3 ms·
I asked this elsewhere in the thread to a different user, but it seems relevant here as well: Curious how your service would handle a app that mandates non-ema
by ss3000 6y ago
I asked this elsewhere in the thread to a different user, but it seems relevant here as well:
Curious how your service would handle a app that mandates non-email based MFA like SMS or TOTP.
Additionally, what about testing a onboarding flow that might require some form of manual approval?
Thanks!
- tmcneal 6y agoWe have the ability to handle MFA logins that use email as the second factor. The way it works is you configure your user account to have an email address that we control (e.g. foo@account-randomchars.email.reflect.run). When the multi-factor challenge comes in, we receive the email, parse it for the challenge code, and fill it in live in your test. We don't have SMS support at the moment but we could take a similar approach there if SMS is used as a second factor. There's a one-time setup here where we set up our system to parse your challenge email. No support for TOTP unfortunately, but if the SMS or email-based challenge support would work for you feel free to reach out and I can talk to the specifics of the one-time setup - todd at reflect dot run