stepUpRequired static method
The refusal for a session whose second factor is missing or older than
policy allows (DV-SESSION-001): RFC 9470's
insufficient_user_authentication, with max_age when the policy has a
window, so a client asks for a code rather than for a sign-in.
Implementation
static Response stepUpRequired(DVMfa policy) {
final Duration? within = policy.within;
DVObservability.logger
.info('DV-SESSION-001: a second factor is required and was not recent.');
return _json(
401,
<String, Object?>{
'error': 'mfa_required',
'code': 'DV-SESSION-001',
'message': 'A second factor is required.',
if (within != null) 'maxAge': within.inSeconds,
},
headers: <String, String>{
'www-authenticate': within == null
? DVSessionAuthentication.mfaChallenge
: '${DVSessionAuthentication.mfaChallenge}, '
'max_age=${within.inSeconds}',
},
);
}