Skip to content

Version 10.0.0 beta05 - #2459

Open
russellwheatley wants to merge 14 commits into
masterfrom
version-10.0.0-beta05
Open

Version 10.0.0 beta05#2459
russellwheatley wants to merge 14 commits into
masterfrom
version-10.0.0-beta05

Conversation

@russellwheatley

@russellwheatley russellwheatley commented Aug 28, 2026

Copy link
Copy Markdown
Member

⚠️ Breaking Changes

Changes

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request removes the recovery codes feature from the Multi-Factor Authentication (MFA) enrollment flow, including the ShowRecoveryCodes step, configuration options, state properties, UI components, localized string resources, and associated tests. I have no feedback to provide.

@demolaf demolaf changed the title fix(auth)!: remove non-functional MFA recovery codes (#2457) Version 10.0.0 beta05 Aug 28, 2026
demolaf and others added 9 commits September 1, 2026 17:17
…tion that owns it (#2454)

* refactor(auth): let the phone screen own its verification loading state

* fix(auth): read auth state per authUI instance when clearing loading on dispose
…eption fallback exhausts

(cherry picked from commit 6fa4f00)
(cherry picked from commit aca99e7)
(cherry picked from commit 8784b13ce29739ed7785aab9ab6fe4faad2a2981)
…data

(cherry picked from commit 8eca4fa)
(cherry picked from commit ac61312)
(cherry picked from commit 126ba985660ff272dbfda427b644ad4fb1ca6197)
…loop

(cherry picked from commit a87cfe3)
(cherry picked from commit 3f4ae70)
(cherry picked from commit 1f1ada380039ed5e7476dfc2e38a683e6edb4549)
…lot (#2452)

* feat(auth): reshape reauthContent into a ReauthContentState content slot

* fix(auth): address reauth review findings and retain state across recreation

* refactor(auth): make reauthentication a request-scoped state machine

* fix(auth): keep a proved reauthentication alive when its operation signs out

* fix(auth): tear down phone verification when a reauthentication attempt fails

* test(auth): cover sign-out-during-retry and phone reauth failure end to end

* test(auth): drop the flaky phone reauth e2e case
@demolaf
demolaf force-pushed the version-10.0.0-beta05 branch from 444543d to 059bba8 Compare September 1, 2026 16:17
@demolaf
demolaf marked this pull request as ready for review September 1, 2026 16:22
…lment (#2462)

* test(auth): pin onComplete and factor refresh on successful MFA enrollment

* test(auth): pin the SMS MFA enrollment route through send, verify and resend

* test(auth): pin the missing TOTP secret guard and the resend's clean enroll
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants