Skip to content

feat(profile-sync-controller)!: open verification session on enrollment and let server manage tokens TTL - #10653

Merged
mathieuartu merged 6 commits into
mainfrom
feat/mfa-enroll-verification-session
Oct 1, 2026
Merged

mathieuartu merged 6 commits into
mainfrom
feat/mfa-enroll-verification-session

Conversation

@mathieuartu

@mathieuartu mathieuartu commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Explanation

⚠️ change is breaking but nothing consumes it in clients, hence why I'm not doing test-drive PRs

References

Related to: https://consensyssoftware.atlassian.net/browse/MUL-2320

Checklist

  • I've updated the test suite for new or updated code as appropriate
  • I've updated documentation (JSDoc, Markdown, etc.) for new or updated code as appropriate
  • I've communicated my changes to consumers by updating changelogs for packages I've changed
  • I've introduced breaking changes in this PR and have prepared draft pull requests for clients and consumer packages to resolve them

Note

Medium Risk
Breaking exports and MFA session semantics affect authentication flows; changes are localized to profile-sync-controller with broad test coverage, but altered session duration and enroll→verify behavior need careful client integration.

Overview
Aligns MFA enrollment and verification session handling with the updated POST /api/v2/mfa/enroll/complete API, which now returns an assertion like verify-complete instead of { status: 'enrolled' }.

completeCredentialEnrollment exchanges that assertion for a verification token and opens a session for the newly enrolled credential (replacing any prior session), so callers usually skip a separate verify step after enroll. Enrollment still succeeds if the token exchange fails; the previous session is kept. completeMfaEnrollment in the SDK now returns MfaVerificationAssertion (breaking for direct SDK callers).

Verification session lifetime no longer uses the removed VERIFICATION_SESSION_TTL_MS (15-minute cap) or JWT exp at open time. Sessions run for the server’s expires_in, measured from obtainedAt on the device clock, with stricter validation when expires_in is missing or invalid. Shared helper #openVerificationSessionFromAssertion powers both verify- and enroll-complete paths.

Docs and JSDoc note that getVerificationToken is low-level and UI flows should prefer verifyOrEnroll.

Reviewed by Cursor Bugbot for commit 17a5de6. Bugbot is set up for automated code reviews on this repo. Configure here.

@mathieuartu mathieuartu self-assigned this Oct 1, 2026
@mathieuartu
mathieuartu requested review from a team as code owners October 1, 2026 10:55
@mathieuartu
mathieuartu deployed to default-branch October 1, 2026 10:56 — with GitHub Actions Active
@mathieuartu mathieuartu changed the title Feat/mfa enroll verification session feat(profile-sync-controller): open verification session on enrollment and let server manage tokens TTL Oct 1, 2026
@gantunesr gantunesr changed the title feat(profile-sync-controller): open verification session on enrollment and let server manage tokens TTL feat(profile-sync-controller)!: open verification session on enrollment and let server manage tokens TTL Oct 1, 2026
ccharly
ccharly previously approved these changes Oct 1, 2026
@mathieuartu
mathieuartu force-pushed the feat/mfa-enroll-verification-session branch from 01d3c64 to 17a5de6 Compare October 1, 2026 15:01
@mathieuartu
mathieuartu added this pull request to the merge queue Oct 1, 2026
Merged via the queue into main with commit 8fe4cb6 Oct 1, 2026
142 checks passed
@mathieuartu
mathieuartu deleted the feat/mfa-enroll-verification-session branch October 1, 2026 15:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants