OpenConext / OpenConext/OpenConext-engineblock

User is shown confusing technical error message when they refuse/can't do MFA (e.g., in eduID)

Open
#1,248 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
PHP
Stars
17
Forks
25
Avg merge
4d 1h
Merged PRs (30d)
1

Description

When an IdP is configured (in manage) to require a specific ACCR fot a service, and the MFA login fails for some reason, Engineblock shows this generic error message to the user:

Screenshot 2023-05-25 at 09 37 07

While technically correct, it would be nice if we could make this specific error a bit more readable for regular users. For me it was not entirely clear on first glance that this was an MFA error. Regular users probably have no idea what is happening here.

To reproduce:

  • connect an SP to eduID and configure Refeds MFA for this connection
  • log into the service but in eduID refuse to install the app or login with a token
  • EB shows this error.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the MFA login flow described in the reproduction steps, using an eduID connection configured with Refeds MFA and refusing the app or token login. Locate where Engineblock displays the generic error shown in the issue and make the result understandable to regular users as an MFA failure, then verify the reproduced flow shows the clearer message.

Written by the indexing model from the issue text.

Assessment

Tech stack
php
Domain
authentication
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.