Finish KEY-WP-0008: registration handoff and client MFA isolation
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 34s
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 34s
Add signed registration/enrollment handoffs, per-request assurance policy with login-session isolation, and /logout. coulomb-social stays AAL1 unless acr_values or another client raises the bar.
This commit is contained in:
parent
fff9e39478
commit
b6af6c5268
22 changed files with 1636 additions and 42 deletions
|
|
@ -11,6 +11,11 @@ type MFAProvider interface {
|
|||
// CheckMFARequired returns true if MFA is required for the given user.
|
||||
CheckMFARequired(ctx context.Context, userID string) (bool, error)
|
||||
|
||||
// HasEnrolledFactor reports whether the user has at least one active
|
||||
// factor. Distinct from CheckMFARequired: a provider-wide require-for-all
|
||||
// policy can demand MFA even when the user has not enrolled yet.
|
||||
HasEnrolledFactor(ctx context.Context, userID string) (bool, error)
|
||||
|
||||
// ValidateMFAToken validates the given OTP token for the user.
|
||||
// Returns ErrMFAFailed if the token is invalid or expired.
|
||||
ValidateMFAToken(ctx context.Context, userID, token string) error
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue