feat: add Okta MFA challenge flow for okta_saml - #246
Conversation
Introduce the okta_saml auth type so Okta-backed contexts can be defined ahead of runtime credential exchange (DevopsArtFactory#85). Config gains okta_org_url and okta_app_id fields in both the flat and structured auth forms, the context add wizard offers okta_saml with non-secret fields only (passwords and MFA secrets never touch config.yaml), and the repository/env flows reject okta_saml contexts with a clear not-implemented-yet error instead of misbehaving. Closes DevopsArtFactory#84 Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BFhLrnpVxivu62cC3k9NZB
Implement runtime credential resolution for okta_saml contexts: `unic env` performs Okta primary authentication (prompting on stderr with no-echo password input, or UNIC_OKTA_USERNAME/UNIC_OKTA_PASSWORD for automation), fetches the SAML assertion from the app embed link, parses the AWS role/principal pairs, and exchanges the assertion via sts:AssumeRoleWithSAML. Role selection is deterministic: the context's role_arn wins, a single role is auto-selected, and multiple roles without a preference produce an explicit error listing the choices. Session credentials are cached under ~/.config/unic/cache/okta-saml/ (0700/0600, keyed by org|app|role) until expiry; the Okta password and session token are never persisted. The TUI passively reuses a valid cached session and otherwise points at `unic env <context>`. Okta MFA challenges are rejected with a clear error until DevopsArtFactory#87 lands. Closes DevopsArtFactory#85 Closes DevopsArtFactory#86 Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BFhLrnpVxivu62cC3k9NZB
Handle MFA_REQUIRED during Okta primary authentication with a v1 factor set of TOTP (token:software:totp) and Okta Verify push. TOTP is preferred when both are enrolled because it completes without waiting; push sends the notification and polls the verify link (3s interval, 60s timeout) with explicit rejected/timeout/cancel handling. Accounts with only unsupported factors get an error listing what is available versus supported, and MFA_ENROLL is reported as no-enrolled-factor. One-time codes are read interactively and never persisted. Closes DevopsArtFactory#87 Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BFhLrnpVxivu62cC3k9NZB
|
Warning Review limit reached
Next review available in: 14 minutes You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (12)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Recreated as #259 from an in-repo branch under the maintainer account; this PR is superseded. |
Summary
Implements #87 (Okta SAML track #26). Stacked on #245 — merge #244 → #245 → this.
token:software:totp) and Okta Verify push. TOTP is preferred when both are enrolled because it completes without waiting.MFA_REQUIREDnow enters a challenge flow instead of erroring: factor selection → verification via the factor's verify link with the state token.REJECTED,TIMEOUT, context cancellation, and the poll deadline.MFA_ENROLLis reported as "no enrolled MFA factor".Testing
go test ./...passes: TOTP success and wrong-code failure, push approved-after-polling, push rejected, unsupported-factor listing — all againsthttptestOkta servers with scripted verify responses.make buildpasses.Closes #87
Part of #26