-
Notifications
You must be signed in to change notification settings - Fork 1.8k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Allow displaying hardware keys prompts when relogin is in progress #48813
Changes from 1 commit
8e3353a
198a73d
804716b
f2f6164
3d50c44
5506b80
c40578e
a0eb965
e8bf38e
3652931
8c99075
f25141b
d4ec48a
379f5b3
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Something is not right. After the cert expires and I submit my credentials through the form, the hardware key starts to blink, but I don't see the prompt in the app. I can touch the key and then continue with the PIV prompts. But I don't see the original MFA prompt for the key touch. I do see the MFA prompt during regular login in an OSS cluster. This is with piv-modals.movThere was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Guess what, the MFA modal can't be opened because relogin is in progress... This works during normal login, because in this case the login modal is a regular modal, when relogin is initiated from tshd, it is an important modal). So it looks like we need to remove the There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Hmm I'm still getting this actually, let me take a look to see if I can understand the cause. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Wait I think I just forgot to pull... |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I was going to ask if you have a proof for this, but I just quickly tested this by trying to log in through tsh and Connect at the same time and it seems to be true.
I did try this a looong time ago and back then it seemed to work, as in you'd submit two requests for touch and first touch would resolve the first request and the second touch would resolve the second one. But I think at the time I was still using U2F without knowing this.