Repository navigation
Conversation
Resets 2FA for one user, for operators with server access: requires
--reason (aborts without it), finds the user by email and calls
IRecoveryCodeService::disableTwoFactor, which clears the enrollment, deletes
the recovery codes and revokes the trusted devices in one transaction.
Emits a settings_changed audit event with {reason, actor: "console",
operator} and prints a summary with the number of codes deleted and devices
revoked. Group-enforced users stay challenged at login because enforcement is
derived from group membership; the output says so explicitly.
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
📘 OpenAPI / Swagger preview ➡️ https://OpenStackweb.github.io/openstackid/openapi/pr-171/ This page is automatically updated on each push to this PR. |
Stacked on #169 (base:
feat/mfa-disable-two-factor-service), which is stacked on #166 and #125. Merge bottom-up: #125, #166, #169, then this one.Summary
Second half of ClickUp ticket 12 (Admin Enforcement and Reset Commands):
idp:reset-2fa {email} --reason="...", for operators with server access who need to recover a user that lost their second factor and recovery codes.--reasonis required: without it (or blank) the command exits non-zero before touching anything.IRecoveryCodeService::disableTwoFactor($user, null, null)from feat(mfa): add IRecoveryCodeService::disableTwoFactor #169, which clearstwo_factor_enabledandtwo_factor_enforced_at, deletes the recovery codes and revokes the trusted devices in one transaction. The command does not reimplement any of that.settings_changedaudit event with{"reason": "<--reason>", "actor": "console", "operator": "<os user>@<hostname>"}andip_address127.0.0.1.Things to know
User::shouldRequire2FA()on the reloaded user, which is what the login uses, not through an HTTP login.disableTwoFactoras is.Test plan
tests/unit/Console/Reset2FACommandTest.php: 6 tests (missing and blank reason, unknown user, success with audit metadata, enforced-group warning, audit failure).tests/Reset2FACommandIntegrationTest.php: 3 tests against the DB (no reason changes nothing; self-enrolled user fully cleared with 1settings_changedrow; group-enforced admin still requires 2FA).tests/RecoveryCodeRegenerationTest.phpalready fails on the base branch (Class "Strategies\MFA\MFAChallengeStrategyFactory" not found), unrelated to this change.