Two Factor Authentication - TFA / Passwordless Login
It adds an extra layer of verification for the user login process.
A visitor could see the secret customer key used for the background login service. They could read this hidden text. They could not alter the website or add new information.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youA site is affected if the headless verification setting is turned on by a user with a restricted access right.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Two Factor Authentication - TFA / Passwordless Login to 5.4.1 or 5.5.2, whichever branch you are on.
For developers: what the fix changed
The fix implements the moHeadlessApiKeyIsValid and moHeadlessRejectApiKey methods in miniorange_2faController.php to perform a constant time API key comparison without returning the key in the response. It also introduces a dedicated backdoor token generated by hooks in miniorange_2fa.install to further separate secrets.
Also in this release The release also updates module version metadata and restricts the headless routes to accept only post requests.
config/schema/miniorange_2fa.schema.yml+4 −1 fixminiorange_2fa.info.yml+7 −2miniorange_2fa.install+22 −1 fixminiorange_2fa.routing.yml+10 −2 fixmodules/miniorange_webauthn/miniorange_webauthn.info.yml+6 −1src/Controller/miniorange_2faController.php+139 −44 fixsrc/Form/MoAuthHeadlessSetup.php+3 −3src/Form/MoAuthLoginSettings.php+6 −2src/MoAuthUtilities.php+44 −3