Closed adborden closed 3 years ago
In order for TTS programs using the TTS Bug Bounty program to be compliant, TTS programs need H1 to require MFA through SecureAuth
Reproduce
SecureAuth prompts you for a second factor.
SecureAuth authorizes you to H1 and you're now logged in.
Also noticed H1 is configured with the dev instance of SecureAuth https://secureauth.dev.gsa.gov/
This is now GSA Security's responsibility, so closing.
Background Information
In order for TTS programs using the TTS Bug Bounty program to be compliant, TTS programs need H1 to require MFA through SecureAuth
Implementation Steps
Reproduce
Expected behavior
SecureAuth prompts you for a second factor.
Actual behavior
SecureAuth authorizes you to H1 and you're now logged in.
Acceptance Criteria