Spring / Spring7 Intermediate to Advanced Interview questions
How does multi-factor authentication (MFA) work natively in Spring Security 7?
Spring Security 7 models each completed authentication factor as an authority granted to the Authentication object, and provides authorization managers that check for a required combination of those factor authorities before granting access.
http.authorizeHttpRequests(auth -> auth .requestMatchers("/admin/**").hasAuthority("ROLE_ADMIN") .anyRequest().access(new AllAuthoritiesAuthorizationManager("MFA_SMS", "MFA_TOTP")) );
AllAuthoritiesAuthorizationManager requires every listed factor authority to be present, which is the typical "must complete SMS and TOTP" case; Spring Security 7.1 adds AllRequiredFactorsAuthorizationManager.anyOf() for the more flexible "any one of these factor combinations is acceptable" case. A new Authentication.Builder lets the application add factor details to an existing Authentication after a successful secondary challenge, without rebuilding the token from scratch and losing prior state. The framework's default login page also understands factor.type and factor.reason query parameters, so it can render the correct next-step challenge screen automatically once the first factor succeeds.
More Related questions...