Problem/Motivation
This came from a writeup (AI assisted) by @mxr576 that was presented to me triggering a quick visual of the code.
It appears in TfaAuthDecoratorCompiler we ignore the wrong provider ID for the core HTTP Basic provider.
This doesn't on its own cause a security bypass, as the site owner would first need to have whitelisted the provider and the UserAuth service protections would have had to of failed/been bypassed. It is however possible in such a misconfiguration that a bypass could occur.
This significantly erodes the multi layer redundancy planned for the core provided authentication providers.
Steps to reproduce
Proposed resolution
Validate correct provider ID.
If incorrect update code and docs
Evaluate test changes.
Remaining tasks
User interface changes
API changes
Data model changes
Comments
Comment #2
cmlara