Original page lost after TOTP authentication

Created on 21 February 2016, about 9 years ago
Updated 19 January 2025, 3 months ago

On drupal.org I've noticed an annoyance where the page I originally want to visit gets forgotten after I get redirected to enter my TOTP code.

How to reproduce:

Setup a TOTP with google authenticator.
Login with user/pass.
When entering the TOTP code, don't check the "trust this computer" checkbox.
Browse drupal.org for a couple days until it decides you need to enter another TOTP (but not user/pass).
Notice that you're redirected to the homepage or /user instead of the page you were on.

I don't know if this is caused by this module, or by the way it's configured on drupal.org. I haven't been able to figure out how to test getting a TOTP form w/o the user/pass, if you can explain how I can do that I'll debug it and try to get better info.

πŸ› Bug report
Status

Active

Version

2.0

Component

Code

Created by

πŸ‡ΊπŸ‡ΈUnited States rocketeerbkw Austin, Tx

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

Not all content is available!

It's likely this issue predates Contrib.social: some issue and comment data are missing.

  • πŸ‡ΊπŸ‡ΈUnited States cmlara

    Drupal 7 end-of-life triage:
    Drupal 7 reached end of life on January 5th.

    The 7.x branches of TFA do not have any additional planned releases.

    I do not believe the situation as described (login without password yet prompted for OTP)_ can occur in the 8.x-1.x and newer branches,

    We have a number of locations where we forcefully set the destination. I suspect this issue still exists in some form.

    This should be manually tested in latest versions.

Production build 0.71.5 2024