Devise OTP

Two Factors authentication for Devise using Time Based OTP/rfc6238 tokens.

Cybersecurity & Ethical HackingRubyMIT

Abstract

Devise OTP is an open-source Cybersecurity & Ethical Hacking project. Two Factors authentication for Devise using Time Based OTP/rfc6238 tokens. Devise OTP is a Two-Factor Authentication extension for Devise. The second factor is done using an RFC 6238 Time-Based One-Time Password (TOTP) implemented by the rotp library. It is built using Ruby. The complete source code is publicly available on GitHub under the MIT License, making it a useful reference for students building a Cybersecurity & Ethical Hacking mini project or final-year project.

1. Introduction

Devise OTP is a Two-Factor Authentication extension for Devise. The second factor is done using an RFC 6238 Time-Based One-Time Password (TOTP) implemented by the rotp library.

Devise OTP was recently updated to work with Rails 7+ and Turbo.

Devise::OTP development is sponsored by Business Class Rails SaaS starter kit. If you don't want to setup OTP yourself for your new project, consider starting one on Business Class.

2. Objective

Two Factors authentication for Devise using Time Based OTP/rfc6238 tokens.

This project demonstrates how Ruby can be applied to a real-world Cybersecurity & Ethical Hacking problem.

4. Technology Stack

Ruby

5. System Requirements

General requirements for this technology stack — check the README for exact versions.

  • Ruby and Bundler
  • Git (to clone the repository)

6. Installation & Setup

git clone https://github.com/wmlele/devise-otp.git
cd devise-otp

Full setup instructions are in the project README.

7. Future Enhancements

Suggested extensions you can add to make this your own project.

  • Add logging and alert notifications (email / Telegram)
  • Write a threat model document for the tool
  • Package it with Docker for safe lab testing

8. Viva / Review Questions

Common questions examiners ask for projects in this domain.

  1. Which threat or attack does this project defend against?
  2. What detection or protection technique is used and what are its limits?
  3. How are false positives and false negatives handled?
  4. Which cryptographic algorithms or security standards are involved?
  5. What legal and ethical rules apply when testing a tool like this?

9. Source Code & License

This project is developed by wmlele and published on GitHub under the MIT License. Please follow the license terms and credit the original author when you use or modify this code.

Want to build this as your internship project?

Work on a Cybersecurity & Ethical Hacking project like this with mentor guidance, weekly reviews and an internship certificate from Training Trains, Erode — online or offline.

Apply for Cybersecurity & Ethical Hacking Internship