TfaOverviewForm shows "Disable TFA" link for users without permission

Created on 20 June 2025, about 1 month ago

Problem/Motivation

Users with some permission combinations are shown a broken link to the tfa.disable route when they can't actually access it.

  • When a user has administer tfa for other users but not disable own tfa while viewing own TFA page
  • When a user has disable own tfa but not administer tfa for other users while viewing another user's TFA page

Proposed resolution

Change the logic in TfaOverviewForm::buildForm from hasPermission to Url->access

πŸ› Bug report
Status

Active

Version

2.0

Component

User interface

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

Production build 0.71.5 2024