chore(auth): remove legacy session-token TOTP setup routes - #21334
Open
fxa-agent[bot] wants to merge 1 commit into
Open
fxa-agent[bot] wants to merge 1 commit into
fxa-agent[bot] wants to merge 1 commit into
Conversation
fxa-agent
Bot
force-pushed
the
fxa-14626
branch
from
September 29, 2026 11:22
2377fd0 to
b28dc42
Compare
## Because - The `/v1/mfa/totp/*` routes replace the session-token TOTP setup routes `POST /v1/totp/create`, `/v1/totp/setup/verify` and `/v1/totp/setup/complete`. - The functional tests and the test clients were the last callers of the old routes in the monorepo. ## This pull request - Removes the three legacy routes from `totp.js` and their docs from `totp-api.ts`. The `/v1/mfa/totp/*` routes now hold the handler logic. - Updates `totp.spec.ts` to test the MFA routes. The spec also checks that the old paths are not served. - Removes `createTotpToken`, `verifyTotpSetupCode` and `completeTotpSetup` from `fxa-auth-client`, and removes the content-server wrappers for them. - Moves the auth-server test client (`test/client/api.js`, `index.js`) to the MFA routes. The client signs an `mfa:2fa` JWT locally. - Changes `enableTotpOnAccount` in `pairing-helpers.ts` to take an MFA JWT. Its callers get one from `testAccountTracker.getMfaJwtForScope('2fa', ...)`, which is now public. - Round 1: fixes a 401 (errno 223) in `passkeySetPassword.spec.ts` and `passkeyPasswordFallback.spec.ts`. These calls still passed a session token. - Round 2: no code change. It answers the CI failure on PR #21334 (56 of 89 functional tests with "Internal Server Error"). See "Other information". **Breaking change:** `POST /v1/totp/create`, `/v1/totp/setup/verify` and `/v1/totp/setup/complete` now return 404. The one known external caller is PyFxA `Session.totp_create`. mozilla/PyFxA#126 moves it to `/mfa/totp/*`. That PR must land before this one. I did not check the Firefox desktop and mobile clients. One reviewer call: merge this PR only after mozilla/PyFxA#126 lands. ## Issue that this pull request solves Closes: FXA-14626
fxa-agent
Bot
force-pushed
the
fxa-14626
branch
from
September 29, 2026 12:56
b28dc42 to
2408a15
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Because
/mfa/totp/*set requires anmfa:2faJWT.main, the/mfaroutes forward to the legacy handlers, so the legacy routes cannot go away on their own.This pull request
POST /v1/totp/create,/v1/totp/setup/verifyand/v1/totp/setup/completefromtotp.js, with their Swagger entries./mfa/totp/create,/mfa/totp/setup/verifyand/mfa/totp/setup/completeroutes.createTotpToken,verifyTotpSetupCodeandcompleteTotpSetupfromfxa-auth-client. The*WithJwtmethods stay.createTotpTokenwrapper from the content-serverfxa-client.jsandAccount, with its spec./mfaroutes with a JWT fromsignMfaToken.enableTotpOnAccountto use the*WithJwtmethods with a JWT fromtestAccountTracker.getMfaJwtForScope, which is now public. Six functional specs use it.it.eachtest intotp.spec.tsthat checks that the three legacy paths are not registered.Breaking change: external users of the three endpoints or the three removed client methods must move to
/mfa/totp/*.Issue that this pull request solves
Closes: https://mozilla-hub.atlassian.net/browse/FXA-14626
Checklist
Put an
xin the boxes that applyHow to review (Optional)
packages/fxa-auth-server/lib/routes/totp.jstotp.js,totp.spec.ts,fxa-auth-client, then the test helpers.Screenshots (Optional)
Please attach the screenshots of the changes made in case of change in user interface.
Other information (Optional)
Any other information that is important to this pull request.
One reviewer call: can this deploy before mozilla/PyFxA#126 ships? PyFxA still calls
/totp/create. The ticket says PyFxA#126 moves it to/mfa/totp/*.Tests I ran on the local stack:
curlPOST to the three legacy paths: 404 each (401 before the change). POST/v1/mfa/totp/createwithout a JWT: 401.passwordlessApi.spec.ts"TOTP account returns unverified session": passed.lib/routes/totp.spec.ts: 26 passed.mfa_totp.in.spec.tsandrecovery_phone.in.spec.ts: 16 passed.fxa-auth-clientmocha: 34 passing.tscshows only theoriginalEmailerrors intestAccountTracker.tsthat exist onmain.Not run, left to CI:
signinPasswordless,passkey-signin,cms-2faandstepUpAuth. They need the 123done relier or the CMS.pairingFlow. The sandbox blocks the channel server, and the pairing test without TOTP fails there too.Kept on purpose:
/totp/exists,/session/verify/totpanddb.createTotpToken. The MFA routes usedb.createTotpToken.Follow-ups, not in this PR:
fxa_route_catalog.pyis outside this repo and still lists the legacy routes. It needs a separate change.packages/fxa-shared/sentry/tag.tsstill lists/v1/totp/createas a critical endpoint. That file fails ESLint onmain.