Repository navigation
Conversation
4cf74fd to
5f602c5
Compare
| value = local.parsed_secrets["duoSecurity_duo_skey"] | ||
| } | ||
|
|
||
| secrets { |
There was a problem hiding this comment.
Duo apps have been created for dev, and the secrets have been updated.
a667b27 to
7577edf
Compare
| expect(api.multifactor.enable).not.toHaveBeenCalled(); | ||
| }); | ||
|
|
||
| test("Matching user on non-LDAP connection; no Duo, access granted", async () => { |
There was a problem hiding this comment.
I did ask AI to generate some tests, but I'm not too happy with the way it wrote this one. I'll figure out a better comment.
There was a problem hiding this comment.
Yeah I'm not following how this is inspecting non-LDAP so I don't grok.
| _event.client.client_id = "client00000000000000000000000011"; | ||
| _event.user.email = "joe@mozilla.com"; | ||
| _event.user.groups = []; | ||
| _event.user.multifactor = ["duo"]; |
There was a problem hiding this comment.
Also, "no Duo", but includes Duo?
Jira: IAM-1989
7577edf to
b6abc1e
Compare
gcoxmoz
left a comment
There was a problem hiding this comment.
Conceptually okay but I think "boop the tests" maybe.
I will go ahead and approve because I trust you'll swizzle the few bits that are weird but I think it's safe enough.
| groups | ||
| ); | ||
| const matches = userMatches || groupMatches; | ||
| return matches ? step_up.required_indicator : undefined; |
There was a problem hiding this comment.
Does anything lint that step_up objects are required to have a required_indicator?
If so, great. If not, I suggest (pseudocode), if (step_up.required_indicator ?? false) { raise attributeerror }
There was a problem hiding this comment.
Yeah, that code is in sso-dashboard-configuration.
We aren't allowed to publish (er, well, I guess we can if we force merge) an apps.yml that would break this.
The comment above says as much:
// These values are somewhat trusted, because we have tests in
// sso-dashboard-configuration.
| expect(api.multifactor.enable).not.toHaveBeenCalled(); | ||
| }); | ||
|
|
||
| test("Matching user on non-LDAP connection; no Duo, access granted", async () => { |
There was a problem hiding this comment.
Yeah I'm not following how this is inspecting non-LDAP so I don't grok.
Jira: IAM-1989
Implemented as described in this doc.