Repository navigation
feat(step-up): password_or_mfa is a distinct kind with its own error code - #1872
Merged
Merged
Conversation
…code - GuardStepUp: describe the four kinds explicitly (no legacy alias) - DataLock: accept password_or_mfa - errors: publish STEP_UP_REQUIRED_PASSWORD_OR_MFA with its own copy
Contributor
|
I'll fix CI failures and address comments from users with write access. I'll skip comments containing "(aside)".
|
|
Review complete. No blocking issues — approved ✅; 1 nitpick below. 🧹 Nitpicks (1) — 🟢 1 low
This change introduces the
Reviewed commit: 2896778 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
PR 1 of the plan in constructive-io/constructive-planning#2152 (comment 5926486794):
password_or_mfastops being documented as a "legacy spelling" offresh_auth. The four step-up kinds are now distinct:passwordSTEP_UP_REQUIRED_PASSWORDmfaSTEP_UP_REQUIRED_MFApassword_or_mfaSTEP_UP_REQUIRED_PASSWORD_OR_MFAfresh_auth(default)STEP_UP_REQUIRED_FRESH_AUTHGuardStepUp.step_up_type: description rewritten; enum and default (fresh_auth) unchanged.DataLock.step_up_type: enum gainspassword_or_mfa.@constructive-io/errors:STEP_UP_REQUIRED_PASSWORD_OR_MFAis now published (public, 403) with its own copy. The inventory gains only this one entry (raised by the companion constructive-db PR); I didn't refresh the rest of the audit so this diff stays focused.parse.test.tsasserts all four factor codes are public and each has its own copy.Runtime enforcement lives in the companion constructive-db PR (on branch
feat/step-up-distinct-kinds). Publish this first, then bump deps in constructive-db.Link to Devin session: https://app.devin.ai/sessions/9b47ab5af65f4d508ea6c5db958a9bdf
Open in Devin Desktop: https://app.devin.ai/desktop/session/9b47ab5af65f4d508ea6c5db958a9bdf?variant=devin
Requested by: @pyramation