Design an OTP Notification Service
Problem Low-level design of an OTP-based notification system: generate an OTP for a user action, deliver it over a channel, and validate it — with working interface/class code, then extend the design for new channels and providers.
Requirements
- API: generateOtp(userId, purpose) → dispatches via the user's channel; validateOtp(userId, purpose, code) → success/failure.
- OTP rules: N-digit random code, TTL (e.g. 5 min), limited attempts, single-use, resend with cooldown.
- Pluggable delivery channels (SMS/email → later push/WhatsApp) and swappable providers per channel.
Areas to design
- The class seams that let a new channel or provider drop in without touching the core service.
- The validation path: expiry, attempts, single-use, constant-time compare.
- Security: hashed OTP storage, rate limiting, and non-revealing error responses.
asked …