From 84d475e9b639cf1b4fe879cb12d5cd6c88669777 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Filip=20=C5=9Al=C4=99zak?= Date: Tue, 29 Sep 2026 12:03:05 +0200 Subject: [PATCH 1/2] mfa configure verify via oidc,fido2 --- common/client_types.proto | 20 +++++++++++++++++++- v2/proxy.proto | 2 ++ 2 files changed, 21 insertions(+), 1 deletion(-) diff --git a/common/client_types.proto b/common/client_types.proto index 3e46a4c..bb2a13e 100644 --- a/common/client_types.proto +++ b/common/client_types.proto @@ -412,8 +412,9 @@ message MfaConfigStartRequest { message MfaConfigStartResponse { string session_token = 1; + // Methods that can authorize the session: TOTP, EMAIL, FIDO2 and OIDC. repeated MfaMethod available_methods = 2; - // True when no factor is configured and an email code is the only authorization method. + // True when no method can authorize and an email code is the only authorization method. bool email_fallback = 3; int64 deadline_timestamp = 4; } @@ -424,10 +425,27 @@ message MfaConfigSendCodeRequest { message MfaConfigSendCodeResponse {} +// Issues a single-use challenge for authorizing the session with a FIDO2 security key. +message MfaConfigFido2ChallengeRequest { + string session_token = 1; +} + +message MfaConfigFido2ChallengeResponse { + string challenge = 1; + // Base64url credential IDs of the user's registered security keys. + repeated string credential_ids = 2; +} + +// For OIDC the client polls this until the browser authentication completes. message MfaConfigAuthorizeRequest { string session_token = 1; MfaMethod method = 2; + // Empty for FIDO2 and OIDC. string code = 3; + // FIDO2 assertion, encoded as in `ClientMfaFinishRequest`: base64url signature. + optional string signature = 4; + optional bytes auth_data = 5; + optional bytes credential_id = 6; } message MfaConfigAuthorizeResponse { diff --git a/v2/proxy.proto b/v2/proxy.proto index 6eec523..f988277 100644 --- a/v2/proxy.proto +++ b/v2/proxy.proto @@ -120,6 +120,7 @@ message CoreResponse { defguard.client_types.MfaConfigStartResponse mfa_config_start = 23; defguard.client_types.MfaConfigAuthorizeResponse mfa_config_authorize = 24; defguard.client_types.MfaConfigSendCodeResponse mfa_config_send_code = 25; + defguard.client_types.MfaConfigFido2ChallengeResponse mfa_config_fido2_challenge = 26; } } @@ -223,6 +224,7 @@ message CoreRequest { defguard.client_types.MfaConfigAuthorizeRequest mfa_config_authorize = 25; defguard.client_types.MfaConfigSendCodeRequest mfa_config_send_code = 26; defguard.client_types.MfaConfigEndRequest mfa_config_end = 27; + defguard.client_types.MfaConfigFido2ChallengeRequest mfa_config_fido2_challenge = 28; } } From ee27d9390f5abc1335b480f4a5f5fb5b32b92c00 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Filip=20=C5=9Al=C4=99zak?= Date: Wed, 30 Sep 2026 13:35:22 +0200 Subject: [PATCH 2/2] review fix --- common/client_types.proto | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/common/client_types.proto b/common/client_types.proto index bb2a13e..4c0bb33 100644 --- a/common/client_types.proto +++ b/common/client_types.proto @@ -442,8 +442,8 @@ message MfaConfigAuthorizeRequest { MfaMethod method = 2; // Empty for FIDO2 and OIDC. string code = 3; - // FIDO2 assertion, encoded as in `ClientMfaFinishRequest`: base64url signature. - optional string signature = 4; + // FIDO2 assertion. + optional bytes signature = 4; optional bytes auth_data = 5; optional bytes credential_id = 6; }