Variable refuseUnmetStepUp
refuseUnmetStepUp: (
req: any,
grant: any,
session: any,
missing: any,
) => Promise<
| {
none: boolean;
pushed?: undefined;
redirect?: undefined;
why?: undefined;
}
| {
none?: undefined;
pushed?: undefined;
redirect: string;
why?: undefined;
}
| { none?: undefined; pushed: boolean; redirect?: undefined; why: string },
> = ...
The approval page asked the person to sign in again for the authentication level the rights need, and the sign-in that came back still does not meet it: the request is answered
request_denied(STS-GNAP-0899), recorded as the decision, and the finish method is enacted — RFC 9470's "one sign-in, then refuse" in GNAP's vocabulary.