Repository navigation
Reduce configuration and hide password MFA - #1416
Merged
Merged
Conversation
Retired account names, generic OIDC settings and the hosted-oidc-only profile are now unknown configuration: the refusal tables, their Compose presence markers and the upgrade rename table are gone, and the account setting list is written out explicitly so trimming and the whitespace-only mode refusal still apply. The deprecated CAPACITYLENS_RATE_LIMIT_TRUST_FORWARDED alias and the CAPACITYLENS_OPTIMISTIC_CONCURRENCY switch are removed. Under production an unset CAPACITYLENS_CORS_ORIGIN defaults to the public URL's origin; Compose still passes it empty, keeping the fail-closed allow-list. .env.example is regrouped as the operator reference (required, common, providers, mail, operations); development-only variables move to the development guide. Refs #1407 Signed-off-by: Kevinjohn Gallagher <kevinjohngallagher@hotmail.com>
SMALLSASS_ACCOUNT_REQUIRE_MFA is no longer read and the sign-in hooks no longer require a password second factor, so mfaRequired is always false. The app no longer mounts the enrolment screen; MfaEnrollmentScreen and its test stay in the tree, unreferenced. Operator, user and policy documents no longer describe the feature; security records keep describing the dormant code. SMALLSASS_ACCOUNT_SSO_MFA_ENFORCED, CAPACITYLENS_STORAGE_ENCRYPTED and CAPACITYLENS_SECURITY_LOG_FORWARDING are removed with their startup warnings; a missing internal TLS identity keeps its own warning. The security review records that CL-06's control moved to operator documentation. Refs #1407 Signed-off-by: Kevinjohn Gallagher <kevinjohngallagher@hotmail.com>
Signed-off-by: Kevinjohn Gallagher <kevinjohngallagher@hotmail.com>
Signed-off-by: Kevinjohn Gallagher <kevinjohngallagher@hotmail.com>
This was referenced Oct 1, 2026
This was referenced Oct 1, 2026
Owner
Author
|
Polish review: no P1/P2 findings.
Merge order for this batch: #1411, #1412, #1414 → #1413, #1415, #1416 → #1417 → #1418, #1419 → #1420 → #1421 → #1422 → #1423 → #1424 → #1425 → #1426. Predecessor: none. |
This was referenced Oct 1, 2026
…ion-mfa-hide # Conflicts: # docs/reference/development.html # docs/security/control-inventories.html # docs/security/security-review-2026-07-14.html # docs/security/threat-model.html
Signed-off-by: Kevinjohn Gallagher <kevinjohngallagher@hotmail.com>
This was referenced Oct 1, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Part of #1407 (T7). Merge predecessor: none. Followed by #1417 and #1418, stacked on this branch.
hosted-oidc-onlycheck are deleted;CANONICAL_ACCOUNT_NAMESis an explicit list, so trimming and the whitespace-mode refusal still work. Retired names are simply unknown.REQUIRE_MFAandSSO_MFA_ENFORCEDare no longer read, the enrolment screen is no longer reachable, and MFA/TOTP is gone from README, AGENTS.md, DECISIONS.md, user stories and operator/user docs. The two-factor wiring stays dormant; security records still describe it.STORAGE_ENCRYPTEDandSECURITY_LOG_FORWARDINGattestation flags and their warnings are removed; a missing internal TLS identity still warns on its own line. The security review gains a dated note that CL-06's control moved to operator documentation.CAPACITYLENS_RATE_LIMIT_TRUST_FORWARDEDalias and the optimistic-concurrency env read are removed (concurrency checks always on).NODE_ENV=production, an unsetCAPACITYLENS_CORS_ORIGINdefaults to the public URL's origin; empty stays fail-closed; Compose passes it empty..env.exampleregrouped as the operator reference; development-only variables moved to the development guide.After merge: open "Investigate MFA via Better Auth". It will note that the Better Auth two-factor endpoints stay reachable by direct API call, and that the sign-in code prompt still appears for an identity enrolled that way.
Validation: integrated with the rest of Batch 2 and Batch 3 (T7, T15, T6, T8, T16) on 84ae32e7 over origin/main da72918:
pnpm run gate:allandpnpm run e2e(290 tests) pass on Node 24.16.0. Independently reviewed before E2E; review findings fixed.Merge order
Merge predecessor for this PR: none.