Skip to content

2FA code is not verified until after confirming backup codes #1466

@Tisawesomeness

Description

@Tisawesomeness

Observed/problematic behavior

See steps to reproduce

Expected behavior

No "Invalid TOTP code" message

Steps to reproduce

  1. Start linking 2FA by scanning the QR code and setting up your 2FA authenticator
  2. Enter the 2FA code and click "Verify TOTP code and activate"
  3. Wait 2-3 minutes (may be shorter, at least a short enough time that creating an entry in a password manager causes the 2FA code to expire)
  4. Paste one of the backup codes and click "Confirm"
  5. Observe the "Invalid TOTP code" message:

Image

You can also enter a nonsense TOTP code such as AAAAAA, and it will not be checked until you paste one of the backup codes and click "Confirm".

Other

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    Status

    New

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions