Skip to content

Reduce configuration and hide password MFA - #1416

Merged
Kevinjohn merged 6 commits into
mainfrom
feature/config-reduction-mfa-hide
Oct 1, 2026
Merged

Kevinjohn merged 6 commits into
mainfrom
feature/config-reduction-mfa-hide

Conversation

@Kevinjohn

@Kevinjohn Kevinjohn commented Oct 1, 2026 •

Copy link
Copy Markdown
Owner

Part of #1407 (T7). Merge predecessor: none. Followed by #1417 and #1418, stacked on this branch.

  • Retired-name tables, generic OIDC keys and the hosted-oidc-only check are deleted; CANONICAL_ACCOUNT_NAMES is an explicit list, so trimming and the whitespace-mode refusal still work. Retired names are simply unknown.
  • MFA is hidden, not removed (D5): REQUIRE_MFA and SSO_MFA_ENFORCED are no longer read, the enrolment screen is no longer reachable, and MFA/TOTP is gone from README, AGENTS.md, DECISIONS.md, user stories and operator/user docs. The two-factor wiring stays dormant; security records still describe it.
  • STORAGE_ENCRYPTED and SECURITY_LOG_FORWARDING attestation flags and their warnings are removed; a missing internal TLS identity still warns on its own line. The security review gains a dated note that CL-06's control moved to operator documentation.
  • CAPACITYLENS_RATE_LIMIT_TRUST_FORWARDED alias and the optimistic-concurrency env read are removed (concurrency checks always on).
  • Under NODE_ENV=production, an unset CAPACITYLENS_CORS_ORIGIN defaults to the public URL's origin; empty stays fail-closed; Compose passes it empty.
  • .env.example regrouped as the operator reference; development-only variables moved to the development guide.

After merge: open "Investigate MFA via Better Auth". It will note that the Better Auth two-factor endpoints stay reachable by direct API call, and that the sign-in code prompt still appears for an identity enrolled that way.

Validation: integrated with the rest of Batch 2 and Batch 3 (T7, T15, T6, T8, T16) on 84ae32e7 over origin/main da72918: pnpm run gate:all and pnpm run e2e (290 tests) pass on Node 24.16.0. Independently reviewed before E2E; review findings fixed.

Merge order

  1. Route support to Discussions and remove PR screenshots #1411, Add project status, comparison, testing and philosophy pages #1412, Archive changelog sections before 0.41.0-alpha.3 #1414 (independent)
  2. Add a first-change path for contributors #1413 (after Archive changelog sections before 0.41.0-alpha.3 #1414), Restate the comment standard as numbered voice rules #1415, Reduce configuration and hide password MFA #1416
  3. Rename SMALLSASS_ACCOUNT_ settings to CAPACITYLENS_ #1417 → Add an init command that writes the environment file #1418
  4. Retire unused settings and derive engagement grouping #1419 → Move diagnostics to an Owner and Admin page #1420 → Reshape the documentation into four role guides #1421 → Use @/ for app imports that leave their folder #1422 → Consolidate server test scaffolding #1423 → Normalise server route handlers and reply messages #1424 → Apply the comment-voice rules and check them in the gate #1425 (Apply the comment-voice rules and check them in the gate #1425 also after Restate the comment standard as numbered voice rules #1415) → Name the tenant boundary account in code #1426

Merge predecessor for this PR: none.

Retired account names, generic OIDC settings and the hosted-oidc-only
profile are now unknown configuration: the refusal tables, their Compose
presence markers and the upgrade rename table are gone, and the account
setting list is written out explicitly so trimming and the whitespace-only
mode refusal still apply.

The deprecated CAPACITYLENS_RATE_LIMIT_TRUST_FORWARDED alias and the
CAPACITYLENS_OPTIMISTIC_CONCURRENCY switch are removed. Under production an
unset CAPACITYLENS_CORS_ORIGIN defaults to the public URL's origin; Compose
still passes it empty, keeping the fail-closed allow-list.

.env.example is regrouped as the operator reference (required, common,
providers, mail, operations); development-only variables move to the
development guide.

Refs #1407

Signed-off-by: Kevinjohn Gallagher <kevinjohngallagher@hotmail.com>
SMALLSASS_ACCOUNT_REQUIRE_MFA is no longer read and the sign-in hooks no
longer require a password second factor, so mfaRequired is always false.
The app no longer mounts the enrolment screen; MfaEnrollmentScreen and its
test stay in the tree, unreferenced. Operator, user and policy documents no
longer describe the feature; security records keep describing the dormant
code.

SMALLSASS_ACCOUNT_SSO_MFA_ENFORCED, CAPACITYLENS_STORAGE_ENCRYPTED and
CAPACITYLENS_SECURITY_LOG_FORWARDING are removed with their startup
warnings; a missing internal TLS identity keeps its own warning. The
security review records that CL-06's control moved to operator
documentation.

Refs #1407

Signed-off-by: Kevinjohn Gallagher <kevinjohngallagher@hotmail.com>
Signed-off-by: Kevinjohn Gallagher <kevinjohngallagher@hotmail.com>
Signed-off-by: Kevinjohn Gallagher <kevinjohngallagher@hotmail.com>
@Kevinjohn

Copy link
Copy Markdown
Owner Author

Polish review: no P1/P2 findings.

  • Independent review checked that no stale retired setting can weaken a security control.
    • Mode defaults to password-only, open signup stays off, and proxy trust stays off.
    • hosted-oidc-only still refuses to start.
  • A user already enrolled in TOTP still signs in: the two-factor plugin and the login prompt remain. No path still demands enrolment.
  • The production CORS default yields only the configured public origin. An empty value stays fail-closed, and * is still rejected.
  • Ladder passes on Node 24: format, lint, typecheck, file sizes, server tsc, crypto inventory and account conformance. Focused auth and config suites pass.
  • Not applied:
    • The now-unused requireMfa plumbing and the optimisticConcurrency option. Removing them changes AppOptions and the /api/auth/me shape.
    • The unreachable MfaEnrollmentScreen, which stays hidden rather than removed by design.

Merge order for this batch: #1411, #1412, #1414 → #1413, #1415, #1416 → #1417 → #1418, #1419 → #1420 → #1421 → #1422 → #1423 → #1424 → #1425 → #1426. Predecessor: none.

…ion-mfa-hide

# Conflicts:
#	docs/reference/development.html
#	docs/security/control-inventories.html
#	docs/security/security-review-2026-07-14.html
#	docs/security/threat-model.html
Signed-off-by: Kevinjohn Gallagher <kevinjohngallagher@hotmail.com>
@Kevinjohn
Kevinjohn merged commit e5b401c into main Oct 1, 2026
5 checks passed
@Kevinjohn
Kevinjohn deleted the feature/config-reduction-mfa-hide branch October 1, 2026 19:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

polish-done Polish review complete

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant