Page MenuHomePhabricator

Fix a double-prompt for MFA when recovering a password account

Authored by epriestley on Dec 18 2018, 8:04 PM.



Depends on D19905. Ref T13222. In D19843, I refactored this stuff but $jump_into_hisec was dropped.

This is a hint to keep the upgraded session in hisec mode, which we need to do a password reset when using a recovery link. Without it, we double prompt you for MFA: first to upgrade to a full session, then to change your password.

Pass this into the engine properly to avoid the double-prompt.

Test Plan
  • Used bin/auth recover to get a partial session with MFA enabled and a password provider.
  • Before: double MFA prompt.
  • After: session stays upgraded when it becomes full, no second prompt.

Diff Detail

rP Phabricator
Automatic diff as part of commit; lint not applicable.
Automatic diff as part of commit; unit tests not applicable.

Event Timeline

epriestley created this revision.Dec 18 2018, 8:04 PM
epriestley requested review of this revision.Dec 18 2018, 8:05 PM
amckinley accepted this revision.Dec 18 2018, 11:16 PM
This revision is now accepted and ready to land.Dec 18 2018, 11:16 PM
This revision was automatically updated to reflect the committed changes.