Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 8 additions & 0 deletions packages/profile-sync-controller/CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,9 +9,17 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0

### Changed

- Open the verification session on enrollment and let the server set its lifetime ([#10653](https://github.com/MetaMask/core/pull/10653))
- `completeCredentialEnrollment` opens a verification session with the assertion `POST /api/v2/mfa/enroll/complete` returns for the new credential, replacing any earlier one, so no separate verification is needed right after enrolling. If the token exchange fails, the enrollment still succeeds and the earlier session is kept
- `SRPJwtBearerAuth.completeMfaEnrollment` and `JwtBearerAuth.completeMfaEnrollment` return that assertion
- The session lasts for the token's `expires_in`, measured on the device clock, instead of at most 15 minutes
- Replace JS AES implementation with `@metamask/cryptography` ([#10621](https://github.com/MetaMask/core/pull/10621))
- Bump `immer` from `^9.0.21` to `^11.1.18` ([#10382](https://github.com/MetaMask/core/pull/10382))

### Removed

- **BREAKING:** Remove `VERIFICATION_SESSION_TTL_MS`, as the server now sets the verification session lifetime ([#10653](https://github.com/MetaMask/core/pull/10653))

### Fixed

- Coalesce overlapping `performSignIn` calls so only one sign-in runs at a time ([#10646](https://github.com/MetaMask/core/pull/10646))
Expand Down
15 changes: 11 additions & 4 deletions packages/profile-sync-controller/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -58,14 +58,21 @@ email OTP enrollment and verification:
The controller never inspects the token's assurance level; the server
decides. A setup flow that proved a factor itself can pass
`maxSessionAgeMs` (for example, the time since the flow started) so chained
enrollments reuse that proof. Enrollment does not end the session.
enrollments reuse that proof. `completeCredentialEnrollment()` opens a
verification session with the assertion the server returns for the new
credential (replacing any earlier one), so no separate verification is
needed right after enrolling.
- `beginCredentialVerification()` and `completeCredentialVerification()`
verify an enrolled credential and return a verification token.
- `getVerificationToken()` reuses a live verification session when it satisfies
the caller's freshness requirement; `clearVerificationSession()` clears it. The
session lasts as long as the verification token (at most
`VERIFICATION_SESSION_TTL_MS`, 15 minutes) and ends on lock, sign-out, reset, or
a rejected base session.
session lasts as long as the server says the token does (`expires_in`,
measured from when it was obtained) and ends on lock, sign-out, reset, or a
rejected base session. It is
a low-level read: features should go through the client MFA kit
(`verifyOrEnroll`), which reuses a matching session without showing any
screen. Read it directly only from code that cannot show UI, and treat `null`
as "let the UI layer ask".

Clients must retain the challenge `flowId`, perform the platform ceremony, and
send the resulting proof to the matching completion method. OTP codes,
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -44,6 +44,11 @@ export type AuthenticationControllerBeginCredentialEnrollmentAction = {
/**
* Completes credential enrollment and refreshes the credential cache.
*
* The server returns an assertion for the new credential, which opens a
* verification session like `completeCredentialVerification`, replacing
* any earlier one. If that exchange fails, the earlier session is kept:
* the credential is enrolled either way.
*
* A cache-refresh failure does not undo successful enrollment. Email
* enrollment invalidates the primary SRP session *after* refresh so the
* credentials call can reuse the still-valid access token; the next token
Expand Down Expand Up @@ -91,6 +96,12 @@ export type AuthenticationControllerCompleteCredentialVerificationAction = {
* Returns the active verification token when it meets the requested
* freshness.
*
* Low-level: features should go through the client MFA kit
* (`verifyOrEnroll`), which reuses a matching session without showing any
* screen and checks which method proved it. Read the token directly only
* from code that cannot show UI, and treat `null` as "let the UI layer
* ask".
*
* @param request - Optional maximum session age in milliseconds, measured
* from when the token was obtained. Zero always requires a new ceremony.
* @returns A live verification token, or null when no reusable session
Expand Down
Loading
Loading