DefGuard / defguard

Enterprise, fast, secure VPN & SSO platform with hardware keys, 2FA/MFA
https://defguard.net
Other
741 stars 22 forks source link

fix: verify mfa status during openid authorization #641

Closed t-aleksander closed 2 weeks ago

t-aleksander commented 2 weeks ago

πŸ“– Description

Previously only the session existence and its expiration status was checked during the openid authorization, which is not enough, as the session is created before the MFA verification takes place.

πŸ› οΈ Dev Branch Merge Checklist:

Documentation

Testing

Deployment

🏚️ Main Branch Merge Checklist:

Testing

Documentation