FeatureFuel
1

OAuth 2.1 server: no way to require MFA (aal2) for OAuth client access tokens

Source: supabase/supabase#50990 · opened by @jhurleyai
Problem. Tokens issued by the OAuth 2.1 server always carry aal: "aal1" and amr: [{"method":"oauth_provider/authorization_code"}]. The OAuth session is created fresh at AAL1 (/oauth/token → IssueRefreshToken → models.NewSession), and the consenting session's AAL is never considered. The consent endpoints (GET /oauth/authorizations/{id}, POST …/consent) only require authentication, not a particular AAL, and the GET auto-approves a previously consented client. So a resource server that requires aal2 (e.g. an MCP server fronting sensitive data in a project that enforces TOTP for its users) cannot accept any OAuth token, and has no supported way to know that consent was given from an MFA-verified session. Request (any of): 1. Stamp the OAuth session with the consenting session's AAL/AMR (e.g. aal2, amr including totp), as suggested as an alternative fix in #2801. 2. An OAuth server setting to require aal2 on the consenting session for the autho…

No pledges yet. Be the first to back this.

Make a pledge

Pledge your monetary support if this feature is added.

$

Comments

No comments yet.

Replying to

Add a comment

What do you think about this feature request?


Similar requests