You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 904fe51
Browse filesBrowse the repository at this point in the historyBrowse files
sec(auth): stop leaking MFA enrollment via login error responses (closes#388)
The login handler previously forwarded err.Error() verbatim for any
auth failure not matching ErrMFARequired or ErrInvalidMFACode. This
included "MFA is enabled but not configured", which revealed to an
attacker that credentials were correct and MFA was enrolled (but
broken). Two attack vectors were closed:
1. Add ErrMFANotConfigured sentinel to internal/auth/errors.go and
return it (wrapped via %w) from verifyPasswordAndMFA. Map it to
"mfa_required" in the login handler -- identical to ErrMFARequired
-- so "MFA enrolled + working" is indistinguishable from "MFA
enrolled + broken secret" in the HTTP response.
2. Replace the bare err.Error() fallthrough in the login handler with
a fixed "invalid credentials" string so no internal error message
ever reaches the client.
Tests positively assert response equivalence: ErrMFARequired and
ErrMFANotConfigured produce the same 401 + "mfa_required" body; all
wrong-password paths produce the same 401 + "invalid credentials" body.
0 commit comments