Skip to content

feat(step-up): password_or_mfa is a distinct kind with its own error code - #1872

Merged
pyramation merged 1 commit into
mainfrom
feat/step-up-password-or-mfa-distinct
Oct 1, 2026
Merged

pyramation merged 1 commit into
mainfrom
feat/step-up-password-or-mfa-distinct

Conversation

@pyramation

Copy link
Copy Markdown
Contributor

Summary

PR 1 of the plan in constructive-io/constructive-planning#2152 (comment 5926486794): password_or_mfa stops being documented as a "legacy spelling" of fresh_auth. The four step-up kinds are now distinct:

kind satisfied by error
password recent password re-entry STEP_UP_REQUIRED_PASSWORD
mfa recent second factor STEP_UP_REQUIRED_MFA
password_or_mfa either factor; an SSO sign-in alone does not count STEP_UP_REQUIRED_PASSWORD_OR_MFA
fresh_auth (default) any recent sign-in / re-verification (SSO, magic link, OTP, …) STEP_UP_REQUIRED_FRESH_AUTH
  • GuardStepUp.step_up_type: description rewritten; enum and default (fresh_auth) unchanged.
  • DataLock.step_up_type: enum gains password_or_mfa.
  • @constructive-io/errors: STEP_UP_REQUIRED_PASSWORD_OR_MFA is now published (public, 403) with its own copy. The inventory gains only this one entry (raised by the companion constructive-db PR); I didn't refresh the rest of the audit so this diff stays focused.
  • parse.test.ts asserts all four factor codes are public and each has its own copy.

Runtime enforcement lives in the companion constructive-db PR (on branch feat/step-up-distinct-kinds). Publish this first, then bump deps in constructive-db.

Link to Devin session: https://app.devin.ai/sessions/9b47ab5af65f4d508ea6c5db958a9bdf
Open in Devin Desktop: https://app.devin.ai/desktop/session/9b47ab5af65f4d508ea6c5db958a9bdf?variant=devin
Requested by: @pyramation

…code

- GuardStepUp: describe the four kinds explicitly (no legacy alias)
- DataLock: accept password_or_mfa
- errors: publish STEP_UP_REQUIRED_PASSWORD_OR_MFA with its own copy
@devin-ai-integration

Copy link
Copy Markdown
Contributor

I'll fix CI failures and address comments from users with write access. I'll skip comments containing "(aside)".

  • Disable automatic comment, CI, and merge conflict monitoring

@tenki-reviewer

tenki-reviewer Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Review complete. No blocking issues — approved ✅; 1 nitpick below.

🧹 Nitpicks (1) — 🟢 1 low
  • 🟢 Regenerate SDK docs still describing password_or_mfa as legacy alias (step-up.ts:24) — This PR redefines password_or_mfa as a distinct step-up factor — "either factor; an SSO sign-in alone does not count" — replacing the old wording that called it a legacy spelling of fresh_auth (packages/node-type-registry/src/guard/step-up.ts:24-28).

This change introduces the password_or_mfa step-up factor as a first-class code, threading it from the DB error inventory through registry codegen into the guard logic that classifies step-up verification errors. Tests are updated to assert the new enum value and message uniqueness.

Files Change
packages/errors/scripts/db-error-inventory.json, packages/errors/scripts/generate-registry.py Add the password_or_mfa factor entry to the inventory and its hand-written mapping in the registry generator.
packages/errors/__tests__/parse.test.ts Update parse tests for the new factor code and switch duplicate-message assertions to a Set-based uniqueness check.
packages/node-type-registry/src/data/data-lock.ts, src/guard/step-up.ts Register password_or_mfa in the data lock and classify it in the step-up guard alongside existing factors.

Reviewed commit: 2896778

@pyramation
pyramation merged commit 72d662e into main Oct 1, 2026
20 checks passed
@pyramation
pyramation deleted the feat/step-up-password-or-mfa-distinct branch October 1, 2026 09:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant