Skip to content

fix: fallback to password login when mfa needs captcha#12438

Merged
wanghe-fit2cloud merged 1 commit intodev-v2from
fix/mfa-captcha-fallback
Apr 9, 2026
Merged

fix: fallback to password login when mfa needs captcha#12438
wanghe-fit2cloud merged 1 commit intodev-v2from
fix/mfa-captcha-fallback

Conversation

@ssongliu
Copy link
Copy Markdown
Member

@ssongliu ssongliu commented Apr 8, 2026

No description provided.

@f2c-ci-robot
Copy link
Copy Markdown

f2c-ci-robot bot commented Apr 8, 2026

Adding the "do-not-merge/release-note-label-needed" label because no release-note block was detected, please follow our release note process to remove it.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@f2c-ci-robot
Copy link
Copy Markdown

f2c-ci-robot bot commented Apr 8, 2026

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign zhengkunwang223 for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

Copy link
Copy Markdown

@chatgpt-codex-connector chatgpt-codex-connector bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: d8b1b772eb

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

go saveLoginLogs(c, wrapLoginErr(msgKey, err))
if msgKey == "ErrMFA" {
global.IPTracker.RecordFailure(ip)
failures := initauth.GetMFASessionStore().RecordFailure(req.SessionID)
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Count MFA failures only for invalid codes

This now increments the MFA session failure counter for every ErrMFA response, but ErrMFA is also returned when the session is missing or the request IP does not match (AuthService.MFALogin checks those before code validation). As a result, retries from a changed client IP (or any caller holding a valid session ID) can consume failure budget without ever submitting a wrong OTP, eventually deleting the session and forcing captcha fallback. Please gate RecordFailure to the actual invalid-code path (or return a distinct error for non-code MFA failures).

Useful? React with 👍 / 👎.

@wanghe-fit2cloud wanghe-fit2cloud merged commit 218f92a into dev-v2 Apr 9, 2026
2 of 3 checks passed
@wanghe-fit2cloud wanghe-fit2cloud deleted the fix/mfa-captcha-fallback branch April 9, 2026 02:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants