acm-udayton / acm-udayton/ACM-Meeting-Records

[FEATURE] Add JWT authentication endpoints

未關閉
#157 0 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
enhancement
主要語言
Python
星號
7
分支
2
平均合併
4 天 23 小時
30 天內合併 PR
2

描述

## Feature Description

Replicate our existing session-based authentication and MFA flow with JWTs.

---

## Acceptance Criteria & Solution Requirements
*To close this issue, the following must be met (can be finalized in the comments):*
- [ ] 1. Application runs as expected with the new feature integrated seamlessly.
- [ ] 2. Code quality metrics are maintained, and linting has been considered in development.
- [ ] 3. Testing metrics are maintained, and tests have been updated/added wherever relevant during development.
- [ ] 4. Documentation has been updated to reflect the changes made during development.
- [ ] 5. Add a /api/v1/login REST endpoint to request username and password. If not an MFA-enabled account, issue the `access_token` and `refresh_token` JWTs. If MFA is enabled, issue a short-lived (5 minutes) intermediate `mfa_token`.
- [ ] 6. Add a /api/v1/mfa-otp REST endpoint to request MFA OTP. Require a `mfa_token` be sent as the bearer. If MFA is correct, issue the `access_token` and `refresh_token` JWTs.
- [ ] 7. Add a /api/v1/mfa-recovery REST endpoint to request MFA recovery code. Require a `mfa_token` be sent as the bearer. If MFA is correct, issue the `access_token` and `refresh_token` JWTs.

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。