Skip to content

2FA challenge after 2FA setup during login is problematic #15744

@ChristophWurst

Description

@ChristophWurst

Steps to take

  • Admin enforces 2FA
  • Admin enables Two-Factor TOTP
  • User logs in
  • User sets up TOTP
  • User is redirected to TOTP challenge

If the user is quick, their TOTP app will show them the very same code as during the setup. TOTP does, however, detect code reuse and therefore will fail.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions