Users are directed to TFA overview regardless of 'setup own tfa' permission

Created on 24 October 2019, about 5 years ago
Updated 16 September 2023, about 1 year ago

Problem/Motivation

When a user is required to set up TFA, the page displays a message:

You are required to setup two-factor authentication here. You have 2 attempts left. After this you will be unable to login.

This message is displayed regardless of the user's access to the TFA overview page. As a result, users may be served an 'Access denied' page when clicking 'here'.

Proposed resolution

Display a different message for users without the 'setup own tfa' permission.

Remaining tasks

  1. Write a patch
  2. Review
  3. Commit

User interface changes

Users that have no access to setup their TFA are not directed to the account TFA overview page.

API changes

None.

Data model changes

None.

πŸ“Œ Task
Status

Fixed

Version

2.0

Component

Code

Created by

πŸ‡³πŸ‡±Netherlands idebr

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

Not all content is available!

It's likely this issue predates Contrib.social: some issue and comment data are missing.

Production build 0.71.5 2024