Çok Faktörlü Kimlik Doğrulama (MFA)
MFA'nın kullanıcı kimlik doğrulamasına ek bir güvenlik katmanı kazandırmak üzere OIDC akışlarıyla nasıl bütünleştiğini keşfedin.
Çok Faktörlü Kimlik Doğrulama (MFA), CoddyKit'te ücretsiz bir OAuth2 & OpenID Connect Deep Dive dersidir. Bu, 4 dersinin 3. dersidir. Aşağıdan dersin tamamını ücretsiz okuyabilir, sonra tarayıcıda yerleşik kod editörü ve 7/24 yapay zeka koçu ile uygulamalı olarak pratik yapabilirsin. Bu, OAuth2 & OpenID Connect Deep Dive öğrenme yolunun bir parçasıdır ve ilerlemeniz web ve CoddyKit uygulaması arasında senkronize olur. OAuth2 & OpenID Connect Deep Dive kursu toplamda 4 dersten oluşur.
Bu dersin bazı bölümleri henüz çevrilmemiş olup İngilizce olarak gösterilmektedir.
What is Multi-Factor Authentication?
Multi-Factor Authentication (MFA) adds an extra layer of security to user accounts beyond just a password.
Instead of relying on a single piece of evidence (like "something you know"), MFA requires two or more verification methods from different categories.
The "Factors" of MFA
MFA typically combines factors from these categories:
- Something you know: A password or PIN.
- Something you have: A phone, hardware token, or authenticator app.
- Something you are: A fingerprint, face scan, or voice recognition.
Using multiple factors makes it much harder for unauthorized users to gain access.
Why MFA in OIDC?
OpenID Connect (OIDC) itself doesn't perform MFA. Instead, it acts as a secure way for an Identity Provider (IdP) to tell your application whether a user authenticated with MFA.
Your application can then use this information to make informed authorization decisions.
Introducing ACR Values
In OIDC, "Authentication Context Class References" (ACR values) are used to specify how a user was authenticated.
These are unique identifiers that represent different levels or methods of authentication, including whether MFA was used.
Requesting a Specific ACR Level
When your application initiates an OIDC authorization request, it can include the acr_values parameter.
This parameter tells the Identity Provider that your application prefers or requires a specific authentication context, such as MFA.
Example: Requesting MFA
Here's a simplified example of an OIDC authorization URL requesting an MFA context. The specific acr_values like "mfa" or "https://acr.example.com/mfa" depend on the Identity Provider's configuration.
public class Main {
public static void main(String[] args) {
String authUrl = "https://idp.example.com/authorize?"
+ "response_type=code"
+ "&client_id=my_client_app"
+ "&redirect_uri=https://app.example.com/callback"
+ "&scope=openid%20profile"
+ "&acr_values=mfa";
System.out.println("Authorization URL:\n" + authUrl);
}
}Receiving MFA Status in the ID Token
After successful authentication, the Identity Provider returns an ID Token to your application. This token contains various claims about the user and their authentication session.
The acr claim within the ID Token indicates the actual authentication context class reference that was satisfied.
Example: Decoding an ID Token with 'acr'
Let's imagine an ID Token payload after a user authenticated with MFA. The acr claim would be present, confirming the authentication method used.
In a real application, you would decode and validate the JWT to read this claim.
public class Main {
public static void main(String[] args) {
// Example of a decoded ID Token payload
// In a real app, you'd parse a JWT.
String idTokenPayload = "{\n \"iss\": \"https://idp.example.com\",\n \"sub\": \"user123\",\n \"aud\": \"my_client_app\",\n \"exp\": 1678886400,\n \"iat\": 1678882800,\n \"auth_time\": 1678882700,\n \"acr\": \"mfa\",\n \"amr\": [\"pwd\", \"otp\"]\n}";
System.out.println("Simulated ID Token Payload:\n" + idTokenPayload);
}
}Enforcing MFA-Based Policies
Once your application receives and validates the ID Token, it can check the acr claim.
Based on this, you can implement conditional access policies. For example, if a user tries to access sensitive data, and the acr claim doesn't indicate MFA, you might deny access or prompt for re-authentication.
Quick Check
Which OIDC parameter is used by a client application to request that a user authenticates with Multi-Factor Authentication?
Recap: MFA & OIDC
We've learned that MFA adds critical security layers by requiring multiple authentication factors.
OIDC doesn't perform MFA itself, but it provides a standardized way (via acr_values in requests and the acr claim in ID Tokens) for applications to request and receive information about the authentication context, enabling robust, MFA-aware security policies.
Sıkça Sorulan Sorular
“Çok Faktörlü Kimlik Doğrulama (MFA)” dersi ücretsiz mi?
Evet — “Çok Faktörlü Kimlik Doğrulama (MFA)” dersin tüm metni burada web'de ücretsiz olarak okunabilir. Etkileşimli olarak pratik yapmak (yerleşik kod editörü ve 7/24 yapay zeka koçu) ve OAuth2 & OpenID Connect Deep Dive kursunun geri kalanını açmak için CoddyKit PRO'ya yükselt. OAuth2 & OpenID Connect Deep Dive kursu toplamda 4 dersten oluşur.
“Çok Faktörlü Kimlik Doğrulama (MFA)” dersinde ne öğreneceğim?
MFA'nın kullanıcı kimlik doğrulamasına ek bir güvenlik katmanı kazandırmak üzere OIDC akışlarıyla nasıl bütünleştiğini keşfedin. OAuth2 & OpenID Connect Deep Dive ile uygulamalı kodu tarayıcıda doğrudan çalıştırarak pratik yaparsın ve 7/24 yapay zeka koçu dersi çalışırken sorularını yanıtlar.
OAuth2 & OpenID Connect Deep Dive öğrenmeye başlamak için deneyim gerekli mi?
Önceden deneyim gerekmez. CoddyKit'te OAuth2 & OpenID Connect Deep Dive, başlangıçtan ileri seviyeye kadar yapılandırıldığı için buradan başlayabilir veya başından başlayıp kendi hızında ilerleme yapabilirsin. Bu, 4 dersinin 3. dersidir.
“Çok Faktörlü Kimlik Doğrulama (MFA)” dersi ne kadar sürer?
Çoğu CoddyKit dersi yaklaşık 5–10 dakika sürer. Her biri kısa ve etkileşimli olduğu için sabit ilerleme yaparsın ve web ile uygulama arasında tam olarak bıraktığın yerden devam edebilirsin.
Bu OAuth2 & OpenID Connect Deep Dive dersinde kod yazıp çalıştırabilir miyim?
Evet. Her OAuth2 & OpenID Connect Deep Dive dersi yerleşik bir kod editörü içerir, bu sayede tarayıcıda gerçek kod yazıp çalıştırabilir ve anlık yapay zeka geri bildirimi alırsın — yerel kurulum gerekli değildir.
Bu kursun tüm dersleri
- Kimlik Sağlayıcılarla Entegrasyon
- Mikro Hizmetler ve API Gateway Güvenliği
- Çok Faktörlü Kimlik Doğrulama (MFA)
- Uygulamalar Arasında Tek Oturum Açma