-
-
Notifications
You must be signed in to change notification settings - Fork 1
All issues
Issue creation is restricted in this repository
Issues
is:issue state:open
is:issue state:open
Search results
Test suite is intermittently flaky, including in the sequential coverage run
bugSomething isn't workingSomething isn't workingStatus: Open.#190 In fells-code/seamless-auth-api;Refresh rotation resets the absolute session lifetime, so there is no absolute cap
enhancementNew feature or requestNew feature or requestsecuritySecurity-sensitive: auth, tokens, OTP, sessions, cryptoSecurity-sensitive: auth, tokens, OTP, sessions, cryptoStatus: Open.#185 In fells-code/seamless-auth-api;React SDK cannot request a security key at enrollment
enhancementNew feature or requestNew feature or requestStatus: Open.#183 In fells-code/seamless-auth-api;No authentication coverage report for assessment and insurance responses
enhancementNew feature or requestNew feature or requestStatus: Open.#178 In fells-code/seamless-auth-api;No enforceable phishing-resistant-only login mode, and magic link is on by default
enhancementNew feature or requestNew feature or requestsecuritySecurity-sensitive: auth, tokens, OTP, sessions, cryptoSecurity-sensitive: auth, tokens, OTP, sessions, cryptoStatus: Open.#177 In fells-code/seamless-auth-api;No concurrent session limit per user
enhancementNew feature or requestNew feature or requestsecuritySecurity-sensitive: auth, tokens, OTP, sessions, cryptoSecurity-sensitive: auth, tokens, OTP, sessions, cryptoStatus: Open.#176 In fells-code/seamless-auth-api;Production JWKS key rotation is not implemented
enhancementNew feature or requestNew feature or requestsecuritySecurity-sensitive: auth, tokens, OTP, sessions, cryptoSecurity-sensitive: auth, tokens, OTP, sessions, cryptoStatus: Open.#175 In fells-code/seamless-auth-api;Audit records are updatable and have no integrity protection
enhancementNew feature or requestNew feature or requestsecuritySecurity-sensitive: auth, tokens, OTP, sessions, cryptoSecurity-sensitive: auth, tokens, OTP, sessions, cryptoStatus: Open.#174 In fells-code/seamless-auth-api;Audit events have no retention policy and no bulk export
enhancementNew feature or requestNew feature or requestsecuritySecurity-sensitive: auth, tokens, OTP, sessions, cryptoSecurity-sensitive: auth, tokens, OTP, sessions, cryptoStatus: Open.#173 In fells-code/seamless-auth-api;Run FIDO2 conformance self-validation and remediate findings
enhancementNew feature or requestNew feature or requestStatus: Open.#172 In fells-code/seamless-auth-api;Add the FIDO2 conformance test interface behind an environment flag
enhancementNew feature or requestNew feature or requestStatus: Open.#171 In fells-code/seamless-auth-api;No authenticator policy: synced passkeys cannot be blocked and AAGUIDs cannot be restricted
enhancementNew feature or requestNew feature or requestsecuritySecurity-sensitive: auth, tokens, OTP, sessions, cryptoSecurity-sensitive: auth, tokens, OTP, sessions, cryptoStatus: Open.#170 In fells-code/seamless-auth-api;