Skip to content

Bug 2060356 - #2727

Merged
dklawren merged 1 commit into
mozilla:masterfrom
dklawren:2060356
Aug 25, 2026
Merged

Bug 2060356#2727
dklawren merged 1 commit into
mozilla:masterfrom
dklawren:2060356

Conversation

@dklawren

@dklawren dklawren commented Aug 25, 2026

Copy link
Copy Markdown
Collaborator

r+ carried over from private pull request
https://bugzilla.mozilla.org/show_bug.cgi?id=2060356

Copilot AI balanced review requested due to automatic review settings August 25, 2026 18:18

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Hardens Duo MFA verification against unverified token replay and removes unsupported recovery-code behavior.

Changes:

  • Centralizes out-of-band verification checks in the MFA provider.
  • Prevents provider substitution and Duo recovery-code generation.
  • Adds cleanup migration, UI handling, and regression tests.

Reviewed changes

Copilot reviewed 8 out of 8 changed files in this pull request and generated no comments.

Show a summary per file
File Description
userprefs.cgi Uses the enrolled provider and blocks Duo recovery codes.
token.cgi Relies on centralized MFA event verification.
template/en/default/account/prefs/mfa.html.tmpl Hides recovery-code controls for Duo.
t/mfa-duo-verify.t Tests verified and unverified Duo token handling.
Bugzilla/MFA/Duo.pm Enforces Duo verification proof and rejects recovery codes.
Bugzilla/MFA.pm Adds provider-specific event verification.
Bugzilla/Install/DB.pm Removes existing Duo recovery codes.
Bugzilla/App/Controller/MFA/Duo.pm Allows the Duo callback to establish verification proof.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@dklawren
dklawren merged commit 9e23f77 into mozilla:master Aug 25, 2026
8 checks passed
@dklawren
dklawren deleted the 2060356 branch August 25, 2026 18:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants