access-token'. This must be either the root token created on installation, or the issuer token presented upon issuer creation.
| Endpoint | Method | Description |
|---|---|---|
| /api/v1/system/audit | GET | Return audit entries |
| /api/v1/system/configuration | GET | Return current system configuration |
| /api/v1/system/configuration | POST | Updates the system configuration |
| key | type | description |
|---|---|---|
| http_port | integer | the port to run on. Requires a restart! |
| deny_limit | integer | how many times is a user allowed to input a wrong token before we don't allow validation for the given message. This is to defeat brute force attacks |
| veriy_token | boolean | whether to verify if the tiny-mfa-access-token is set and contains a valid token |
{
"http_port" : 57687,
"deny_limit": 3,
"verify_tokens": true
}
| Endpoint | Method | Description |
|---|---|---|
| /api/v1/issuer | GET | Return all registered issuers |
| /api/v1/issuer | POST | Create a new issuer using a POST request |
| /api/v1/issuer/{issuer} | GET | Return a distinct issuer by its name |
| /api/v1/issuer/{issuer} | POST | Updates a distinct issuer using a POST request |
| /api/v1/issuer/{issuer} | DELETE | Deletes a distinct issuer using a DELETE request |
| key | type | description |
|---|---|---|
| name | string | the name of this issuer |
| contact | string | a mail adress of the responsible person |
| token_length | integer | Length of the desired totp tokens |
| enabled | boolean | whether this issuer is active |
{
"name": "issuer.local",
"contact": "[email protected]",
"token_length": 6,
"enabled": true
}
| key | type | description |
|---|---|---|
| contact | string | a mail adress of the responsible person |
| token_length | integer | Length of the desired totp tokens |
| enabled | boolean | whether this issuer is active |
{
"contact": "[email protected]",
"token_length": 8,
"enabled": true
}
| Endpoint | Method | Description |
|---|---|---|
| /api/v1/issuer/{issuer}/token | GET | Return all registered access tokens for a given issuer |
| /api/v1/issuer/{issuer}/token | POST | Creates a new access token for the given issuer using a PUT request |
| /api/v1/issuer/{issuer}/token/{tokenid} | DELETE | Deletes a distinct access token in the scope of a distinct issuer |
| key | type | description |
|---|---|---|
| description | string | a description for the new token |
{
"description" : "my access token"
}
| Endpoint | Method | Description |
|---|---|---|
| /api/v1/issuer/{issuer}/users | GET | Return all users belonging to the scope of a distinct issuer |
| /api/v1/issuer/{issuer}/users | POST | Create a new user in the scope of a distinct issuer |
| /api/v1/issuer/{issuer}/users/{user} | GET | Return a distinct user in the scope of a distinct issuer |
| /api/v1/issuer/{issuer}/users/{user} | POST | Update a distinct user in the scope of a distinct issuer |
| /api/v1/issuer/{issuer}/users/{user} | DELETE | Deletes a distinct user in the scope of a distinct issuer |
| key | type | description |
|---|---|---|
| name | string | the name this user |
| string | a mail adress of the user | |
| enabled | boolean | whether this user is active |
{
"name" : "demo",
"email": "[email protected]",
"enabled": true
}
| key | type | description |
|---|---|---|
| string | a mail adress of the user | |
| enabled | boolean | whether this user is active |
{
"email": "[email protected]",
"enabled": true
}
| Endpoint | Method | Description |
|---|---|---|
| /api/v1/issuer/{issuer}/users/{user}/totp | GET | Generates and returns a PNG image of a QRCode in the scope of a distinct user and issuer |
| /api/v1/issuer/{issuer}/users/{user}/totp | POST | Validates a given token in the scope of a distinct user and issuer |
| key | type | description |
|---|---|---|
| token | string | the token to validate |
{
"token": "123456"
}
This will result in a working tiny-mfa instance:
version: "3"
services:
database:
image: postgres:latest
networks:
- tiny-mfa-net
volumes:
- data:/var/lib/postgresql/data
environment:
- POSTGRES_USER=postgres
- POSTGRES_PASSWORD=postgres
- POSTGRES_DB=tinymfa
tinymfa:
image: tinymfa/go-tiny-mfa
networks:
- tiny-mfa-net
ports:
- "57687:57687"
volumes:
- tinysecret:/opt/go-tiny-mfa/secrets
environment:
- POSTGRES_HOST=database
- POSTGRES_USER=postgres
- POSTGRES_PASSWORD=postgres
- POSTGRES_DB=tinymfa
restart: unless-stopped
volumes:
data:
tinysecret:
networks:
tiny-mfa-net:
curl --location --request POST 'http://localhost:57687/api/v1/issuer' \
--header 'Content-Type: application/json' \
--data-raw '{
"name": "issuer.local",
"contact": "[email protected]",
"token_length:" 6,
"enabled": true
}'
curl --location --request POST 'http://localhost:57687/api/v1/issuer/issuer.local/users' \
--header 'Content-Type: application/json' \
--data-raw '{
"name" : "demo",
"email": "[email protected]",
"enabled": true
}'
curl --location --request GET 'http://localhost:57687/api/v1/issuer/issuer.local/users/demo/totp'
curl --location --request POST 'http://localhost:57687/api/v1/issuer/issuer.local/users/demo/totp' \
--header 'Content-Type: application/json' \
--data-raw '{
"token" : "123456"
}'
Content type
Image
Digest
sha256:1825affeb…
Size
6.5 MB
Last updated
over 2 years ago
docker pull tinymfa/go-tiny-mfa