Support opt-in MFA per browser client with authoritative enrollment checks
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 40s
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 40s
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
This commit is contained in:
parent
e1e292919a
commit
ac8ed65203
14 changed files with 298 additions and 12 deletions
56
workplans/KEY-WP-0035-optional-mfa.md
Normal file
56
workplans/KEY-WP-0035-optional-mfa.md
Normal file
|
|
@ -0,0 +1,56 @@
|
|||
---
|
||||
id: KEY-WP-0035
|
||||
type: workplan
|
||||
title: "Opt-in MFA for demo-company login"
|
||||
domain: infotech
|
||||
repo: key-cape
|
||||
status: active
|
||||
owner: codex
|
||||
topic_slug: infotech
|
||||
created: "2026-09-13"
|
||||
updated: "2026-09-13"
|
||||
---
|
||||
|
||||
Requested behavior: password-only login before OTP activation; require OTP after
|
||||
activation. Do not lower assurance of unrelated applications.
|
||||
|
||||
## Implement enrollment-dependent browser policy
|
||||
|
||||
```task
|
||||
id: KEY-WP-0035-T01
|
||||
status: done
|
||||
priority: high
|
||||
```
|
||||
|
||||
Add mfaOptional, preserve explicit AAL2 and existing client policy, fail closed on
|
||||
provider lookup errors and malformed/incomplete responses. Preserve the setting
|
||||
in config/runtime/canonical model and flag manual migration requirements.
|
||||
Validation: `go test ./...` and `git diff --check` passed on 2026-09-13. See docs/optional-mfa.md.
|
||||
|
||||
## Restore authoritative factor lookup and enable the reviewed client
|
||||
|
||||
```task
|
||||
id: KEY-WP-0035-T02
|
||||
status: wait
|
||||
priority: high
|
||||
```
|
||||
|
||||
Live factor-read credentials return HTTP 401. The owner route
|
||||
net-kingdom-privacyidea-admin-token is non-resolvable pending railiance-platform's
|
||||
approved custody/renewal contract (NK-WP-0033). Native credential handoff required;
|
||||
no secrets in work records. Do not enable the policy before lookup is verified.
|
||||
Prepare exact byte-preserving client migration after the provider contract is
|
||||
available; deploy digest-pinned source and run no-factor/enrolled/error checks.
|
||||
|
||||
## Verify optional enrollment and account management access
|
||||
|
||||
```task
|
||||
id: KEY-WP-0035-T03
|
||||
status: wait
|
||||
priority: high
|
||||
```
|
||||
|
||||
Verify provider self-service login, possession-confirmed activation, cancellation
|
||||
and removal/recovery. Resolve shared portal assurance scope before surfacing the
|
||||
verified OTP setup link. Actual user login acceptance remains open under
|
||||
KEY-WP-0034 and VERGABE-WP-0019; this work does not finish either workplan.
|
||||
Loading…
Add table
Add a link
Reference in a new issue