S-15c · Enforce MFA on the medewerker (Keycloak) realm (#158)
Closes #132.
Staff logins (behandel + beheer portals) now need a second factor; the citizen realms are unchanged.
**How:** every seeded medewerker carries a TOTP credential, which activates Keycloak's stock *conditional OTP* step in both the browser flow and the direct grant — no custom browser-flow JSON in the export. `CONFIGURE_TOTP` is a default required action so a medewerker added later must enrol first. ADR-0031 records the choice and, explicitly, that the shared fixture secret is a demo posture only.
**Tests (red first, 30c5279):**
- `check_realms.py` asserts the medewerker password-only grant is **refused**, then that password + TOTP succeeds and still carries the `behandelaar` role. It failed with `[MFA NOT ENFORCED]` against the old export.
- The three medewerker e2e logins move to `loginMedewerker()` (`tests/e2e/medewerker-login.ts`), which submits Keycloak's OTP prompt. Both TOTP implementations (Python `hmac`, Node `crypto`) are ~6 lines of RFC 6238 — no new dependency.
Verified locally against Keycloak 26.1: password-only → `invalid_grant`, password + code → 200, and the browser flow's `#otp` prompt accepts a computed code and issues an auth code.
## Definition of Done
- [x] Failing test/verify committed first; implementation makes it pass.
- [x] Conventional Commits referencing the issue (`refs #132`).
- [ ] CI green (verify-stack compose smoke + relevant checks).
- [x] `docker compose up` reaches green health within 3 minutes (Keycloak change is import-time only).
- [x] Docs touched (runbook, synthetic-data, demo-script) + ADR-0031 + demo note.
- [x] Closed by the merging PR (`closes #132`).
🤖 Generated with [Claude Code](https://claude.com/claude-code)Reviewed-on: #158
This commit was merged in pull request #158.
This commit is contained in:
+36
-4
@@ -140,7 +140,8 @@ zaaktype cache). Store is in-memory: an edit reverts to the configured env on re
|
||||
|
||||
```bash
|
||||
make up
|
||||
# 1. Log in as bram-beheerder / test123 → "Default-fill" tab → change a value → Opslaan.
|
||||
# 1. Log in as bram-beheerder / test123 + OTP (`python3 infra/keycloak/check_realms.py otp`)
|
||||
# → "Default-fill" tab → change a value → Opslaan.
|
||||
open http://localhost:8143/default-fill
|
||||
#
|
||||
# 2. Automated: the ACL uses the current default-fill per zaak (unit) and the endpoints are behind the
|
||||
@@ -161,7 +162,8 @@ directly (ADR-0025); managing the default-fill config (S-15b) and MFA (S-15c) co
|
||||
|
||||
```bash
|
||||
make up
|
||||
# 1. Log in as bram-beheerder / test123 → the catalogus lists the published zaaktypen.
|
||||
# 1. Log in as bram-beheerder / test123 + OTP (`python3 infra/keycloak/check_realms.py otp`)
|
||||
# → the catalogus lists the published zaaktypen.
|
||||
open http://localhost:8143
|
||||
#
|
||||
# 2. Automated (a CI verify-stack e2e): a beheerder logs in and sees BIG-REGISTRATIE.
|
||||
@@ -304,7 +306,8 @@ make verify-local # → "OK — a fresh local stack completed the flow with
|
||||
|
||||
# 3. Or by hand in the browser: log in at http://localhost:8140 (jan-burger / test123), submit +
|
||||
# upload a PDF, then approve it in the werkbak at http://localhost:8142 (merel-behandelaar /
|
||||
# test123); it shows as INGESCHREVEN in the openbaar register at http://localhost:8141.
|
||||
# test123 + OTP, see S-15c); it shows as INGESCHREVEN in the openbaar register at
|
||||
# http://localhost:8141.
|
||||
```
|
||||
|
||||
> The zaaktype is discovered by the ACL itself since S-27 (below); `local-seed`'s `acl.env` now
|
||||
@@ -589,7 +592,7 @@ or **afwijzen** — which also completes the Beoordelen task so the process adva
|
||||
|
||||
```text
|
||||
# 1. Open the behandel portal and log in as a behandelaar (medewerker realm):
|
||||
# http://localhost:8142/ → merel-behandelaar / test123
|
||||
# http://localhost:8142/ → merel-behandelaar / test123 + OTP
|
||||
#
|
||||
# 2. The werkbak lists the registrations awaiting beoordeling (referentie / bsn / status).
|
||||
# Find the reference from the submit confirmation and click "Goedkeuren" on that row.
|
||||
@@ -812,3 +815,32 @@ make verify-domain # → "the timed-out registration's zaak was cancelled to
|
||||
`POST /annuleringen` → ZGW `resultaten` + `statussen` (Geannuleerd); the aggregate then moves to
|
||||
`Verlopen`. The ACL cancels the zaak **before** the aggregate is expired, so a failed ZGW call leaves the
|
||||
job for redelivery rather than diverging the two (ADR-0019).
|
||||
|
||||
---
|
||||
|
||||
## S-15c — MFA on the medewerker realm (#132, ADR-0031)
|
||||
|
||||
**Outcome:** staff logins (behandel + beheer portals) need a **second factor**. The medewerker realm
|
||||
seeds every medewerker with a TOTP credential, so Keycloak's conditional-OTP step challenges them in
|
||||
both the browser flow and the direct grant; a password alone no longer yields a token. `CONFIGURE_TOTP`
|
||||
is a default required action, so a medewerker added later must enrol first. Citizen realms (digid,
|
||||
eherkenning, eidas) are unchanged — they mock brokers that carry their own assurance.
|
||||
|
||||
```bash
|
||||
# 1. Manual: log in to the behandel portal. After username + password Keycloak asks for a code.
|
||||
python3 infra/keycloak/check_realms.py otp # a valid code, right now
|
||||
open http://localhost:8142 # merel-behandelaar / test123 + that code
|
||||
#
|
||||
# 2. Automated: the realm smoke check asserts the password alone is REFUSED, then that
|
||||
# password + TOTP succeeds and still carries the behandelaar role:
|
||||
make keycloak-smoke # → "medewerker merel-behandelaar password-only login refused [OK]"
|
||||
#
|
||||
# 3. End-to-end: every staff login in the e2e goes through the OTP prompt (loginMedewerker):
|
||||
make verify-e2e # → registration.spec (behandelaar approves), catalogus.spec, default-fill.spec
|
||||
```
|
||||
|
||||
**The path:** the seeded `otp` credential in `infra/keycloak/realms/medewerker-realm.json` activates
|
||||
Keycloak's stock conditional-OTP subflow — no custom browser flow. The fixture secret is shared and
|
||||
committed on purpose so the checks can compute codes; a real deployment enrols per-user authenticators
|
||||
(ADR-0031).
|
||||
|
||||
|
||||
Reference in New Issue
Block a user