PLT-4767 Implement MFA Enforcement (#4662)
* Create MFA setup page and remove MFA setup from account settings modal * Add enforce MFA to system console and force redirect * Lockdown mfa required API routes, add localization, other changes * Minor fixes * Fix typo * Fix some unit tests * Fix more unit tests * Minor fix * Updating UI for MFA screen (#4670) * Updating UI for MFA screen * Updating styles for MFA page * Add the ability to switch between email/sso with MFA enabled * Added mfa change email * Minor UI updates for MFA enforcement * Fix unit test * Fix client unit test * Allow switching email to ldap and back when MFA is enabled * Fix unit test * Revert config.json
Этот коммит содержится в:
коммит произвёл
enahum
родитель
f0d71d8789
Коммит
30a10d35a8
@@ -275,7 +275,7 @@ func (us SqlUserStore) UpdateFailedPasswordAttempts(userId string, attempts int)
|
||||
return storeChannel
|
||||
}
|
||||
|
||||
func (us SqlUserStore) UpdateAuthData(userId string, service string, authData *string, email string) StoreChannel {
|
||||
func (us SqlUserStore) UpdateAuthData(userId string, service string, authData *string, email string, resetMfa bool) StoreChannel {
|
||||
|
||||
storeChannel := make(StoreChannel, 1)
|
||||
|
||||
@@ -301,6 +301,10 @@ func (us SqlUserStore) UpdateAuthData(userId string, service string, authData *s
|
||||
query += ", Email = :Email"
|
||||
}
|
||||
|
||||
if resetMfa {
|
||||
query += ", MfaActive = false, MfaSecret = ''"
|
||||
}
|
||||
|
||||
query += " WHERE Id = :UserId"
|
||||
|
||||
if _, err := us.GetMaster().Exec(query, map[string]interface{}{"LastPasswordUpdate": updateAt, "UpdateAt": updateAt, "UserId": userId, "AuthService": service, "AuthData": authData, "Email": email}); err != nil {
|
||||
|
||||
@@ -756,7 +756,7 @@ func TestUserStoreUpdateAuthData(t *testing.T) {
|
||||
service := "someservice"
|
||||
authData := model.NewId()
|
||||
|
||||
if err := (<-store.User().UpdateAuthData(u1.Id, service, &authData, "")).Err; err != nil {
|
||||
if err := (<-store.User().UpdateAuthData(u1.Id, service, &authData, "", true)).Err; err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
|
||||
|
||||
@@ -143,7 +143,7 @@ type UserStore interface {
|
||||
UpdateLastPictureUpdate(userId string) StoreChannel
|
||||
UpdateUpdateAt(userId string) StoreChannel
|
||||
UpdatePassword(userId, newPassword string) StoreChannel
|
||||
UpdateAuthData(userId string, service string, authData *string, email string) StoreChannel
|
||||
UpdateAuthData(userId string, service string, authData *string, email string, resetMfa bool) StoreChannel
|
||||
UpdateMfaSecret(userId, secret string) StoreChannel
|
||||
UpdateMfaActive(userId string, active bool) StoreChannel
|
||||
Get(id string) StoreChannel
|
||||
|
||||
Ссылка в новой задаче
Block a user