Condition for roles to be excluded should be if user has ANY role needing TFA they should get it

Created on 5 March 2023, about 2 years ago
Updated 15 March 2023, almost 2 years ago


With the current condition for excluding a user from TFA by role, if a user has multiple roles and one role does NOT need TFA, the user is excluded, even if the user has other roles that SHOULD need TFA.

Steps to reproduce

  1. On a site with multiple user roles, configure Email TFA to exclude only some roles.
  2. Create a user with multiple roles including one or more that are excluded and one or more that are not excluded.
  3. Log in as that user and see that no Email TFA code is required.
  4. Remove from that user the excluded roles, and see that Email TFA is required.

Proposed resolution

Recode the condition so that if a user has ANY roles requiring Email TFA they have to enter the code.

See attached proposed patch.

Remaining tasks

Maintainer review of patch.

User interface changes


API changes


Data model changes


✨ Feature request

Closed: duplicate





Created by

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

Not all content is available!

It's likely this issue predates some issue and comment data are missing.

Production build 0.71.5 2024