Skip to content

chore(auth): remove /mfa/test and /mfa/test2 scaffolding routes - #21324

Merged
clouserw merged 1 commit into
mainfrom
fxa-14622
Sep 25, 2026
Merged

clouserw merged 1 commit into
mainfrom
fxa-14622

Conversation

@vbudhram

@vbudhram vbudhram commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Because

  • The /mfa/test and /mfa/test2 routes were scaffolding from when we built the MFA auth strategy. They have no remaining callers.
  • The test MFA action existed only for those routes.

This pull request

  • Removes GET /mfa/test, POST /mfa/test and POST /mfa/test2 from lib/routes/mfa.ts in fxa-auth-server.
  • Removes test from the default mfa.actions in the auth-server config.
  • Removes mfaTestGet, mfaTestPost and mfaTestPost2 from fxa-auth-client. This is a breaking change for those three methods only.
  • Removes the test action from the config override in mfa_totp.in.spec.ts.
  • Deletes functional-tests/tests/misc/mfa.spec.ts, which only drove the removed routes.

Issue that this pull request solves

Closes: https://mozilla-hub.atlassian.net/browse/FXA-14622

Checklist

Put an x in the boxes that apply

  • My commit is GPG signed.
  • If applicable, I have modified or added tests which pass locally.
  • I have added necessary documentation (if appropriate).
  • I have verified that my changes render correctly in RTL (if appropriate).
  • I have manually reviewed all AI generated code.

How to review (Optional)

  • Key files/areas to focus on: packages/fxa-auth-server/lib/routes/mfa.ts, packages/fxa-auth-server/config/index.ts
  • Suggested review order:
  • Risky or complex parts: a deployment that sets MFA__ACTIONS still overrides the new default.

Screenshots (Optional)

Other information (Optional)

  • OTP request and verify with real actions stay covered. See lib/routes/mfa.spec.ts and the functional specs passkeyWrapApi.spec.ts and changePasswordAfterPrimaryEmailSwap.spec.ts.
  • The deleted spec also checked that a wrong scope gets a 403. That tested the built-in hapi scope check, not FxA code, so I did not add a replacement.
  • Local results: Jest for config/index.spec.ts, lib/routes/mfa.spec.ts, lib/routes/auth-schemes/mfa.spec.ts and lib/routes/passkeys.spec.ts: 173 passed, 0 failed. nx lint passes for the three changed packages.
  • I did not run the functional tests locally. CI runs them.
  • Follow-up: fxa-settings still lists a test MFA scope in src/lib/types.ts, which the MfaGuard stories and tests use.

## Because

- The `/mfa/test` and `/mfa/test2` routes were scaffolding from when we built the MFA auth strategy. They have no remaining callers.
- The `test` MFA action existed only for those routes.

## This pull request

- Removes `GET /mfa/test`, `POST /mfa/test` and `POST /mfa/test2` from `lib/routes/mfa.ts` in `fxa-auth-server`.
- Removes `test` from the default `mfa.actions` in the auth-server config.
- Removes `mfaTestGet`, `mfaTestPost` and `mfaTestPost2` from `fxa-auth-client`. This is a breaking change for those three methods only.
- Removes the `test` action from the config override in `mfa_totp.in.spec.ts`.
- Deletes `functional-tests/tests/misc/mfa.spec.ts`, which only drove the removed routes.

## Issue that this pull request solves

Closes: https://mozilla-hub.atlassian.net/browse/FXA-14622
Copilot AI lite review requested due to automatic review settings September 25, 2026 18:34
@vbudhram
vbudhram requested a review from a team as a code owner September 25, 2026 18:34
@vbudhram vbudhram added the auto label Sep 25, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

No unresolved blocking issues were identified.

Review effort: Lite
Findings: None

What changed in this PR

Removes obsolete MFA scaffolding routes, configuration, client methods, and functional tests.

Changes:

  • Deletes /mfa/test and /mfa/test2.
  • Removes the test MFA action and client methods.
  • Deletes obsolete functional-test coverage.
File Description
packages/​fxa-auth-server/​test/​remote/​mfa_totp.in.spec.ts Updates MFA configuration
packages/​fxa-auth-server/​lib/​routes/​mfa.ts Removes scaffolding routes
packages/​fxa-auth-server/​config/​index.ts Removes the default test action
packages/​fxa-auth-client/​lib/​client.ts Removes obsolete client methods
packages/​functional-tests/​tests/​misc/​mfa.spec.ts Deletes obsolete route tests

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@clouserw
clouserw merged commit 42e0d84 into main Sep 25, 2026
22 checks passed
@clouserw
clouserw deleted the fxa-14622 branch September 25, 2026 21:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants