Problem/Motivation

This came from a writeup (AI assisted) by @mxr576 that was presented to me triggering a quick visual of the code.

It appears in TfaAuthDecoratorCompiler we ignore the wrong provider ID for the core HTTP Basic provider.

This doesn't on its own cause a security bypass, as the site owner would first need to have whitelisted the provider and the UserAuth service protections would have had to of failed/been bypassed. It is however possible in such a misconfiguration that a bypass could occur.

This significantly erodes the multi layer redundancy planned for the core provided authentication providers.

Steps to reproduce

Proposed resolution

Validate correct provider ID.
If incorrect update code and docs
Evaluate test changes.

Remaining tasks

User interface changes

API changes

Data model changes

Comments

cmlara created an issue. See original summary.

cmlara’s picture

Issue summary: View changes