Nucleus .Net Core CMS

Models.UserSecrets Class

Namespace: Nucleus.Abstractions.Models
Assembly: Nucleus.Abstractions.dll
Represents password and other user-login information.
Secret key for multifactor authentication using TOTP (RFC6238).
Not in use
Not in use
Gets or sets the number of times that the user has entered the wrong password, within the configured time window.
Gets or sets the date/time of the first password attempt failure, within the configured time window.
Gets or sets whether the user is locked out.
Date/Time of the last lockout for the user.
Remarks
Users are locked out for a configurable period of time after a configurable number of failed password attempts.
Date/time of the last successful login.
Date/time that the user last changed their password.
Not in use
Expiry date/time for the password. When a password is expired, the user must enter a new password the next time they log in.
User's password hash.
Algorithm used to create the PasswordHash.
Not in use
Auto-generated token used for password resets.
Expiry date/time for PasswordResetToken
Random value used by the hash algorithm.
Determines how many numeric characters are in the one-time passcode.
Number of seconds that a one-time passcode is valid for.
Algorithm used to encrypt the EncryptedTotpSecretKey.
Auto-generated token used for new user verification.
Expiry date/time for VerificationToken
SetPassword (String newPassword)
Set the password for the user.
Parameters
Name Type
newPassword String
Remarks
Use SetPassword rather than this function. The UserManager method sets other properties like the password expiry date.
VerifyPassword (String password)
Compare the submitted password with the user's saved password.
Parameters
Name Type
password String
Remarks
Login modules should use Nucleus.Core.UserManager.VerifyPassword rather than calling this function directly, because UserManager.VerifyPassword tracks login failures and manages account suspension. If the user 'secrets' record has a blank password or blank password hash algorithm, this function always returns false, because users without a password cannot login using the login module. Users can have no password if they are authenticated by a different method such as OAuth, or an Authenticator app.