Skip to content

Logging in with a 2FA backup code still require a U2F tap (making them useless) #1912

@benjojo

Description

@benjojo

Describe the bug

When a user has been locked out and needs to use to use their factor backup codes, they are unable to because once they use the backup code it will still ask for their U2F key, meaning that the entire backup code is just completely useless

To Reproduce
Steps to reproduce the behavior:

recovery-broken.mp4

Expected behavior

to not be asked for my U2F key

Who is affected by the problem?

All U2F key users

What is the impact?

the lost 2FA recovery mechanism is useless

What is the proposed priority?
urgent

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions