[Browser MFA] Add proto for Browser MFA feature (#64048)

This commit is contained in:
Dan Share
2026-03-06 07:02:44 +00:00
committed by GitHub
parent 85e46df86d
commit 7c6057cce2
5 changed files with 1372 additions and 1044 deletions
File diff suppressed because it is too large Load Diff
@@ -2447,6 +2447,9 @@ message PresenceMFAChallengeRequest {
// ProxyAddress is the address of the proxy the client is connected to, used
// to select a redirect URL for connectors that have more than one.
string ProxyAddress = 3 [(gogoproto.jsontag) = "proxy_address,omitempty"];
// BrowserMFATSHRedirectURL should be supplied if the client supports Browser MFA.
// If unset, the server will only return non-Browser MFA challenges.
string BrowserMFATSHRedirectURL = 4 [(gogoproto.jsontag) = "browser_mfa_tsh_redirect_url,omitempty"];
}
// PresenceMFAChallengeSend is a presence challenge request or response.
@@ -52,6 +52,7 @@ message MFADevice {
U2FDevice u2f = 9;
WebauthnDevice webauthn = 10;
SSOMFADevice sso = 11;
BrowserMFADevice browser = 12;
}
}
@@ -125,3 +126,8 @@ message SSOMFADevice {
// display_name is the display name of the SSO connector
string display_name = 3;
}
// BrowserMFADevice is a synthetic MFA device that is made available if a user
// has at least one WebAuthn device and no SSO setup. This message doesn't
// require any fields, it just needs to exist so it can be an MFA option.
message BrowserMFADevice {}
+266 -51
View File
@@ -45,6 +45,7 @@ type MFADevice struct {
// *MFADevice_U2F
// *MFADevice_Webauthn
// *MFADevice_Sso
// *MFADevice_Browser
Device isMFADevice_Device `protobuf_oneof:"device"`
XXX_NoUnkeyedLiteral struct{} `json:"-"`
XXX_unrecognized []byte `json:"-"`
@@ -102,11 +103,15 @@ type MFADevice_Webauthn struct {
type MFADevice_Sso struct {
Sso *SSOMFADevice `protobuf:"bytes,11,opt,name=sso,proto3,oneof" json:"sso,omitempty"`
}
type MFADevice_Browser struct {
Browser *BrowserMFADevice `protobuf:"bytes,12,opt,name=browser,proto3,oneof" json:"browser,omitempty"`
}
func (*MFADevice_Totp) isMFADevice_Device() {}
func (*MFADevice_U2F) isMFADevice_Device() {}
func (*MFADevice_Webauthn) isMFADevice_Device() {}
func (*MFADevice_Sso) isMFADevice_Device() {}
func (*MFADevice_Browser) isMFADevice_Device() {}
func (m *MFADevice) GetDevice() isMFADevice_Device {
if m != nil {
@@ -143,6 +148,13 @@ func (m *MFADevice) GetSso() *SSOMFADevice {
return nil
}
func (m *MFADevice) GetBrowser() *BrowserMFADevice {
if x, ok := m.GetDevice().(*MFADevice_Browser); ok {
return x.Browser
}
return nil
}
// XXX_OneofWrappers is for the internal use of the proto package.
func (*MFADevice) XXX_OneofWrappers() []interface{} {
return []interface{}{
@@ -150,6 +162,7 @@ func (*MFADevice) XXX_OneofWrappers() []interface{} {
(*MFADevice_U2F)(nil),
(*MFADevice_Webauthn)(nil),
(*MFADevice_Sso)(nil),
(*MFADevice_Browser)(nil),
}
}
@@ -368,12 +381,55 @@ func (m *SSOMFADevice) XXX_DiscardUnknown() {
var xxx_messageInfo_SSOMFADevice proto.InternalMessageInfo
// BrowserMFADevice is a synthetic MFA device that is made available if a user
// has at least one WebAuthn device and no SSO setup. This message doesn't
// require any fields, it just needs to exist so it can be an MFA option.
type BrowserMFADevice struct {
XXX_NoUnkeyedLiteral struct{} `json:"-"`
XXX_unrecognized []byte `json:"-"`
XXX_sizecache int32 `json:"-"`
}
func (m *BrowserMFADevice) Reset() { *m = BrowserMFADevice{} }
func (m *BrowserMFADevice) String() string { return proto.CompactTextString(m) }
func (*BrowserMFADevice) ProtoMessage() {}
func (*BrowserMFADevice) Descriptor() ([]byte, []int) {
return fileDescriptor_aee666f88c27ffea, []int{5}
}
func (m *BrowserMFADevice) XXX_Unmarshal(b []byte) error {
return m.Unmarshal(b)
}
func (m *BrowserMFADevice) XXX_Marshal(b []byte, deterministic bool) ([]byte, error) {
if deterministic {
return xxx_messageInfo_BrowserMFADevice.Marshal(b, m, deterministic)
} else {
b = b[:cap(b)]
n, err := m.MarshalToSizedBuffer(b)
if err != nil {
return nil, err
}
return b[:n], nil
}
}
func (m *BrowserMFADevice) XXX_Merge(src proto.Message) {
xxx_messageInfo_BrowserMFADevice.Merge(m, src)
}
func (m *BrowserMFADevice) XXX_Size() int {
return m.Size()
}
func (m *BrowserMFADevice) XXX_DiscardUnknown() {
xxx_messageInfo_BrowserMFADevice.DiscardUnknown(m)
}
var xxx_messageInfo_BrowserMFADevice proto.InternalMessageInfo
func init() {
proto.RegisterType((*MFADevice)(nil), "types.MFADevice")
proto.RegisterType((*TOTPDevice)(nil), "types.TOTPDevice")
proto.RegisterType((*U2FDevice)(nil), "types.U2FDevice")
proto.RegisterType((*WebauthnDevice)(nil), "types.WebauthnDevice")
proto.RegisterType((*SSOMFADevice)(nil), "types.SSOMFADevice")
proto.RegisterType((*BrowserMFADevice)(nil), "types.BrowserMFADevice")
}
func init() {
@@ -381,57 +437,58 @@ func init() {
}
var fileDescriptor_aee666f88c27ffea = []byte{
// 785 bytes of a gzipped FileDescriptorProto
0x1f, 0x8b, 0x08, 0x00, 0x00, 0x00, 0x00, 0x00, 0x02, 0xff, 0x94, 0x54, 0xff, 0x6e, 0x1b, 0x45,
0x10, 0x8e, 0xe3, 0xc4, 0x3e, 0x8f, 0x9d, 0xc4, 0x59, 0x0a, 0x1c, 0x91, 0x70, 0x5a, 0x53, 0xda,
0xa0, 0x0a, 0x5b, 0xa4, 0x7f, 0x23, 0x14, 0x17, 0xaa, 0x46, 0xa1, 0x04, 0x5d, 0x1d, 0x40, 0x48,
0xe8, 0xb4, 0x77, 0x3b, 0xb9, 0x2c, 0x3e, 0xdf, 0xae, 0x6e, 0xf7, 0x52, 0x9d, 0x78, 0x09, 0x1e,
0x2b, 0x7f, 0x22, 0x1e, 0x80, 0x1f, 0x79, 0x03, 0xde, 0x00, 0xed, 0xde, 0xde, 0xd9, 0x0d, 0x02,
0x89, 0xff, 0x76, 0xbf, 0xf9, 0x66, 0x66, 0x67, 0xbe, 0x4f, 0x0b, 0x8f, 0x34, 0xa6, 0x28, 0x45,
0xae, 0xa7, 0x29, 0x26, 0x34, 0x2e, 0xa7, 0xba, 0x94, 0xa8, 0xa6, 0xcb, 0x4b, 0x1a, 0x32, 0xbc,
0xe6, 0x31, 0x4e, 0x64, 0x2e, 0xb4, 0x20, 0xdb, 0x16, 0x3f, 0xb8, 0x97, 0x88, 0x44, 0x58, 0x64,
0x6a, 0x4e, 0x55, 0xf0, 0xe0, 0x30, 0x11, 0x22, 0x49, 0x71, 0x6a, 0x6f, 0x51, 0x71, 0x39, 0xd5,
0x7c, 0x89, 0x4a, 0xd3, 0xa5, 0x74, 0x84, 0xd1, 0x5d, 0xc2, 0xeb, 0x9c, 0x4a, 0x89, 0xb9, 0x72,
0xf1, 0x87, 0xff, 0xf2, 0x0a, 0xd4, 0x94, 0x51, 0x4d, 0x2b, 0xd6, 0xf8, 0xd7, 0x36, 0xf4, 0x5e,
0x3e, 0x3f, 0xf9, 0xdc, 0xbe, 0x8b, 0x10, 0xd8, 0x5a, 0xf0, 0x8c, 0xf9, 0xad, 0xfb, 0xad, 0xa3,
0x5e, 0x60, 0xcf, 0xe4, 0x3d, 0xf0, 0x54, 0x11, 0x85, 0x16, 0xdf, 0xb4, 0x78, 0x57, 0x15, 0xd1,
0x99, 0x09, 0xf9, 0xd0, 0xbd, 0xc6, 0x5c, 0x71, 0x91, 0xf9, 0xed, 0x2a, 0xe2, 0xae, 0xe4, 0x13,
0xf0, 0xea, 0x46, 0xfe, 0xd6, 0xfd, 0xd6, 0x51, 0xff, 0x78, 0x6f, 0x62, 0xfb, 0x4f, 0x5e, 0x3a,
0x78, 0xb6, 0x75, 0xf3, 0xdb, 0xe1, 0x46, 0xd0, 0xd0, 0xc8, 0x2e, 0x6c, 0x72, 0xe6, 0x6f, 0xdb,
0x3a, 0x9b, 0x9c, 0x91, 0xcf, 0xc0, 0xa3, 0x8c, 0x21, 0x0b, 0xa9, 0xf6, 0x3b, 0xb6, 0xc4, 0xc1,
0xa4, 0x1a, 0x79, 0x52, 0x8f, 0x3c, 0x99, 0xd7, 0x3b, 0x99, 0x79, 0xa6, 0xda, 0xcf, 0xbf, 0x1f,
0xb6, 0x82, 0xae, 0xcd, 0x3a, 0xd1, 0xe4, 0x04, 0x7a, 0x29, 0x55, 0x3a, 0x2c, 0x14, 0x32, 0xbf,
0xfb, 0x3f, 0x2a, 0x78, 0x26, 0xed, 0x42, 0x21, 0x23, 0x8f, 0x61, 0x4b, 0x0b, 0x2d, 0x7d, 0xcf,
0x66, 0xef, 0xbb, 0x11, 0xe6, 0xe7, 0xf3, 0xaf, 0xab, 0x85, 0xbd, 0xd8, 0x08, 0x2c, 0x81, 0x3c,
0x84, 0x76, 0x71, 0x7c, 0xe9, 0xf7, 0x2c, 0x6f, 0xe8, 0x78, 0x17, 0xc7, 0xcf, 0x1b, 0x9a, 0x09,
0x93, 0xa7, 0xe0, 0xbd, 0xc6, 0x88, 0x16, 0xfa, 0x2a, 0xf3, 0xc1, 0x52, 0xdf, 0x76, 0xd4, 0x6f,
0x1d, 0xdc, 0xf0, 0x1b, 0x22, 0x79, 0x0c, 0x6d, 0xa5, 0x84, 0xdf, 0xb7, 0xfc, 0xb7, 0x1c, 0xff,
0xd5, 0xab, 0xf3, 0x46, 0x35, 0x53, 0x5d, 0x29, 0x31, 0xf3, 0xa0, 0x53, 0xd9, 0x6b, 0x3c, 0x02,
0x58, 0xbd, 0x91, 0x0c, 0xa1, 0xbd, 0xc0, 0xd2, 0x69, 0x6a, 0x8e, 0xe3, 0x1f, 0xa0, 0xd7, 0xbc,
0x8d, 0xbc, 0x0f, 0xb0, 0xc0, 0x32, 0xbc, 0xa2, 0x19, 0x4b, 0xd1, 0xb2, 0x06, 0x41, 0x6f, 0x81,
0xe5, 0x0b, 0x0b, 0x90, 0x77, 0xa1, 0x2b, 0x8d, 0xfc, 0x58, 0x5a, 0xf5, 0x07, 0x41, 0x47, 0x16,
0xd1, 0x19, 0x96, 0x46, 0xfc, 0x58, 0x14, 0x99, 0xc6, 0xdc, 0x8a, 0xbf, 0x13, 0xd4, 0xd7, 0xf1,
0x5f, 0x6d, 0xd8, 0x7d, 0x73, 0x20, 0xf2, 0x01, 0xec, 0xc4, 0x39, 0x32, 0xcc, 0x34, 0xa7, 0x69,
0xc8, 0x99, 0xeb, 0x33, 0x58, 0x81, 0xa7, 0x8c, 0x3c, 0x82, 0x3d, 0x59, 0x44, 0x29, 0x8f, 0x4d,
0xb7, 0x30, 0x8e, 0x44, 0xee, 0x5a, 0xee, 0x54, 0xf0, 0x19, 0x96, 0xcf, 0x22, 0x91, 0x93, 0x8f,
0x60, 0x48, 0xb5, 0x36, 0xb2, 0x69, 0x2e, 0xb2, 0xd0, 0x6c, 0xc4, 0xf9, 0x6f, 0x6f, 0x0d, 0x9f,
0x97, 0x12, 0xc9, 0x3b, 0xd0, 0xa1, 0x34, 0x29, 0x38, 0xb3, 0x2e, 0x1c, 0x04, 0xee, 0x46, 0x9e,
0xc0, 0xbe, 0xe2, 0x49, 0x46, 0x75, 0x91, 0x63, 0x58, 0x8f, 0xb1, 0x6d, 0xc7, 0x18, 0x36, 0x81,
0x67, 0x15, 0x4e, 0x3e, 0x06, 0xb2, 0xde, 0x4f, 0x44, 0x3f, 0x62, 0x5c, 0x79, 0x72, 0x10, 0xec,
0xaf, 0x45, 0xce, 0x6d, 0x80, 0x3c, 0x80, 0x41, 0x8e, 0x8a, 0x9b, 0xb9, 0xec, 0xda, 0x8c, 0xf5,
0xbc, 0xa0, 0x5f, 0x63, 0x66, 0x77, 0x47, 0x30, 0x5c, 0x5b, 0x47, 0x2e, 0xcd, 0x46, 0x3c, 0x3b,
0xc1, 0xee, 0x0a, 0x0f, 0xe4, 0x29, 0x23, 0xdf, 0xc1, 0xc1, 0x1a, 0x33, 0xa2, 0xf1, 0xa2, 0x90,
0x21, 0xa6, 0x3c, 0xe1, 0x51, 0x8a, 0xce, 0x6f, 0xff, 0x74, 0xf5, 0x4c, 0x88, 0xf4, 0x1b, 0x9a,
0x16, 0x18, 0xf8, 0xab, 0xec, 0x99, 0x4d, 0xfe, 0xc2, 0xe5, 0x92, 0x2f, 0xe1, 0xde, 0x9d, 0xca,
0xc8, 0xc2, 0x42, 0x3a, 0x63, 0xfe, 0x57, 0x4d, 0xf2, 0x66, 0x4d, 0x64, 0x17, 0x72, 0xfc, 0x13,
0x0c, 0xd6, 0x3d, 0x69, 0x96, 0x10, 0x8b, 0x2c, 0xc3, 0x58, 0x8b, 0xbc, 0xd6, 0xbb, 0x17, 0xf4,
0x1b, 0xec, 0x94, 0x91, 0x0f, 0x61, 0x77, 0x45, 0xb1, 0x22, 0x56, 0xdf, 0xcb, 0x4e, 0x83, 0x5a,
0x09, 0x1f, 0xc0, 0x80, 0x71, 0x25, 0x53, 0x5a, 0x86, 0x19, 0x5d, 0xd6, 0x4a, 0xf7, 0x1d, 0xf6,
0x15, 0x5d, 0xe2, 0xec, 0xd3, 0x9b, 0x3f, 0x47, 0x1b, 0x37, 0xb7, 0xa3, 0xd6, 0x2f, 0xb7, 0xa3,
0xd6, 0x1f, 0xb7, 0xa3, 0xd6, 0xf7, 0x4f, 0x12, 0xae, 0xaf, 0x8a, 0x68, 0x12, 0x8b, 0xe5, 0x34,
0xc9, 0xe9, 0x35, 0xaf, 0x14, 0xa2, 0xe9, 0xb4, 0xf9, 0x15, 0xa9, 0xe4, 0xd5, 0x97, 0x18, 0x75,
0xec, 0x8c, 0x4f, 0xff, 0x0e, 0x00, 0x00, 0xff, 0xff, 0x0b, 0x34, 0x9e, 0x36, 0xb8, 0x05, 0x00,
0x00,
// 812 bytes of a gzipped FileDescriptorProto
0x1f, 0x8b, 0x08, 0x00, 0x00, 0x00, 0x00, 0x00, 0x02, 0xff, 0x94, 0x54, 0xdd, 0x6e, 0xe3, 0x44,
0x14, 0x6e, 0x9a, 0x34, 0x71, 0x4e, 0xdc, 0x36, 0x1d, 0x16, 0xd6, 0x54, 0x22, 0xdd, 0x0d, 0xcb,
0x6e, 0xd1, 0x8a, 0x44, 0xb4, 0xd7, 0x08, 0x35, 0x0b, 0xab, 0xad, 0xca, 0x52, 0xe4, 0x6d, 0x01,
0x21, 0x21, 0x6b, 0xec, 0x39, 0x75, 0x87, 0x38, 0x9e, 0x91, 0x3d, 0x6e, 0x65, 0xf1, 0x00, 0xdc,
0xf2, 0x58, 0xbd, 0xe4, 0x09, 0xf8, 0xe9, 0x1b, 0xf0, 0x06, 0x68, 0xc6, 0x63, 0x27, 0x2d, 0x02,
0x69, 0xef, 0x66, 0xbe, 0xf3, 0x9d, 0x73, 0xfc, 0x9d, 0xf3, 0x79, 0xe0, 0xa9, 0xc2, 0x04, 0xa5,
0xc8, 0xd4, 0x34, 0xc1, 0x98, 0x46, 0xe5, 0x54, 0x95, 0x12, 0xf3, 0xe9, 0xe2, 0x82, 0x06, 0x0c,
0xaf, 0x78, 0x84, 0x13, 0x99, 0x09, 0x25, 0xc8, 0x86, 0xc1, 0x77, 0x1f, 0xc4, 0x22, 0x16, 0x06,
0x99, 0xea, 0x53, 0x15, 0xdc, 0xdd, 0x8b, 0x85, 0x88, 0x13, 0x9c, 0x9a, 0x5b, 0x58, 0x5c, 0x4c,
0x15, 0x5f, 0x60, 0xae, 0xe8, 0x42, 0x5a, 0xc2, 0xe8, 0x3e, 0xe1, 0x3a, 0xa3, 0x52, 0x62, 0x96,
0xdb, 0xf8, 0x93, 0xff, 0xf8, 0x0a, 0x54, 0x94, 0x51, 0x45, 0x2b, 0xd6, 0xf8, 0x97, 0x0e, 0xf4,
0x5f, 0xbf, 0x3c, 0xfa, 0xc2, 0x7c, 0x17, 0x21, 0xd0, 0x99, 0xf3, 0x94, 0x79, 0xad, 0x47, 0xad,
0xfd, 0xbe, 0x6f, 0xce, 0xe4, 0x7d, 0x70, 0xf2, 0x22, 0x0c, 0x0c, 0xbe, 0x6e, 0xf0, 0x5e, 0x5e,
0x84, 0x27, 0x3a, 0xe4, 0x41, 0xef, 0x0a, 0xb3, 0x9c, 0x8b, 0xd4, 0x6b, 0x57, 0x11, 0x7b, 0x25,
0x9f, 0x82, 0x53, 0x37, 0xf2, 0x3a, 0x8f, 0x5a, 0xfb, 0x83, 0x83, 0xed, 0x89, 0xe9, 0x3f, 0x79,
0x6d, 0xe1, 0x59, 0xe7, 0xe6, 0xf7, 0xbd, 0x35, 0xbf, 0xa1, 0x91, 0x2d, 0x58, 0xe7, 0xcc, 0xdb,
0x30, 0x75, 0xd6, 0x39, 0x23, 0x9f, 0x83, 0x43, 0x19, 0x43, 0x16, 0x50, 0xe5, 0x75, 0x4d, 0x89,
0xdd, 0x49, 0x25, 0x79, 0x52, 0x4b, 0x9e, 0x9c, 0xd5, 0x33, 0x99, 0x39, 0xba, 0xda, 0xaf, 0x7f,
0xec, 0xb5, 0xfc, 0x9e, 0xc9, 0x3a, 0x52, 0xe4, 0x08, 0xfa, 0x09, 0xcd, 0x55, 0x50, 0xe4, 0xc8,
0xbc, 0xde, 0x5b, 0x54, 0x70, 0x74, 0xda, 0x79, 0x8e, 0x8c, 0x3c, 0x83, 0x8e, 0x12, 0x4a, 0x7a,
0x8e, 0xc9, 0xde, 0xb1, 0x12, 0xce, 0x4e, 0xcf, 0xbe, 0xa9, 0x06, 0xf6, 0x6a, 0xcd, 0x37, 0x04,
0xf2, 0x04, 0xda, 0xc5, 0xc1, 0x85, 0xd7, 0x37, 0xbc, 0xa1, 0xe5, 0x9d, 0x1f, 0xbc, 0x6c, 0x68,
0x3a, 0x4c, 0x0e, 0xc1, 0xb9, 0xc6, 0x90, 0x16, 0xea, 0x32, 0xf5, 0xc0, 0x50, 0xdf, 0xb5, 0xd4,
0xef, 0x2c, 0xdc, 0xf0, 0x1b, 0x22, 0x79, 0x06, 0xed, 0x3c, 0x17, 0xde, 0xc0, 0xf0, 0xdf, 0xb1,
0xfc, 0x37, 0x6f, 0x4e, 0x9b, 0xad, 0xe9, 0xea, 0x79, 0x2e, 0xc8, 0x21, 0xf4, 0xc2, 0x4c, 0x5c,
0xe7, 0x98, 0x79, 0xae, 0x21, 0x3f, 0xb4, 0xe4, 0x59, 0x85, 0xae, 0x26, 0xd4, 0xcc, 0x99, 0x03,
0xdd, 0xca, 0x93, 0xe3, 0x11, 0xc0, 0x52, 0x18, 0x19, 0x42, 0x7b, 0x8e, 0xa5, 0x35, 0x82, 0x3e,
0x8e, 0x7f, 0x84, 0x7e, 0x23, 0x88, 0x7c, 0x00, 0x30, 0xc7, 0x32, 0xb8, 0xa4, 0x29, 0x4b, 0xd0,
0xb0, 0x5c, 0xbf, 0x3f, 0xc7, 0xf2, 0x95, 0x01, 0xc8, 0x43, 0xe8, 0x49, 0xed, 0x19, 0x2c, 0x8d,
0x65, 0x5c, 0xbf, 0x2b, 0x8b, 0xf0, 0x04, 0x4b, 0xed, 0x98, 0x48, 0x14, 0xa9, 0xc2, 0xcc, 0x38,
0x66, 0xd3, 0xaf, 0xaf, 0xe3, 0xbf, 0xdb, 0xb0, 0x75, 0x77, 0x0a, 0xe4, 0x43, 0xd8, 0x8c, 0x32,
0x64, 0x98, 0x2a, 0x4e, 0x93, 0x80, 0x33, 0xdb, 0xc7, 0x5d, 0x82, 0xc7, 0x8c, 0x3c, 0x85, 0x6d,
0x59, 0x84, 0x09, 0x8f, 0x74, 0xb7, 0x20, 0x0a, 0x45, 0x66, 0x5b, 0x6e, 0x56, 0xf0, 0x09, 0x96,
0x2f, 0x42, 0x91, 0x91, 0x8f, 0x61, 0x48, 0x95, 0xd2, 0xbb, 0x56, 0x5c, 0xa4, 0x81, 0x9e, 0x8c,
0x35, 0xed, 0xf6, 0x0a, 0x7e, 0x56, 0x4a, 0x24, 0xef, 0x41, 0x97, 0xd2, 0xb8, 0xe0, 0xcc, 0x58,
0xd7, 0xf5, 0xed, 0x8d, 0x3c, 0x87, 0x9d, 0x9c, 0xc7, 0x29, 0x55, 0x45, 0x86, 0x41, 0x2d, 0x63,
0xc3, 0xc8, 0x18, 0x36, 0x81, 0x17, 0x15, 0x4e, 0x3e, 0x01, 0xb2, 0xda, 0x4f, 0x84, 0x3f, 0x61,
0x54, 0x19, 0xd9, 0xf5, 0x77, 0x56, 0x22, 0xa7, 0x26, 0x40, 0x1e, 0x83, 0x9b, 0x61, 0xce, 0xb5,
0x2e, 0x33, 0x36, 0xed, 0x57, 0xc7, 0x1f, 0xd4, 0x98, 0x9e, 0xdd, 0x3e, 0x0c, 0x57, 0xc6, 0x91,
0x49, 0x3d, 0x11, 0xc7, 0x28, 0xd8, 0x5a, 0xe2, 0xbe, 0x3c, 0x66, 0xe4, 0x7b, 0xd8, 0x5d, 0x61,
0x86, 0x34, 0x9a, 0x17, 0x32, 0xc0, 0x84, 0xc7, 0x3c, 0x4c, 0xd0, 0x9a, 0xf4, 0xdf, 0xbf, 0xc2,
0x4c, 0x88, 0xe4, 0x5b, 0x9a, 0x14, 0xe8, 0x7b, 0xcb, 0xec, 0x99, 0x49, 0xfe, 0xd2, 0xe6, 0x92,
0xaf, 0xe0, 0xc1, 0xbd, 0xca, 0xc8, 0x82, 0x42, 0x5a, 0x37, 0xff, 0x5f, 0x4d, 0x72, 0xb7, 0x26,
0xb2, 0x73, 0x39, 0xfe, 0x19, 0xdc, 0x55, 0x23, 0xeb, 0x21, 0x44, 0x22, 0x4d, 0x31, 0x52, 0x22,
0xab, 0xf7, 0xdd, 0xf7, 0x07, 0x0d, 0x76, 0xcc, 0xc8, 0x47, 0xb0, 0xb5, 0xa4, 0x98, 0x25, 0x56,
0x6f, 0xd2, 0x66, 0x83, 0x9a, 0x15, 0x3e, 0x06, 0x97, 0xf1, 0x5c, 0x26, 0xb4, 0x0c, 0x52, 0xba,
0xa8, 0x37, 0x3d, 0xb0, 0xd8, 0xd7, 0x74, 0x81, 0x63, 0x02, 0xc3, 0xfb, 0x3f, 0xc6, 0xec, 0xb3,
0x9b, 0xbf, 0x46, 0x6b, 0x37, 0xb7, 0xa3, 0xd6, 0x6f, 0xb7, 0xa3, 0xd6, 0x9f, 0xb7, 0xa3, 0xd6,
0x0f, 0xcf, 0x63, 0xae, 0x2e, 0x8b, 0x70, 0x12, 0x89, 0xc5, 0x34, 0xce, 0xe8, 0x15, 0xaf, 0xb6,
0x46, 0x93, 0x69, 0xf3, 0xbc, 0x52, 0xc9, 0xab, 0xb7, 0x35, 0xec, 0x1a, 0xdd, 0x87, 0xff, 0x04,
0x00, 0x00, 0xff, 0xff, 0x68, 0xf6, 0x48, 0xe8, 0x01, 0x06, 0x00, 0x00,
}
func (m *MFADevice) Marshal() (dAtA []byte, err error) {
@@ -608,6 +665,27 @@ func (m *MFADevice_Sso) MarshalToSizedBuffer(dAtA []byte) (int, error) {
}
return len(dAtA) - i, nil
}
func (m *MFADevice_Browser) MarshalTo(dAtA []byte) (int, error) {
size := m.Size()
return m.MarshalToSizedBuffer(dAtA[:size])
}
func (m *MFADevice_Browser) MarshalToSizedBuffer(dAtA []byte) (int, error) {
i := len(dAtA)
if m.Browser != nil {
{
size, err := m.Browser.MarshalToSizedBuffer(dAtA[:i])
if err != nil {
return 0, err
}
i -= size
i = encodeVarintMfaDevice(dAtA, i, uint64(size))
}
i--
dAtA[i] = 0x62
}
return len(dAtA) - i, nil
}
func (m *TOTPDevice) Marshal() (dAtA []byte, err error) {
size := m.Size()
dAtA = make([]byte, size)
@@ -844,6 +922,33 @@ func (m *SSOMFADevice) MarshalToSizedBuffer(dAtA []byte) (int, error) {
return len(dAtA) - i, nil
}
func (m *BrowserMFADevice) Marshal() (dAtA []byte, err error) {
size := m.Size()
dAtA = make([]byte, size)
n, err := m.MarshalToSizedBuffer(dAtA[:size])
if err != nil {
return nil, err
}
return dAtA[:n], nil
}
func (m *BrowserMFADevice) MarshalTo(dAtA []byte) (int, error) {
size := m.Size()
return m.MarshalToSizedBuffer(dAtA[:size])
}
func (m *BrowserMFADevice) MarshalToSizedBuffer(dAtA []byte) (int, error) {
i := len(dAtA)
_ = i
var l int
_ = l
if m.XXX_unrecognized != nil {
i -= len(m.XXX_unrecognized)
copy(dAtA[i:], m.XXX_unrecognized)
}
return len(dAtA) - i, nil
}
func encodeVarintMfaDevice(dAtA []byte, offset int, v uint64) int {
offset -= sovMfaDevice(v)
base := offset
@@ -940,6 +1045,18 @@ func (m *MFADevice_Sso) Size() (n int) {
}
return n
}
func (m *MFADevice_Browser) Size() (n int) {
if m == nil {
return 0
}
var l int
_ = l
if m.Browser != nil {
l = m.Browser.Size()
n += 1 + l + sovMfaDevice(uint64(l))
}
return n
}
func (m *TOTPDevice) Size() (n int) {
if m == nil {
return 0
@@ -1053,6 +1170,18 @@ func (m *SSOMFADevice) Size() (n int) {
return n
}
func (m *BrowserMFADevice) Size() (n int) {
if m == nil {
return 0
}
var l int
_ = l
if m.XXX_unrecognized != nil {
n += len(m.XXX_unrecognized)
}
return n
}
func sovMfaDevice(x uint64) (n int) {
return (math_bits.Len64(x|1) + 6) / 7
}
@@ -1455,6 +1584,41 @@ func (m *MFADevice) Unmarshal(dAtA []byte) error {
}
m.Device = &MFADevice_Sso{v}
iNdEx = postIndex
case 12:
if wireType != 2 {
return fmt.Errorf("proto: wrong wireType = %d for field Browser", wireType)
}
var msglen int
for shift := uint(0); ; shift += 7 {
if shift >= 64 {
return ErrIntOverflowMfaDevice
}
if iNdEx >= l {
return io.ErrUnexpectedEOF
}
b := dAtA[iNdEx]
iNdEx++
msglen |= int(b&0x7F) << shift
if b < 0x80 {
break
}
}
if msglen < 0 {
return ErrInvalidLengthMfaDevice
}
postIndex := iNdEx + msglen
if postIndex < 0 {
return ErrInvalidLengthMfaDevice
}
if postIndex > l {
return io.ErrUnexpectedEOF
}
v := &BrowserMFADevice{}
if err := v.Unmarshal(dAtA[iNdEx:postIndex]); err != nil {
return err
}
m.Device = &MFADevice_Browser{v}
iNdEx = postIndex
default:
iNdEx = preIndex
skippy, err := skipMfaDevice(dAtA[iNdEx:])
@@ -2207,6 +2371,57 @@ func (m *SSOMFADevice) Unmarshal(dAtA []byte) error {
}
return nil
}
func (m *BrowserMFADevice) Unmarshal(dAtA []byte) error {
l := len(dAtA)
iNdEx := 0
for iNdEx < l {
preIndex := iNdEx
var wire uint64
for shift := uint(0); ; shift += 7 {
if shift >= 64 {
return ErrIntOverflowMfaDevice
}
if iNdEx >= l {
return io.ErrUnexpectedEOF
}
b := dAtA[iNdEx]
iNdEx++
wire |= uint64(b&0x7F) << shift
if b < 0x80 {
break
}
}
fieldNum := int32(wire >> 3)
wireType := int(wire & 0x7)
if wireType == 4 {
return fmt.Errorf("proto: BrowserMFADevice: wiretype end group for non-group")
}
if fieldNum <= 0 {
return fmt.Errorf("proto: BrowserMFADevice: illegal tag %d (wire type %d)", fieldNum, wire)
}
switch fieldNum {
default:
iNdEx = preIndex
skippy, err := skipMfaDevice(dAtA[iNdEx:])
if err != nil {
return err
}
if (skippy < 0) || (iNdEx+skippy) < 0 {
return ErrInvalidLengthMfaDevice
}
if (iNdEx + skippy) > l {
return io.ErrUnexpectedEOF
}
m.XXX_unrecognized = append(m.XXX_unrecognized, dAtA[iNdEx:iNdEx+skippy]...)
iNdEx += skippy
}
}
if iNdEx > l {
return io.ErrUnexpectedEOF
}
return nil
}
func skipMfaDevice(dAtA []byte) (n int, err error) {
l := len(dAtA)
iNdEx := 0
+51 -1
View File
@@ -96,6 +96,12 @@ export interface MFADevice {
* @generated from protobuf field: types.SSOMFADevice sso = 11;
*/
sso: SSOMFADevice;
} | {
oneofKind: "browser";
/**
* @generated from protobuf field: types.BrowserMFADevice browser = 12;
*/
browser: BrowserMFADevice;
} | {
oneofKind: undefined;
};
@@ -250,6 +256,15 @@ export interface SSOMFADevice {
*/
displayName: string;
}
/**
* BrowserMFADevice is a synthetic MFA device that is made available if a user
* has at least one WebAuthn device and no SSO setup. This message doesn't
* require any fields, it just needs to exist so it can be an MFA option.
*
* @generated from protobuf message types.BrowserMFADevice
*/
export interface BrowserMFADevice {
}
// @generated message type with reflection information, may provide speed optimized methods
class MFADevice$Type extends MessageType<MFADevice> {
constructor() {
@@ -264,7 +279,8 @@ class MFADevice$Type extends MessageType<MFADevice> {
{ no: 8, name: "totp", kind: "message", oneof: "device", T: () => TOTPDevice },
{ no: 9, name: "u2f", kind: "message", jsonName: "u2f", oneof: "device", T: () => U2FDevice },
{ no: 10, name: "webauthn", kind: "message", oneof: "device", T: () => WebauthnDevice },
{ no: 11, name: "sso", kind: "message", oneof: "device", T: () => SSOMFADevice }
{ no: 11, name: "sso", kind: "message", oneof: "device", T: () => SSOMFADevice },
{ no: 12, name: "browser", kind: "message", oneof: "device", T: () => BrowserMFADevice }
]);
}
create(value?: PartialMessage<MFADevice>): MFADevice {
@@ -328,6 +344,12 @@ class MFADevice$Type extends MessageType<MFADevice> {
sso: SSOMFADevice.internalBinaryRead(reader, reader.uint32(), options, (message.device as any).sso)
};
break;
case /* types.BrowserMFADevice browser */ 12:
message.device = {
oneofKind: "browser",
browser: BrowserMFADevice.internalBinaryRead(reader, reader.uint32(), options, (message.device as any).browser)
};
break;
default:
let u = options.readUnknownField;
if (u === "throw")
@@ -373,6 +395,9 @@ class MFADevice$Type extends MessageType<MFADevice> {
/* types.SSOMFADevice sso = 11; */
if (message.device.oneofKind === "sso")
SSOMFADevice.internalBinaryWrite(message.device.sso, writer.tag(11, WireType.LengthDelimited).fork(), options).join();
/* types.BrowserMFADevice browser = 12; */
if (message.device.oneofKind === "browser")
BrowserMFADevice.internalBinaryWrite(message.device.browser, writer.tag(12, WireType.LengthDelimited).fork(), options).join();
let u = options.writeUnknownFields;
if (u !== false)
(u == true ? UnknownFieldHandler.onWrite : u)(this.typeName, message, writer);
@@ -673,3 +698,28 @@ class SSOMFADevice$Type extends MessageType<SSOMFADevice> {
* @generated MessageType for protobuf message types.SSOMFADevice
*/
export const SSOMFADevice = new SSOMFADevice$Type();
// @generated message type with reflection information, may provide speed optimized methods
class BrowserMFADevice$Type extends MessageType<BrowserMFADevice> {
constructor() {
super("types.BrowserMFADevice", []);
}
create(value?: PartialMessage<BrowserMFADevice>): BrowserMFADevice {
const message = globalThis.Object.create((this.messagePrototype!));
if (value !== undefined)
reflectionMergePartial<BrowserMFADevice>(this, message, value);
return message;
}
internalBinaryRead(reader: IBinaryReader, length: number, options: BinaryReadOptions, target?: BrowserMFADevice): BrowserMFADevice {
return target ?? this.create();
}
internalBinaryWrite(message: BrowserMFADevice, writer: IBinaryWriter, options: BinaryWriteOptions): IBinaryWriter {
let u = options.writeUnknownFields;
if (u !== false)
(u == true ? UnknownFieldHandler.onWrite : u)(this.typeName, message, writer);
return writer;
}
}
/**
* @generated MessageType for protobuf message types.BrowserMFADevice
*/
export const BrowserMFADevice = new BrowserMFADevice$Type();