From 4c58aa2ccf5b264bd7d71225304aa0f21313f833 Mon Sep 17 00:00:00 2001 From: Jason Ertel Date: Fri, 28 Apr 2023 13:14:30 -0400 Subject: [PATCH] Add privileged session config option to kratos config UI --- salt/kratos/defaults.yaml | 2 ++ salt/kratos/soc_kratos.yaml | 6 +++++- 2 files changed, 7 insertions(+), 1 deletion(-) diff --git a/salt/kratos/defaults.yaml b/salt/kratos/defaults.yaml index bcb166772..b1572a5ff 100644 --- a/salt/kratos/defaults.yaml +++ b/salt/kratos/defaults.yaml @@ -5,6 +5,8 @@ kratos: whoami: required_aal: highest_available selfservice: + settings: + privileged_session_max_age: 5m methods: password: enabled: true diff --git a/salt/kratos/soc_kratos.yaml b/salt/kratos/soc_kratos.yaml index e3b88e28f..4fefa0583 100644 --- a/salt/kratos/soc_kratos.yaml +++ b/salt/kratos/soc_kratos.yaml @@ -12,6 +12,11 @@ kratos: advanced: True helpLink: kratos.html selfservice: + settings: + privileged_session_max_age: + description: The length of time after a successful authentication for a user's session to be elevated to a privileged session. Privileged sessions are able to change passwords and MFA settings for that user. If a session is no longer privileged then the user is sent to the login form first, before the security settings can be adjusted. + global: True + helpLink: kratos.html methods: password: enabled: @@ -23,7 +28,6 @@ kratos: haveibeenpwned_enabled: description: Set to True to check if a newly chosen password has ever been found in a published list of previously-compromised passwords. Requires outbound Internet connectivity when enabled. global: True - advanced: True helpLink: kratos.html totp: enabled: