Sitelet https://github.com/SadPossum/GMA-Module-Auth/pull/22
Skip to content

Add session-bound multi-factor step-up - #22

Draft
SadPossum wants to merge 1 commit into
devfrom
codex/recent-mfa-step-up
Draft

SadPossum wants to merge 1 commit into
devfrom
codex/recent-mfa-step-up

Conversation

@SadPossum

Copy link
Copy Markdown
Owner

Summary

  • add authenticated bearer and browser MFA step-up endpoints that require the current password, a TOTP or recovery code, and the exact current refresh-token generation
  • rotate the existing session into fresh password-plus-factor evidence only after every proof succeeds, with opaque invalid-credential responses, replay-family revocation, and separate password/factor throttling
  • preserve existing authentication evidence during factor-management operations so recovery-code regeneration and MFA disablement cannot manufacture a newer authentication time
  • harden enrollment activation and management flows with refresh preflight/rechecks, completion-time evidence, and cutoff-bounded durable failure cleanup

Validation

  • dotnet build Gma.Modules.Auth.slnx --no-restore -m:1 — 0 warnings, 0 errors
  • dotnet test Gma.Modules.Auth.slnx --no-build --filter "Category!=Docker" — 329 passed
  • GMA_REQUIRE_DOCKER_TESTS=true dotnet test tests/Gma.Modules.Auth.IntegrationTests/Gma.Modules.Auth.IntegrationTests.csproj --no-build — 3 passed
  • boundary checks passed
  • PostgreSQL and SQL Server migration drift checks passed
  • repository security and release checks passed
  • vulnerable-package scan found no vulnerable direct or transitive packages
  • three independent reviews found no remaining merge-blocking domain, security, transaction, evidence-integrity, API, or regression issues

Boundaries and follow-ups

  • this PR adds reusable GMA Auth capability only; it does not activate a StayQuest privileged-operation assurance policy
  • external-only accounts still receive the explicit Auth.PasswordNotConfigured result; provider-specific OIDC reauthentication is a separate slice
  • layered endpoint-assurance metadata composition in GMA Framework remains a separate framework concern

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants