RGJ
(Richard - Communiteq)
2022 年10 月 31 日 13:50
25
If you have managed hosting you should be able to ask your managed hosting provider to do this for you, so I don’t see the problem there.
I’m afraid this topic is the formal bug report.
Of course the fix should also include removal of existing backup codes where there is no 2FA method present.
When there is no 2FA configured, the backup codes should IMO be removed from the database to prevent unnecessary “orphaned” data being present.
3 个赞
RGJ
(Richard - Communiteq)
2022 年10 月 31 日 14:13
27
Although sam
is the right person to ask if this bug can be prioritized (not sure if tagging is appreciated though), I suspect an email to team@discourse.org will get your operational problem fixed more quickly.
5 个赞
RGJ
(Richard - Communiteq)
2022 年10 月 31 日 15:21
29
Other people are reading this topic as well so IMO it did not harm to point everyone in the right direction.
3 个赞
@Osama are you handling this fix or do I need to get to work?
sam
(Sam Saffron)
2022 年11 月 1 日 05:14
31
Feel free to send a carefully tested PR and we will evaluate.
Moved @lukastribus discussion to team PM who can triage there.
1 个赞
The solution to this problem was merged - FEATURE: better UI to manage 2fa by lis2 · Pull Request #19338 · discourse/discourse · GitHub
When the last authenticator is deleted, we disable 2fa. User is asked to confirm to avoid disabling 2fa by mistake:
7 个赞