Skip to content

feat(node-type-registry): GuardStepUp accepts only fresh_auth, not password_or_mfa - #1870

Merged
pyramation merged 1 commit into
mainfrom
feat/step-up-fresh-auth-only
Oct 1, 2026
Merged

pyramation merged 1 commit into
mainfrom
feat/step-up-fresh-auth-only

Conversation

@pyramation

Copy link
Copy Markdown
Contributor

Summary

This carries out the password_or_mfa decision on constructive-io/constructive-planning#2152 for the published node-type-registry.

- step_up_type: 'password' | 'mfa' | 'fresh_auth' | 'password_or_mfa'
+ step_up_type: 'password' | 'mfa' | 'fresh_auth'

I regenerated blueprint-types.generated.ts with pnpm generate:types. The SQL side is in constructive-io/constructive-db, where GuardStepUp, is_valid_step_up and the generated require_step_up now reject password_or_mfa.

Layer

  • Layer: the published node-type-registry schema for GuardStepUp.
  • What is removed: the password_or_mfa enum value and the description calling it the "legacy spelling of fresh_auth".
  • Why it was compat-only: the value existed only so blueprints written before fresh_auth kept validating. The platform is pre-launch, so there are no such blueprints.

Link to Devin session: https://app.devin.ai/sessions/0f9216183d904190b25c5344962e2f12
Open in Devin Desktop: https://app.devin.ai/desktop/session/0f9216183d904190b25c5344962e2f12?variant=devin
Requested by: @pyramation

@devin-ai-integration

Copy link
Copy Markdown
Contributor

I'll fix CI failures and address comments from users with write access. I'll skip comments containing "(aside)".

  • Disable automatic comment, CI, and merge conflict monitoring

@tenki-reviewer

tenki-reviewer Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Review complete. No issues found — approved ✅.


This small change trims the step_up_type guard enum in packages/node-type-registry/src/guard/step-up.ts from four values to three, dropping password_or_mfa — which the removed doc comment described as the legacy spelling of fresh_auth. No in-repo code references the removed value, and the sibling data-lock.ts enum never included it, so the change is self-consistent within this repository. One low-severity compatibility note: configs persisted elsewhere with the legacy spelling would fail validation after upgrade; consider a validation-time alias if such configs exist. Review coverage of this diff was complete except for that note, which fell just under the confidence threshold and is not emitted as a formal finding.

Files Change
packages/node-type-registry/src/guard/step-up.ts Removes the password_or_mfa enum value and its legacy-alias note from the step_up_type definition.

Reviewed commit: 340ccce

@pyramation
pyramation merged commit 6b5d004 into main Oct 1, 2026
20 checks passed
@pyramation
pyramation deleted the feat/step-up-fresh-auth-only branch October 1, 2026 04:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant