defenseunicorns / uds-identity-config

https://uds.defenseunicorns.com/core/identity/
Apache License 2.0
0 stars 0 forks source link

Should MFA / OTP be required for credential reset #117

Open UnicornChance opened 1 week ago

UnicornChance commented 1 week ago

Is your feature request related to a problem? Please describe.

Follow on discussion to this PR, at the moment the MFA is not required when a user resets credentials which opens a backdoor for them to access their account and reset the MFA as well.

bburky commented 2 days ago

This is maybe ok, but we should think through it.

If we don't think the answers to those are "yes", then we should require MFA during the reset flow.