Skip to content

Require re-authentication during MFA setup flow #8879

Merged
mitchellhenke merged 1 commit intomainfrom
aduth-mitchellhenke/remove-in-mfa-setup-exemption-for-reauthn
Jul 27, 2023
Merged

Require re-authentication during MFA setup flow #8879
mitchellhenke merged 1 commit intomainfrom
aduth-mitchellhenke/remove-in-mfa-setup-exemption-for-reauthn

Conversation

@mitchellhenke
Copy link
Contributor

🛠 Summary of changes

To make the re-authentication logic more consistent, this PR requires users in the MFA registration flow to also be required to re-authenticate if too much time has passed. We expanded the timeframe recently, so this should be relatively rare in practice.

@mitchellhenke mitchellhenke requested a review from aduth July 27, 2023 15:12
changelog: Bug Fixes, Account Registration, Require re-authentication during MFA setup flow

Co-authored-by: Andrew Duthie <andrew.duthie@gsa.gov>
@mitchellhenke mitchellhenke force-pushed the aduth-mitchellhenke/remove-in-mfa-setup-exemption-for-reauthn branch from 5eb3693 to fe3d88b Compare July 27, 2023 15:13
Copy link
Contributor

@aduth aduth left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍

@mitchellhenke mitchellhenke merged commit ac4eb34 into main Jul 27, 2023
@mitchellhenke mitchellhenke deleted the aduth-mitchellhenke/remove-in-mfa-setup-exemption-for-reauthn branch July 27, 2023 15:43
amirbey pushed a commit that referenced this pull request Jul 27, 2023
changelog: Bug Fixes, Account Registration, Require re-authentication during MFA setup flow

Co-authored-by: Andrew Duthie <andrew.duthie@gsa.gov>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants