Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Support TOTP two-factor authentication #4737

Merged
merged 3 commits into from
Jan 15, 2024
Merged

Conversation

JohnNiang
Copy link
Member

@JohnNiang JohnNiang commented Oct 17, 2023

What type of PR is this?

/kind feature
/area core

What this PR does / why we need it:

See #4541 for more.

Which issue(s) this PR fixes:

Fixes #4541

Special notes for your reviewer:

Does this PR introduce a user-facing change?

支持 2FA 认证方式

@f2c-ci-robot f2c-ci-robot bot added kind/feature Categorizes issue or PR as related to a new feature. do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. release-note Denotes a PR that will be considered when it comes time to generate release notes. labels Oct 17, 2023
@f2c-ci-robot f2c-ci-robot bot requested review from LIlGG and minliacom October 17, 2023 06:45
@f2c-ci-robot f2c-ci-robot bot added the area/core Issues or PRs related to the Halo Core label Oct 17, 2023
@JohnNiang
Copy link
Member Author

Hi @ruibaby ,似乎缺失 2FA 页面的 UI。

@ruibaby
Copy link
Member

ruibaby commented Oct 25, 2023

Hi @ruibaby ,似乎缺失 2FA 页面的 UI。

想想咋整,如果用页面提供,会影响原来登录失效弹框的流程。

@JohnNiang
Copy link
Member Author

Hi @ruibaby ,似乎缺失 2FA 页面的 UI。

想想咋整,如果用页面提供,会影响原来登录失效弹框的流程。

暂时不考虑页面提供吧。按照目前提供的登录页面和登录弹窗单独适配即可。

@f2c-ci-robot f2c-ci-robot bot added the needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD. label Nov 16, 2023
@JohnNiang JohnNiang added this to the 2.11.0 milestone Nov 24, 2023
@JohnNiang JohnNiang modified the milestones: 2.11.0, 2.12.x Dec 1, 2023
@JohnNiang
Copy link
Member Author

Hi @ruibaby , I find it difficult to resolve conflicts involved in the console, please help me resolve them before continuing. ❤️

@ruibaby
Copy link
Member

ruibaby commented Dec 1, 2023

Hi @ruibaby , I find it difficult to resolve conflicts involved in the console, please help me resolve them before continuing. ❤️

Okay,I will reset and then place it in the user center.

@f2c-ci-robot f2c-ci-robot bot removed the needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD. label Dec 7, 2023
@f2c-ci-robot f2c-ci-robot bot added the needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD. label Dec 28, 2023
@f2c-ci-robot f2c-ci-robot bot removed the needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD. label Jan 13, 2024
@JohnNiang JohnNiang changed the title WIP: Support Multi-factor authentication WIP: Support two-factor authentication Jan 14, 2024
@JohnNiang JohnNiang changed the title WIP: Support two-factor authentication WIP: Support TOTP two-factor authentication Jan 14, 2024
@JohnNiang JohnNiang force-pushed the feat/mfa branch 2 times, most recently from f960a5d to 75cd29c Compare January 14, 2024 16:48
@ruibaby
Copy link
Member

ruibaby commented Jan 15, 2024

/retitle Support TOTP two-factor authentication

Ready for review

@f2c-ci-robot f2c-ci-robot bot changed the title WIP: Support TOTP two-factor authentication Support TOTP two-factor authentication Jan 15, 2024
@f2c-ci-robot f2c-ci-robot bot removed the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Jan 15, 2024
ruibaby and others added 2 commits January 15, 2024 15:21
Signed-off-by: John Niang <johnniang@foxmail.com>
Signed-off-by: John Niang <johnniang@foxmail.com>
Copy link

codecov bot commented Jan 15, 2024

Codecov Report

Attention: 313 lines in your changes are missing coverage. Please review.

Comparison is base (b050e29) 56.47% compared to head (7946585) 55.98%.
Report is 3 commits behind head on main.

❗ Current head 7946585 differs from pull request most recent head daf4334. Consider uploading reports for the commit daf4334 to get more accurate results

Files Patch % Lines
...uthentication/twofactor/TwoFactorAuthEndpoint.java 32.00% 102 Missing ⚠️
...ation/twofactor/totp/TotpAuthenticationFilter.java 22.22% 49 Missing ⚠️
.../authentication/login/UsernamePasswordHandler.java 17.50% 33 Missing ⚠️
...nfra/exception/RequestBodyValidationException.java 0.00% 21 Missing ⚠️
...lo/app/security/authentication/login/HaloUser.java 52.94% 16 Missing ⚠️
...twofactor/DefaultTwoFactorAuthResponseHandler.java 28.57% 15 Missing ⚠️
...ication/twofactor/totp/DefaultTotpAuthService.java 69.23% 10 Missing and 2 partials ⚠️
...urity/authentication/twofactor/TwoFactorUtils.java 0.00% 10 Missing ⚠️
...un/halo/app/security/LogoutSecurityConfigurer.java 56.25% 7 Missing ⚠️
...ernamePasswordDelegatingAuthenticationManager.java 0.00% 7 Missing ⚠️
... and 12 more
Additional details and impacted files
@@             Coverage Diff              @@
##               main    #4737      +/-   ##
============================================
- Coverage     56.47%   55.98%   -0.50%     
- Complexity     3003     3027      +24     
============================================
  Files           525      538      +13     
  Lines         17614    17973     +359     
  Branches       1304     1319      +15     
============================================
+ Hits           9948    10062     +114     
- Misses         7126     7367     +241     
- Partials        540      544       +4     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

Copy link
Member

@ruibaby ruibaby left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

@f2c-ci-robot f2c-ci-robot bot added the lgtm Indicates that a PR is ready to be merged. label Jan 15, 2024
Copy link

f2c-ci-robot bot commented Jan 15, 2024

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: guqing

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@f2c-ci-robot f2c-ci-robot bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Jan 15, 2024
@f2c-ci-robot f2c-ci-robot bot removed the lgtm Indicates that a PR is ready to be merged. label Jan 15, 2024
@guqing
Copy link
Member

guqing commented Jan 15, 2024

/lgtm

@f2c-ci-robot f2c-ci-robot bot added the lgtm Indicates that a PR is ready to be merged. label Jan 15, 2024
@ruibaby ruibaby merged commit 3de60dd into halo-dev:main Jan 15, 2024
7 checks passed
@JohnNiang JohnNiang deleted the feat/mfa branch January 15, 2024 09:16
@ruibaby ruibaby modified the milestones: 2.12.x, 2.12.0 Jan 16, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
approved Indicates a PR has been approved by an approver from all required OWNERS files. area/core Issues or PRs related to the Halo Core kind/feature Categorizes issue or PR as related to a new feature. lgtm Indicates that a PR is ready to be merged. release-note Denotes a PR that will be considered when it comes time to generate release notes.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

新功能建议:增加登录用户二步验证(Authenticator)
3 participants