-
Notifications
You must be signed in to change notification settings - Fork 1.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[PM-12512] Add Endpoint to allow users to request a new device otp #5146
base: main
Are you sure you want to change the base?
Conversation
…ite a test for new method in UserService.
Codecov ReportAttention: Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## main #5146 +/- ##
==========================================
+ Coverage 42.96% 43.01% +0.05%
==========================================
Files 1444 1447 +3
Lines 66101 66157 +56
Branches 6057 6061 +4
==========================================
+ Hits 28397 28455 +58
+ Misses 36422 36420 -2
Partials 1282 1282 ☔ View full report in Codecov by Sentry. |
New Issues
Fixed Issues
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Can we get complete test coverage for this new method?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Yep, added more explicit testing and some extra ones for SendOTPAsync
in d99e6f6
🎟️ Tracking
PM-12512
📔 Objective
When a user tries to log into a new device they are sent and OTP. If for any reason the OTP is invalid, or the user needs another OTP.
This PR adds an endpoint that allows the user to request another OTP in an unauthenticated state. Regardless of secret verification the endpoint will always return 200 to protect against account enumeration.
📸 Screenshots
⏰ Reminders before review
🦮 Reviewer guidelines
:+1:
) or similar for great changes:memo:
) or ℹ️ (:information_source:
) for notes or general info:question:
) for questions:thinking:
) or 💭 (:thought_balloon:
) for more open inquiry that's not quite a confirmed issue and could potentially benefit from discussion:art:
) for suggestions / improvements:x:
) or:warning:
) for more significant problems or concerns needing attention:seedling:
) or ♻️ (:recycle:
) for future improvements or indications of technical debt:pick:
) for minor or nitpick changes