LG-10290: Fix F/T unlock cancel sign-in redirect#8738
Merged
Conversation
changelog: Upcoming Features, Face or Touch Unlock, Fix redirect for cancelled sign-in
mitchellhenke
approved these changes
Jul 10, 2023
jmdembe
approved these changes
Jul 10, 2023
aduth
commented
Jul 10, 2023
Comment on lines
-9
to
-10
| const webauthnPlatformRequested = | ||
| webauthnInProgressContainer.dataset.platformAuthenticatorRequested === 'true'; |
Contributor
Author
There was a problem hiding this comment.
Explanation for the fix:
This data- property was removed in #8723, and was meant to be substituted by hard-coding the value into the form...
Comment on lines
-44
to
-45
| (document.getElementById('platform') as HTMLInputElement).value = | ||
| String(webauthnPlatformRequested); |
Contributor
Author
There was a problem hiding this comment.
...but since we were still assigning a value here from the non-existent data- attribute, the form value was being overridden.
The solution is to just not set the value when the error happens, so that the form value remains undisturbed.
Contributor
Author
|
We don't have good test coverage for this, but I might plan to merge this anyways, with a quick follow-on with one or the other of...
|
Contributor
Author
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🎫 Ticket
LG-10290
🛠 Summary of changes
Fixes an issue introduced in #8723 where a user would be redirected to the Security Key version of the WebAuthn MFA verification page if they cancelled the browser dialog for face or touch unlock.
📜 Testing Plan
Before: User is redirected to an error page and prompted to "Connect your security key"
After: Error state reflects cancelled Face or Touch Unlock MFA