Skip to content

Commit ceee370

Browse files
Merge remote-tracking branch 'origin/main' into stlc/promote-next
2 parents 37d9a77 + c053ce4 commit ceee370

5 files changed

Lines changed: 166 additions & 18 deletions

File tree

‎src/kernel/resources/credentials.py‎

Lines changed: 81 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,7 @@
33
from __future__ import annotations
44

55
from typing import Dict, Optional
6+
from typing_extensions import Literal
67

78
import httpx
89

@@ -54,6 +55,9 @@ def create(
5455
name: str,
5556
values: Dict[str, str],
5657
sso_provider: str | Omit = omit,
58+
totp_algorithm: Literal["SHA1", "SHA256", "SHA512"] | Omit = omit,
59+
totp_digits: int | Omit = omit,
60+
totp_period: int | Omit = omit,
5761
totp_secret: str | Omit = omit,
5862
# Use the following arguments if you need to pass additional parameters to the API that aren't available via kwargs.
5963
# The extra values given here take precedence over values defined on the client or passed to this method.
@@ -77,8 +81,20 @@ def create(
7781
button, it will be clicked first before filling credential values on the
7882
identity provider's login page.
7983
80-
totp_secret: Base32-encoded TOTP secret for generating one-time passwords. Used for automatic
81-
2FA during login.
84+
totp_algorithm: HMAC algorithm used to generate TOTP codes. Defaults to SHA1 and is ignored when
85+
an `otpauth://` URI supplies the algorithm.
86+
87+
totp_digits: Number of digits in generated TOTP codes. Defaults to 6 and is ignored when an
88+
`otpauth://` URI supplies the digit count.
89+
90+
totp_period: TOTP rotation period in seconds. Defaults to 30 and is ignored when an
91+
`otpauth://` URI supplies the period.
92+
93+
totp_secret: Accepts a 16-128 character base32-encoded TOTP secret or an `otpauth://totp/...`
94+
URI. The range accepts existing shorter seeds and longer seeds regardless of
95+
HMAC algorithm; RFC 6238 recommends unpadded base32 lengths of 32/52/103 for
96+
SHA1/SHA256/SHA512. Only URI parameters present override the corresponding
97+
explicit TOTP fields. Used for automatic 2FA during login.
8298
8399
extra_headers: Send extra headers
84100
@@ -96,6 +112,9 @@ def create(
96112
"name": name,
97113
"values": values,
98114
"sso_provider": sso_provider,
115+
"totp_algorithm": totp_algorithm,
116+
"totp_digits": totp_digits,
117+
"totp_period": totp_period,
99118
"totp_secret": totp_secret,
100119
},
101120
credential_create_params.CredentialCreateParams,
@@ -147,6 +166,9 @@ def update(
147166
name: str | Omit = omit,
148167
remove_value_keys: SequenceNotStr[str] | Omit = omit,
149168
sso_provider: Optional[str] | Omit = omit,
169+
totp_algorithm: Literal["SHA1", "SHA256", "SHA512"] | Omit = omit,
170+
totp_digits: int | Omit = omit,
171+
totp_period: int | Omit = omit,
150172
totp_secret: str | Omit = omit,
151173
values: Dict[str, str] | Omit = omit,
152174
# Use the following arguments if you need to pass additional parameters to the API that aren't available via kwargs.
@@ -170,8 +192,20 @@ def update(
170192
sso_provider: If set, indicates this credential should be used with the specified SSO
171193
provider. Set to empty string or null to remove.
172194
173-
totp_secret: Base32-encoded TOTP secret for generating one-time passwords. Spaces and
174-
formatting are automatically normalized. Set to empty string to remove.
195+
totp_algorithm: HMAC algorithm used to generate TOTP codes. Requires totp_secret and is ignored
196+
when an `otpauth://` URI supplies the algorithm.
197+
198+
totp_digits: Number of digits in generated TOTP codes. Requires totp_secret and is ignored
199+
when an `otpauth://` URI supplies the digit count.
200+
201+
totp_period: TOTP rotation period in seconds. Requires totp_secret and is ignored when an
202+
`otpauth://` URI supplies the period.
203+
204+
totp_secret: Accepts a 16-128 character base32-encoded TOTP secret or an `otpauth://totp/...`
205+
URI. Only URI parameters present override the corresponding explicit TOTP
206+
fields. When rotating a raw secret, omitted fields preserve their existing
207+
values; a new URI defaults unspecified fields to SHA1/6/30. Set to empty string
208+
to remove the secret and its metadata.
175209
176210
values: Field name to value mapping. Values are merged with existing values (new keys
177211
added, existing keys overwritten).
@@ -193,6 +227,9 @@ def update(
193227
"name": name,
194228
"remove_value_keys": remove_value_keys,
195229
"sso_provider": sso_provider,
230+
"totp_algorithm": totp_algorithm,
231+
"totp_digits": totp_digits,
232+
"totp_period": totp_period,
196233
"totp_secret": totp_secret,
197234
"values": values,
198235
},
@@ -360,6 +397,9 @@ async def create(
360397
name: str,
361398
values: Dict[str, str],
362399
sso_provider: str | Omit = omit,
400+
totp_algorithm: Literal["SHA1", "SHA256", "SHA512"] | Omit = omit,
401+
totp_digits: int | Omit = omit,
402+
totp_period: int | Omit = omit,
363403
totp_secret: str | Omit = omit,
364404
# Use the following arguments if you need to pass additional parameters to the API that aren't available via kwargs.
365405
# The extra values given here take precedence over values defined on the client or passed to this method.
@@ -383,8 +423,20 @@ async def create(
383423
button, it will be clicked first before filling credential values on the
384424
identity provider's login page.
385425
386-
totp_secret: Base32-encoded TOTP secret for generating one-time passwords. Used for automatic
387-
2FA during login.
426+
totp_algorithm: HMAC algorithm used to generate TOTP codes. Defaults to SHA1 and is ignored when
427+
an `otpauth://` URI supplies the algorithm.
428+
429+
totp_digits: Number of digits in generated TOTP codes. Defaults to 6 and is ignored when an
430+
`otpauth://` URI supplies the digit count.
431+
432+
totp_period: TOTP rotation period in seconds. Defaults to 30 and is ignored when an
433+
`otpauth://` URI supplies the period.
434+
435+
totp_secret: Accepts a 16-128 character base32-encoded TOTP secret or an `otpauth://totp/...`
436+
URI. The range accepts existing shorter seeds and longer seeds regardless of
437+
HMAC algorithm; RFC 6238 recommends unpadded base32 lengths of 32/52/103 for
438+
SHA1/SHA256/SHA512. Only URI parameters present override the corresponding
439+
explicit TOTP fields. Used for automatic 2FA during login.
388440
389441
extra_headers: Send extra headers
390442
@@ -402,6 +454,9 @@ async def create(
402454
"name": name,
403455
"values": values,
404456
"sso_provider": sso_provider,
457+
"totp_algorithm": totp_algorithm,
458+
"totp_digits": totp_digits,
459+
"totp_period": totp_period,
405460
"totp_secret": totp_secret,
406461
},
407462
credential_create_params.CredentialCreateParams,
@@ -453,6 +508,9 @@ async def update(
453508
name: str | Omit = omit,
454509
remove_value_keys: SequenceNotStr[str] | Omit = omit,
455510
sso_provider: Optional[str] | Omit = omit,
511+
totp_algorithm: Literal["SHA1", "SHA256", "SHA512"] | Omit = omit,
512+
totp_digits: int | Omit = omit,
513+
totp_period: int | Omit = omit,
456514
totp_secret: str | Omit = omit,
457515
values: Dict[str, str] | Omit = omit,
458516
# Use the following arguments if you need to pass additional parameters to the API that aren't available via kwargs.
@@ -476,8 +534,20 @@ async def update(
476534
sso_provider: If set, indicates this credential should be used with the specified SSO
477535
provider. Set to empty string or null to remove.
478536
479-
totp_secret: Base32-encoded TOTP secret for generating one-time passwords. Spaces and
480-
formatting are automatically normalized. Set to empty string to remove.
537+
totp_algorithm: HMAC algorithm used to generate TOTP codes. Requires totp_secret and is ignored
538+
when an `otpauth://` URI supplies the algorithm.
539+
540+
totp_digits: Number of digits in generated TOTP codes. Requires totp_secret and is ignored
541+
when an `otpauth://` URI supplies the digit count.
542+
543+
totp_period: TOTP rotation period in seconds. Requires totp_secret and is ignored when an
544+
`otpauth://` URI supplies the period.
545+
546+
totp_secret: Accepts a 16-128 character base32-encoded TOTP secret or an `otpauth://totp/...`
547+
URI. Only URI parameters present override the corresponding explicit TOTP
548+
fields. When rotating a raw secret, omitted fields preserve their existing
549+
values; a new URI defaults unspecified fields to SHA1/6/30. Set to empty string
550+
to remove the secret and its metadata.
481551
482552
values: Field name to value mapping. Values are merged with existing values (new keys
483553
added, existing keys overwritten).
@@ -499,6 +569,9 @@ async def update(
499569
"name": name,
500570
"remove_value_keys": remove_value_keys,
501571
"sso_provider": sso_provider,
572+
"totp_algorithm": totp_algorithm,
573+
"totp_digits": totp_digits,
574+
"totp_period": totp_period,
502575
"totp_secret": totp_secret,
503576
"values": values,
504577
},

‎src/kernel/types/credential.py‎

Lines changed: 20 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,7 @@
22

33
from typing import List, Optional
44
from datetime import datetime
5+
from typing_extensions import Literal
56

67
from .._models import BaseModel
78

@@ -40,15 +41,33 @@ class Credential(BaseModel):
4041
identity provider's login page.
4142
"""
4243

44+
totp_algorithm: Optional[Literal["SHA1", "SHA256", "SHA512"]] = None
45+
"""HMAC algorithm used to generate TOTP codes.
46+
47+
Defaults to SHA1 for credentials created before this metadata was stored.
48+
"""
49+
4350
totp_code: Optional[str] = None
44-
"""Current 6-digit TOTP code.
51+
"""Current TOTP code.
4552
4653
Only included in create/update responses when totp_secret was just set.
4754
"""
4855

4956
totp_code_expires_at: Optional[datetime] = None
5057
"""When the totp_code expires. Only included when totp_code is present."""
5158

59+
totp_digits: Optional[int] = None
60+
"""Number of digits in generated TOTP codes.
61+
62+
Defaults to 6 for credentials created before this metadata was stored.
63+
"""
64+
65+
totp_period: Optional[int] = None
66+
"""TOTP rotation period in seconds.
67+
68+
Defaults to 30 for credentials created before this metadata was stored.
69+
"""
70+
5271
value_keys: Optional[List[str]] = None
5372
"""The field names stored in this credential's values (e.g., username, password).
5473

‎src/kernel/types/credential_create_params.py‎

Lines changed: 25 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
from __future__ import annotations
44

55
from typing import Dict
6-
from typing_extensions import Required, TypedDict
6+
from typing_extensions import Literal, Required, TypedDict
77

88
__all__ = ["CredentialCreateParams"]
99

@@ -26,8 +26,29 @@ class CredentialCreateParams(TypedDict, total=False):
2626
identity provider's login page.
2727
"""
2828

29-
totp_secret: str
30-
"""Base32-encoded TOTP secret for generating one-time passwords.
29+
totp_algorithm: Literal["SHA1", "SHA256", "SHA512"]
30+
"""HMAC algorithm used to generate TOTP codes.
31+
32+
Defaults to SHA1 and is ignored when an `otpauth://` URI supplies the algorithm.
33+
"""
34+
35+
totp_digits: int
36+
"""Number of digits in generated TOTP codes.
37+
38+
Defaults to 6 and is ignored when an `otpauth://` URI supplies the digit count.
39+
"""
3140

32-
Used for automatic 2FA during login.
41+
totp_period: int
42+
"""TOTP rotation period in seconds.
43+
44+
Defaults to 30 and is ignored when an `otpauth://` URI supplies the period.
45+
"""
46+
47+
totp_secret: str
48+
"""
49+
Accepts a 16-128 character base32-encoded TOTP secret or an `otpauth://totp/...`
50+
URI. The range accepts existing shorter seeds and longer seeds regardless of
51+
HMAC algorithm; RFC 6238 recommends unpadded base32 lengths of 32/52/103 for
52+
SHA1/SHA256/SHA512. Only URI parameters present override the corresponding
53+
explicit TOTP fields. Used for automatic 2FA during login.
3354
"""

‎src/kernel/types/credential_update_params.py‎

Lines changed: 28 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
from __future__ import annotations
44

55
from typing import Dict, Optional
6-
from typing_extensions import TypedDict
6+
from typing_extensions import Literal, TypedDict
77

88
from .._types import SequenceNotStr
99

@@ -28,11 +28,34 @@ class CredentialUpdateParams(TypedDict, total=False):
2828
Set to empty string or null to remove.
2929
"""
3030

31-
totp_secret: str
32-
"""Base32-encoded TOTP secret for generating one-time passwords.
31+
totp_algorithm: Literal["SHA1", "SHA256", "SHA512"]
32+
"""HMAC algorithm used to generate TOTP codes.
33+
34+
Requires totp_secret and is ignored when an `otpauth://` URI supplies the
35+
algorithm.
36+
"""
37+
38+
totp_digits: int
39+
"""Number of digits in generated TOTP codes.
40+
41+
Requires totp_secret and is ignored when an `otpauth://` URI supplies the digit
42+
count.
43+
"""
3344

34-
Spaces and formatting are automatically normalized. Set to empty string to
35-
remove.
45+
totp_period: int
46+
"""TOTP rotation period in seconds.
47+
48+
Requires totp_secret and is ignored when an `otpauth://` URI supplies the
49+
period.
50+
"""
51+
52+
totp_secret: str
53+
"""
54+
Accepts a 16-128 character base32-encoded TOTP secret or an `otpauth://totp/...`
55+
URI. Only URI parameters present override the corresponding explicit TOTP
56+
fields. When rotating a raw secret, omitted fields preserve their existing
57+
values; a new URI defaults unspecified fields to SHA1/6/30. Set to empty string
58+
to remove the secret and its metadata.
3659
"""
3760

3861
values: Dict[str, str]

‎tests/api_resources/test_credentials.py‎

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -45,6 +45,9 @@ def test_method_create_with_all_params(self, client: Kernel) -> None:
4545
"password": "mysecretpassword",
4646
},
4747
sso_provider="google",
48+
totp_algorithm="SHA1",
49+
totp_digits=6,
50+
totp_period=30,
4851
totp_secret="JBSWY3DPEHPK3PXP",
4952
)
5053
assert_matches_type(Credential, credential, path=["response"])
@@ -143,6 +146,9 @@ def test_method_update_with_all_params(self, client: Kernel) -> None:
143146
name="my-updated-login",
144147
remove_value_keys=["old_field"],
145148
sso_provider="google",
149+
totp_algorithm="SHA1",
150+
totp_digits=6,
151+
totp_period=30,
146152
totp_secret="JBSWY3DPEHPK3PXP",
147153
values={
148154
"username": "user@example.com",
@@ -338,6 +344,9 @@ async def test_method_create_with_all_params(self, async_client: AsyncKernel) ->
338344
"password": "mysecretpassword",
339345
},
340346
sso_provider="google",
347+
totp_algorithm="SHA1",
348+
totp_digits=6,
349+
totp_period=30,
341350
totp_secret="JBSWY3DPEHPK3PXP",
342351
)
343352
assert_matches_type(Credential, credential, path=["response"])
@@ -436,6 +445,9 @@ async def test_method_update_with_all_params(self, async_client: AsyncKernel) ->
436445
name="my-updated-login",
437446
remove_value_keys=["old_field"],
438447
sso_provider="google",
448+
totp_algorithm="SHA1",
449+
totp_digits=6,
450+
totp_period=30,
439451
totp_secret="JBSWY3DPEHPK3PXP",
440452
values={
441453
"username": "user@example.com",

0 commit comments

Comments
 (0)