2FA login flow for users who aren't registered with a given client / application
-
I have an authentication flow for a specific client where some users have 2FA enabled. This involves a call to the
loginAPI, which I understand from the documentation will return:200if the auth is successful.202if the auth is successful BUT the user is not registered with the client.242if the auth was successful BUT the user has 2FA enabled.
Our application uses refresh tokens (which are only provided if the user is registered with the client). This means if we get a
202we automatically register the user with the application and re-try login.My question: What happens if the user is BOTH unregistered AND has 2FA? I believe in that case
242is returned by/login, which then signals the need for a 2FA flow. However, I can't find the documentation fortwoFactorLoginto know if202as a possible response from the/api/two-factor/loginendpoint. -
@slifty Let's start with what your desired workflow is and go from there. How would you like the login to work?