mitigating the effects of forceAuthn terrorism
Scott Cantor
scott at restingparrotsoftware.com
Thu Apr 9 14:44:17 UTC 2026
> ForceAuthn doesn't "downgrade" anything, nor does it "destroy" any existing results or "do local SLO" in this code, though I suspect in most implementations it might.
Looking at the code in the MFA flow, I suspect it has that visible effect when the MFA flow is used, and it would be hard to avoid it, even though that's not what it's actually doing under the covers.
I'd have to consider what more could be done to change the behavior without violating the semantic, but making everything even more complex isn't a good answer. The goal is correctness. User convenience is not something really factored in when ForceAuthn is involved.
-- Scott
More information about the users
mailing list