LG-10286: Allow AAL2-restricted sign in to choose another option#8837
Merged
LG-10286: Allow AAL2-restricted sign in to choose another option#8837
Conversation
Contributor
Author
|
Since this depends on / merges to #8834, I'm going to wait for that to be approved and merged, then rebase this against |
50c9149 to
0d2968f
Compare
changelog: Bug Fixes, Sign In, Allow user to use all supported MFA methods in AAL2 strict authentication
e3bb9b4 to
b8339c7
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🎫 Ticket
LG-10286
🛠 Summary of changes
Updates AAL2 strict authentication requests to use a more standardized user flow, allowing a user to use all available methods supported for the request.
Previously, it would not be possible to use Face or Touch Unlock to sign in to a partner requesting phishing-resistant MFA.
With these changes, the user will always be given the option to "Choose another authentication method" when prompted for their MFA. If MFA options are limited due to request parameters of the partner, a warning will be shown on the MFA selection screen explaining why the options are limited.
Draft: Merges to #8834
📜 Testing Plan
👀 Screenshots
Phishing Resistant Required:
PIV/CAC Only: