Commit 41bf9c1
Update git submodules
* Update OATHAuth from branch 'master'
to 511127a8edea3c6ac390fb8ff1269d6e07a2f845
- Fix multi-key handling
Follow up on the multiple-authenticators work by replacing
the user's 2FA module (of which there could only be one) with
the user's 2FA keys in various places.
Functional changes:
* Add OATHUser::getKeysForModule() and a shortcut for the TOTP
module (for typehint friendliness)
* Filter modules for TOTP only in various places:
** ApiOATHValidate (which could maybe be more generic in the
longer term, but would need some sort of support flag - it
will definitely not work with WebAuthn).
** Lots of places that did the same filtering manually.
* Do not throw in various places when the user has multiple kinds
of keys:
** OATHUser::addKey()
** OATHUserRepository::loadKeysFromDatabase()
* Keep throwing in OATHUserRepository::createKey() (which is what
gates the use of multiple authenticators currently, and we want
to preserve that until further UX improvements) but use an error
page rather than an error.
Code cleanup:
* Replace OATHUser::setKeys() (only used in a single place, to
remove a key) with removeKey().
* Hard-deprecate OATHUser::getModule() and remove its uses.
* Remove OATHUser::setModule(). Instead, use the first key in
getModule().
WebAuthn part of the change: Ib9a686171da67b334e80524629df406d10903391
Bug: T242031
Change-Id: I70241b9cfc036ea6439bf30ed724c1377a78d5c01 parent bb6edd7 commit 41bf9c1
1 file changed
+1
-1
lines changedSubmodule OATHAuth updated from 2c0e0b6 to 511127a
0 commit comments