Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Allow admins to verify its identity by providing an OTP code of its MFA, rather than a password. #34905

Open
pitbulk opened this issue Dec 30, 2021 · 1 comment

Comments

@pitbulk
Copy link

pitbulk commented Dec 30, 2021

Description (*)

In a scenario where admins authenticates at Magento using a SSO feature (SAML, OAuth, OIDC), there is usually no password assigned (authentications happens at the Identity Provider side), so there is no sense to request a password for validate an action on the admin area

Expected behavior (*)

Be able to validate the identity of the admin providing a valid OTP code, rather than the admin password.

Benefits

I have currently several customers of my SAML extension that gonna be really happy with this feature.
Also at Magento Marketplace, where you SSO using Adobe credentials, I'm not sure if exists the same problem and no idea how it is resolved there.

@m2-assistant
Copy link

m2-assistant bot commented Dec 30, 2021

Hi @pitbulk. Thank you for your report.
To speed up processing of this issue, make sure that you provided the following information:

  • Summary of the issue
  • Information on your environment
  • Steps to reproduce
  • Expected and actual results

Make sure that the issue is reproducible on the vanilla Magento instance following Steps to reproduce. To deploy vanilla Magento instance on our environment, Add a comment to the issue:

@magento give me 2.4-develop instance - upcoming 2.4.x release

For more details, review the Magento Contributor Assistant documentation.

Add a comment to assign the issue: @magento I am working on this

To learn more about issue processing workflow, refer to the Code Contributions.


⚠️ According to the Magento Contribution requirements, all issues must go through the Community Contributions Triage process. Community Contributions Triage is a public meeting.

🕙 You can find the schedule on the Magento Community Calendar page.

📞 The triage of issues happens in the queue order. If you want to speed up the delivery of your contribution, join the Community Contributions Triage session to discuss the appropriate ticket.

🎥 You can find the recording of the previous Community Contributions Triage on the Magento Youtube Channel

✏️ Feel free to post questions/proposals/feedback related to the Community Contributions Triage process to the corresponding Slack Channel

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
Feature Requests Backlog
  
Ready for Grooming
Development

No branches or pull requests

1 participant