NAME

Airlock::Factor - Role for a second factor that secures an Airlock approval

VERSION

version 0.001

SYNOPSIS

package My::Factor;
use Moo;
with 'Airlock::Factor';

sub verify {
  my ( $self, $subject, $proof ) = @_;
  return $proof eq 'open sesame' ? 1 : 0;
}

DESCRIPTION

A factor answers one question: does this proof, from this subject, hold? Airlock::Policy decides which factors an approval needs; Airlock asks each of them and only then lets the request through.

verify

$factor->verify( $subject, $proof )

Required of the consumer. Returns true when the proof holds. Must not throw for a wrong proof.

name

Required. The name a policy refers to, and the key under which the proof arrives in approve( proofs => { ... } ).

amr

Required. The Authentication Method Reference (RFC 8176) this factor adds to the grant once it has verified, for example otp.

commit

$factor->commit( $subject, $proof )

Called once every factor of an approval has verified. A factor whose proof may be used only once records that here, not in verify, so that a proof is not used up when another factor fails. Returns true; a false return fails the approval.

needs_proof

True when the person has to supply something. A factor that only looks at the subject returns false and is checked without a proof.

available_for

$factor->available_for($subject)

True when the subject can use this factor at all, for example has enrolled.

SUPPORT

Issues

Please report bugs and feature requests on GitHub at https://github.com/Getty/p5-airlock/issues.

IRC

Join #kubernetes on irc.perl.org or message Getty directly.

CONTRIBUTING

Contributions are welcome! Please fork the repository and submit a pull request.

AUTHOR

Torsten Raudssus <getty@cpan.org>

COPYRIGHT AND LICENSE

This software is copyright (c) 2026 by Torsten Raudssus <torsten@raudssus.de> https://raudssus.de/.

This is free software; you can redistribute it and/or modify it under the same terms as the Perl 5 programming language system itself.