Skip to content

Expose organization authentication requirements in OAuth flows - #222

Merged
ericmj merged 2 commits into
mainfrom
organization-tfa-enforcement
Sep 15, 2026
Merged

ericmj merged 2 commits into
mainfrom
organization-tfa-enforcement

Conversation

@ericmj

@ericmj ericmj commented Sep 9, 2026

Copy link
Copy Markdown
Member

OAuth grants now preserve the missing authentication requirements for each organization, including independent SSO and 2FA reasons. Add the shared organization authorization endpoint and pass structured requirements through CLI authentication callbacks so clients can request the required browser verification.

Malformed requirement entries retain the previous authentication state instead of clearing it. Validated with 165 Common Test cases, both properties with 100 generated cases each, and the formatter.

Related: hexpm/hexpm#1913, hexpm/hex#1237.

@ericmj
ericmj merged commit 7710855 into main Sep 15, 2026
10 checks passed
@ericmj
ericmj deleted the organization-tfa-enforcement branch September 15, 2026 13:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant