Allow TwoFactor providers to be stateless#308
Merged
Conversation
Prior to this change, there was no way to determine if a two-factor provider needed preparation before authentication. This change introduces the needsPreparation method in the TwoFactorProviderInterface and its implementations, allowing the system to skip the preparation process for providers that do not require it. The preparation process requires state. For example: Prior to this change, if no state was available, the Totp and Google authenticators would fail, even if they are stateless. Co-authored-by: Tjeerd <tjeerd@ibuildings.nl>
d7a1bf2 to
2df4f9c
Compare
Prior to this change, the needsPreparation method would break existing implementations. This change makes the change not break existing TwoFactorProviders by not actually defining the `needsPreparation` in the interface. This is to be implemented in version 9 of the 2fa package.
2df4f9c to
81f6039
Compare
scheb
requested changes
Jan 18, 2026
Owner
scheb
left a comment
There was a problem hiding this comment.
Thanks for going through the effort adjusting the implementation. I believe we can improve the test case a bit. Other than that, I'm happy to merge that in.
tests/Security/TwoFactor/Provider/TwoFactorProviderInitiatorTest.php
Outdated
Show resolved
Hide resolved
7484f6b to
0ab4058
Compare
…the TwoFactorProvider does not have the needsPreparation function. Also adds `needsPreparation` to TwoFactorProviderInterface.
0ab4058 to
3d141c4
Compare
Owner
|
Released as v8.3.0 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Prior to this change, there was no way to determine if a two-factor provider needed preparation before authentication.
This change introduces the needsPreparation method in the TwoFactorProviderInterface and its implementations, allowing the system to skip the preparation process for providers that do not require it. The preparation process requires state.
For example:
Prior to this change, if no state was available, the Totp and Google authenticators would fail, even if they are stateless.
Now, non-bc breaking.
Fixes #306