From 205e2766f6ed4131f47deb3ab5ebf98e1dfa97cf Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Filip=20=C5=9Al=C4=99zak?= Date: Fri, 2 Oct 2026 14:07:17 +0200 Subject: [PATCH] mfa configuration capabilities in instance info --- common/client_types.proto | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/common/client_types.proto b/common/client_types.proto index 4c0bb33..eaf6275 100644 --- a/common/client_types.proto +++ b/common/client_types.proto @@ -168,6 +168,8 @@ message InstanceInfo { // [2.2] Lightweight summary of the enrolled user's configured MFA methods. // Used for quick checks (e.g. "does this user have any MFA methods?"). MfaUserState mfa_user_state = 11; + // [2.2] absent when this core cannot configure mfa from the client + MfaCapabilities mfa_capabilities = 12; } message DeviceConfigResponse { @@ -232,6 +234,15 @@ message MfaUserState { repeated MfaMethod configured_methods = 1; } +// [2.2] factors an mfa configuration session supports, static per core version. +// current availability comes from MfaConfigStartResponse and MfaUserState. +message MfaCapabilities { + // accepted by CodeMfaSetupStart and CodeMfaSetupFinish + repeated MfaMethod setup_methods = 1; + // accepted by MfaConfigAuthorize + repeated MfaMethod authorize_methods = 2; +} + // Why a step of the submitted plan was refused at Start. Every reason names one // specific step. A plan whose length does not match the resolved flow is a // malformed request and is refused with an INVALID_ARGUMENT status instead of