General WebAuth Tests

  1. basic WebAuth test
  2. test extra redirect
  3. test environment variable prefix
  4. test cancel login
  5. test return url
  6. test query params on initial redirect
  7. test 5 second app-token lifetime
  8. test 5 second app-token lifetime and force login
  9. test last-used update
  10. test inactive-expire
  11. test for no query params on initial redirect
  12. test POST with expired cookie
  13. test PHP (only works if PHP installed)

Multifactor Tests

  1. any multifactor required
  2. OTP multifactor required
  3. OTP multifactor plus password required
  4. random multifactor required
  5. o3 multifactor method required
  6. LoA required at a level any user should meet
  7. LoA required at a level any OTP user should meet
  8. LoA required at a level any strong OTP user should meet
  9. LoA required at a level no user should meet (access denied)
  10. LoA required at a level any OTP users should meet plus o3 multifactor required plus force login for multifactor
  11. force session with password
  12. force session with multifactor
  13. force session with negotiate-auth
  14. force session with random multifactor