mirror of
https://github.com/gravitational/teleport.git
synced 2026-09-24 16:17:11 +08:00
To date clients attempting to access a resource first have to call `proto.AuthService/IsMFARequired` to determine if an mfa ceremony is needed for access to a resource. In an effort to reduce an extra round trip to the Auth server this can can be bundled into `proto.AuthService/GenerateUserSingleUseCerts`. In order for RBAC to determine if mfa is required for SSH sessions the OS login of the session must be known. To accomodate this a new `SSHLogin` field was added to `proto.UserCertsRequest`. The response to the initial request of the stream now contains a `proto.MFARequired` enum which indicates whether mfa is required, not required, or it's unknown if mfa is required. The last variant should only be returned when the `SSHLogin` field is unset in the initial request. The `(auth.Server) isMFARequired` check was also modified for nodes to make use of `ListResources`. Instead of retrieving **all** nodes into memory and finding the matching ones, a request is made to `ListResources` with the `SearchKeywords` populated with the target from `proto.IsMFARequiredRequest_Node.Node.Node`. Care was taken to filter out any matches from labels to preserve the original matching behavior.