Support opt-in MFA per browser client with authoritative enrollment checks
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 40s
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 40s
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
This commit is contained in:
parent
e1e292919a
commit
ac8ed65203
14 changed files with 298 additions and 12 deletions
|
|
@ -176,6 +176,13 @@ entities:
|
|||
items:
|
||||
type: string
|
||||
description: "Role claims emitted for this client's service tokens."
|
||||
mfaOptional:
|
||||
type: boolean
|
||||
description: >
|
||||
Require MFA only after factor enrollment for this browser client,
|
||||
overriding the provider require-for-all default. Enrollment lookup
|
||||
failures deny login. Cannot be combined with mfaRequired. Explicit
|
||||
AAL2 requests still require MFA.
|
||||
mfaRequired:
|
||||
type: boolean
|
||||
nullable: true
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue