Files
teleport/api/client/proto
rosstimothy 640bd01640 Improve performance of MFA ceremony (#24250)
To date clients attempting to access a resource first have to call
`proto.AuthService/IsMFARequired` to determine if an mfa ceremony
is needed for access to a resource. In an effort to reduce an
extra round trip to the Auth server this can can be bundled into
`proto.AuthService/GenerateUserSingleUseCerts`.

In order for RBAC to determine if mfa is required for SSH sessions
the OS login of the session must be known. To accomodate this a
new `SSHLogin` field was added to `proto.UserCertsRequest`.

The response to the initial request of the stream now contains a
`proto.MFARequired` enum which indicates whether mfa is required,
not required, or it's unknown if mfa is required. The last variant
should only be returned when the `SSHLogin` field is unset in the
initial request.

The `(auth.Server) isMFARequired` check was also modified for nodes
to make use of `ListResources`. Instead of retrieving **all** nodes
into memory and finding the matching ones, a request is made to
`ListResources` with the `SearchKeywords` populated with the target
from `proto.IsMFARequiredRequest_Node.Node.Node`. Care was taken
to filter out any matches from labels to preserve the original
matching behavior.
2023-04-14 19:08:28 +00:00
..
2023-02-08 17:21:11 +00:00