Repository navigation
Fix MFA flow to resume the original authorization request - #1380
Merged
Merged
Conversation
enableAuthenticatorApp now upgrades the session to full authentication itself and resumes the saved request. Only applies when the session is genuinely pending MFA with authorities to upgrade with (local, OIDC, SAML); every other caller (a ROLE_USER session enrolling voluntarily, OAuth2, X.509) is left untouched, or sent to /iam/verify as a safe fallback when there's nothing to upgrade with. Runs the same bookkeeping EnforceAupSignatureSuccessHandler runs on every other login: auth timestamp, last-login time, audit event, and the AUP signature check.
The controller only orchestrates account/code checks now, and resolveEnrollmentRedirect lives next to the other authentication-outcome decisions instead of duplicating them. Adds a '/dashboard' fallback in the client JS for a missing redirectUrl. Fix tests.
Use ChangeSessionIdAuthenticationStrategy when upgrading a PRE_AUTHENTICATED user to fully authenticated after MFA enrollment, preserving the existing session attributes and saved authorization request. Add integration tests covering successful session rotation and invalid TOTP verification.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Problem
When a user accesses a protected
/authorizeendpoint for the first time and MFA enrollment is mandatory, the original authorization request is saved before the user is redirected to the login and MFA enrollment flow.After completing the MFA enrollment, the original authorization request was not correctly resumed. Instead, the user could be redirected back to
/iam/verify, requiring the TOTP to be entered again.This resulted in the MFA flow being triggered twice instead of returning the user to the authorization request that originally initiated the flow.
Solution
Preserve the existing session when upgrading the user from
PRE_AUTHENTICATEDto fully authenticated after successful MFA enrollment.A
ChangeSessionIdAuthenticationStrategyis used to rotate the session ID without invalidating the session or losing its attributes, including the saved authorization request.After the MFA upgrade, the original
/authorizerequest can therefore be resumed and the user is redirected back to the authorization flow that initially triggered authentication.Tests
Integration tests were added to verify that:
/authorizerequest is resumed after successful MFA enrollment;