stepUpRequired static method

Response stepUpRequired(
  1. DVMfa policy
)

The refusal for a session whose second factor is missing or older than policy allows (DV-SESSION-001): RFC 9470's insufficient_user_authentication, with max_age when the policy has a window, so a client asks for a code rather than for a sign-in.

Implementation

static Response stepUpRequired(DVMfa policy) {
  final Duration? within = policy.within;
  DVObservability.logger
      .info('DV-SESSION-001: a second factor is required and was not recent.');
  return _json(
    401,
    <String, Object?>{
      'error': 'mfa_required',
      'code': 'DV-SESSION-001',
      'message': 'A second factor is required.',
      if (within != null) 'maxAge': within.inSeconds,
    },
    headers: <String, String>{
      'www-authenticate': within == null
          ? DVSessionAuthentication.mfaChallenge
          : '${DVSessionAuthentication.mfaChallenge}, '
              'max_age=${within.inSeconds}',
    },
  );
}