Skip to content

Fix MFA flow to resume the original authorization request - #1380

Merged
enricovianello merged 5 commits into
eosc-demofrom
fix-mfa-redirect-session
Oct 9, 2026
Merged

enricovianello merged 5 commits into
eosc-demofrom
fix-mfa-redirect-session

Conversation

@rmiccoli

@rmiccoli rmiccoli commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Problem

When a user accesses a protected /authorize endpoint for the first time and MFA enrollment is mandatory, the original authorization request is saved before the user is redirected to the login and MFA enrollment flow.

After completing the MFA enrollment, the original authorization request was not correctly resumed. Instead, the user could be redirected back to /iam/verify, requiring the TOTP to be entered again.

This resulted in the MFA flow being triggered twice instead of returning the user to the authorization request that originally initiated the flow.

Solution

Preserve the existing session when upgrading the user from PRE_AUTHENTICATED to fully authenticated after successful MFA enrollment.

A ChangeSessionIdAuthenticationStrategy is used to rotate the session ID without invalidating the session or losing its attributes, including the saved authorization request.

After the MFA upgrade, the original /authorize request can therefore be resumed and the user is redirected back to the authorization flow that initially triggered authentication.

Tests

Integration tests were added to verify that:

  • the original /authorize request is resumed after successful MFA enrollment;
  • the session ID is rotated when MFA authentication is upgraded;
  • the authentication is upgraded to fully authenticated;
  • an invalid TOTP does not rotate the session ID;
  • an invalid TOTP does not upgrade the authentication.

Soap2G and others added 3 commits October 8, 2026 16:11
enableAuthenticatorApp now upgrades the session to full
authentication itself and resumes the saved request.

Only applies when the session is genuinely pending MFA with
authorities to upgrade with (local, OIDC, SAML); every other
caller (a ROLE_USER session enrolling voluntarily, OAuth2,
X.509) is left untouched, or sent to /iam/verify as a safe
fallback when there's nothing to upgrade with. Runs the same
bookkeeping EnforceAupSignatureSuccessHandler runs on every
other login: auth timestamp, last-login time, audit event, and
the AUP signature check.
The controller only orchestrates account/code checks now,
and resolveEnrollmentRedirect lives next to the other
authentication-outcome decisions instead of duplicating them.

Adds a '/dashboard' fallback in the client JS for a
missing redirectUrl.

Fix tests.
Use ChangeSessionIdAuthenticationStrategy when upgrading a
PRE_AUTHENTICATED user to fully authenticated after MFA enrollment,
preserving the existing session attributes and saved authorization
request.

Add integration tests covering successful session rotation and
invalid TOTP verification.
@rmiccoli rmiccoli added the eosc It's a EOSC related fix/feature label Oct 8, 2026
@sonarqubecloud

sonarqubecloud Bot commented Oct 9, 2026

Copy link
Copy Markdown

@enricovianello
enricovianello merged commit b7eb8db into eosc-demo Oct 9, 2026
12 checks passed
@enricovianello
enricovianello deleted the fix-mfa-redirect-session branch October 9, 2026 16:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

eosc It's a EOSC related fix/feature

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants