Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 19 additions & 1 deletion common/client_types.proto
Original file line number Diff line number Diff line change
Expand Up @@ -412,8 +412,9 @@ message MfaConfigStartRequest {

message MfaConfigStartResponse {
string session_token = 1;
// Methods that can authorize the session: TOTP, EMAIL, FIDO2 and OIDC.
repeated MfaMethod available_methods = 2;
// True when no factor is configured and an email code is the only authorization method.
// True when no method can authorize and an email code is the only authorization method.
bool email_fallback = 3;
int64 deadline_timestamp = 4;
}
Expand All @@ -424,10 +425,27 @@ message MfaConfigSendCodeRequest {

message MfaConfigSendCodeResponse {}

// Issues a single-use challenge for authorizing the session with a FIDO2 security key.
message MfaConfigFido2ChallengeRequest {
string session_token = 1;
}

message MfaConfigFido2ChallengeResponse {
string challenge = 1;
// Base64url credential IDs of the user's registered security keys.
repeated string credential_ids = 2;
}

// For OIDC the client polls this until the browser authentication completes.
message MfaConfigAuthorizeRequest {
string session_token = 1;
MfaMethod method = 2;
// Empty for FIDO2 and OIDC.
string code = 3;
// FIDO2 assertion.
optional bytes signature = 4;
optional bytes auth_data = 5;
optional bytes credential_id = 6;
}

message MfaConfigAuthorizeResponse {
Expand Down
2 changes: 2 additions & 0 deletions v2/proxy.proto
Original file line number Diff line number Diff line change
Expand Up @@ -120,6 +120,7 @@ message CoreResponse {
defguard.client_types.MfaConfigStartResponse mfa_config_start = 23;
defguard.client_types.MfaConfigAuthorizeResponse mfa_config_authorize = 24;
defguard.client_types.MfaConfigSendCodeResponse mfa_config_send_code = 25;
defguard.client_types.MfaConfigFido2ChallengeResponse mfa_config_fido2_challenge = 26;
}
}

Expand Down Expand Up @@ -223,6 +224,7 @@ message CoreRequest {
defguard.client_types.MfaConfigAuthorizeRequest mfa_config_authorize = 25;
defguard.client_types.MfaConfigSendCodeRequest mfa_config_send_code = 26;
defguard.client_types.MfaConfigEndRequest mfa_config_end = 27;
defguard.client_types.MfaConfigFido2ChallengeRequest mfa_config_fido2_challenge = 28;
}
}

Expand Down
Loading