feat(auth0-server-js): add multi-factor authentication (MFA) support#164
feat(auth0-server-js): add multi-factor authentication (MFA) support#164amitsingh05667 wants to merge 37 commits into
Conversation
subhankarmaiti
left a comment
There was a problem hiding this comment.
@amitsingh05667 here are some key point you can consider
- we should Introduce MFA related error classes for better DX
- also please update examples
…ngeAuthenticator method
…auth0-auth-js into feat/server-js-mfa-support
…auth0-auth-js into feat/server-js-mfa-support
…m/auth0/auth0-auth-js into feat/server-js-mfa-support
…dError with isMfaRequiredError
…/auth0-auth-js into feat/server-js-mfa-support
…aClient response handling
I have an additional comment. So I am dismissing my approval.
|
@amitsingh05667 |
|
Warning Review limit reached
More reviews will be available in 17 seconds. Learn how PR review limits work. Your organization has run out of usage credits. Purchase more in the billing tab. ⌛ How to resolve this issue?After more reviews become available, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available. Please see our Fair Usage Limits Policy for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (8)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This multi-factor authentication (MFA) support is split into two PR's as mentioned below -
Summary
ServerMfaClientmodule with comprehensive Multi-Factor Authentication (MFA) support for server-side flowslistAuthenticators(),enrollAuthenticator(),challengeAuthenticator(), andverify()(verifies MFA challenge and saves tokens into session)ServerMfaClientasserverClient.mfaproperty onServerClientDesign decisions
verify()automatically saves tokens into the user's session after successful verification, keeping credentials server-sideauth0-auth-js:listAuthenticators,enrollAuthenticator, andchallengeAuthenticatordelegate directly to the underlyingAuthClient.mfa, keeping transport logic in one placeTest plan
server-mfa-client.spec.tsnpm run buildpasses