diff --git a/packages/functional-tests/tests/misc/mfa.spec.ts b/packages/functional-tests/tests/misc/mfa.spec.ts deleted file mode 100644 index a9306294089..00000000000 --- a/packages/functional-tests/tests/misc/mfa.spec.ts +++ /dev/null @@ -1,62 +0,0 @@ -/* This Source Code Form is subject to the terms of the Mozilla Public - * License, v. 2.0. If a copy of the MPL was not distributed with this - * file, You can obtain one at http://mozilla.org/MPL/2.0/. */ - -import { expect, test } from '../../lib/fixtures/standard'; - -/** - * These tests are end to end tests to validate that mfa endpoints are really - * functioning as intended. They exercise the sending, receiving, and validation - * of an otp code. Upon verification of the otp code, a jwt access token will - * be returned. The tests then validate that the jwt token can be used for the - * 'mfa' auth strategy that we added to work in conjunction with the issued - * access token. - */ -test.describe('severity-2 #smoke', () => { - test(`get otp code for mfa, and exchange it for valid jwt`, async ({ - target, - testAccountTracker, - }) => { - const credentials = await testAccountTracker.signUpSync(); - const client = target.createAuthClient(2); - const resp1 = await client.mfaRequestOtp(credentials.sessionToken, 'test'); - expect(resp1.status).toBe('success'); - - // Verify the otp code - const code = await target.emailClient.getVerifyAccountChangeCode( - credentials.email - ); - - // Try accessing the protected action test endpoint with jwt - const resp2 = await client.mfaOtpVerify( - credentials.sessionToken, - code, - 'test' - ); - expect(resp2.accessToken).toBeDefined(); - const jwtAccessToken = resp2.accessToken; - - // Try accessing the protected action again - const resp3 = await client.mfaTestGet(jwtAccessToken); - expect(resp3.status).toBe('success'); - - const resp4 = await client.mfaTestPost(jwtAccessToken, { message: 'foo' }); - expect(resp4.status).toBe('success'); - expect(resp4.uid).toBe(credentials.uid); - expect(resp4.echo).toBe('foo'); - - let scopeError = undefined; - try { - await client.mfaTestPost2(jwtAccessToken); - } catch (err) { - scopeError = err; - } - expect(scopeError?.code).toBe(403); - expect(scopeError?.errno).toBe(999); - expect(scopeError?.error).toBe('Forbidden'); - expect(scopeError?.message).toBe('Insufficient scope'); - expect(scopeError?.data).toBe( - '{"got":["mfa:test"],"need":[{"selection":["mfa:test2"]}]}' - ); - }); -}); diff --git a/packages/fxa-auth-client/lib/client.ts b/packages/fxa-auth-client/lib/client.ts index 5198e04ca1d..14eaed6ceaf 100644 --- a/packages/fxa-auth-client/lib/client.ts +++ b/packages/fxa-auth-client/lib/client.ts @@ -2324,25 +2324,6 @@ export default class AuthClient { ); } - async mfaTestGet( - jwt: string, - headers?: Headers - ): Promise<{ status: string }> { - return this.jwtGet('/mfa/test', jwt, headers); - } - - async mfaTestPost( - jwt: string, - payload: { message: string }, - headers?: Headers - ) { - return this.jwtPost('/mfa/test', jwt, payload, headers); - } - - async mfaTestPost2(jwt: string, headers?: Headers) { - return this.jwtPost('/mfa/test2', jwt, {}, headers); - } - async deviceList(sessionToken: hexstring, headers?: Headers) { return this.sessionGet('/account/devices', sessionToken, headers); } diff --git a/packages/fxa-auth-server/config/index.ts b/packages/fxa-auth-server/config/index.ts index 6e698fe7df7..d7d7caa25c4 100644 --- a/packages/fxa-auth-server/config/index.ts +++ b/packages/fxa-auth-server/config/index.ts @@ -2979,7 +2979,7 @@ const convictConf = convict({ env: 'MFA__ENABLED', }, actions: { - default: ['test', '2fa', 'email', 'recovery_key', 'password', 'passkey'], + default: ['2fa', 'email', 'recovery_key', 'password', 'passkey'], doc: 'Actions protected by MFA', format: Array, env: 'MFA__ACTIONS', diff --git a/packages/fxa-auth-server/lib/routes/mfa.ts b/packages/fxa-auth-server/lib/routes/mfa.ts index a0c444f24ab..110aedc3632 100644 --- a/packages/fxa-auth-server/lib/routes/mfa.ts +++ b/packages/fxa-auth-server/lib/routes/mfa.ts @@ -304,62 +304,6 @@ export const mfaRoutes = ( return otpHandler.verifyOtpCode(request); }, }, - { - method: 'GET', - path: '/mfa/test', - options: { - auth: { - strategy: 'mfa', - scope: ['mfa:test'], - payload: false, - }, - }, - handler: function (request: AuthRequest) { - log.begin('mfa.test', request); - return { status: 'success' }; - }, - }, - { - method: 'POST', - path: '/mfa/test', - options: { - auth: { - strategy: 'mfa', - scope: ['mfa:test'], - payload: false, - }, - validate: { - payload: isA.object({ - message: isA.string(), - }), - }, - }, - handler: function (request: AuthRequest) { - log.begin('mfa.test', request); - const { message } = request.payload as unknown as { message: string }; - const { uid } = request.auth.credentials; - return { - status: 'success', - uid, - echo: message, - }; - }, - }, - { - method: 'POST', - path: '/mfa/test2', - options: { - auth: { - strategy: 'mfa', - scope: ['mfa:test2'], - payload: false, - }, - }, - handler: function (request: AuthRequest) { - log.begin('mfa.test2', request); - return { status: 'success' }; - }, - }, ]; return routes; diff --git a/packages/fxa-auth-server/test/remote/mfa_totp.in.spec.ts b/packages/fxa-auth-server/test/remote/mfa_totp.in.spec.ts index 1c0b9b97058..31b4a332809 100644 --- a/packages/fxa-auth-server/test/remote/mfa_totp.in.spec.ts +++ b/packages/fxa-auth-server/test/remote/mfa_totp.in.spec.ts @@ -34,7 +34,7 @@ beforeAll(async () => { signinConfirmation: { skipForNewAccounts: { enabled: false } }, mfa: { enabled: true, - actions: ['2fa', 'test'], + actions: ['2fa'], }, }, });