[stable18] Clean up 2FA provider registry when a user is deleted#18770
[stable18] Clean up 2FA provider registry when a user is deleted#18770
Conversation
Signed-off-by: Christoph Wurst <christoph@winzerhof-wurst.at>
|
This does not seem to be resolved in 18.0.3.
Created a group "2fa", enforced 2FA for this group, added a user and put it into group "2fa", signed in as this user, was forced to setup 2FA with TOTP. Deleted the user, recreated it and put it into group "2fa", signed in as this user, was asked to authenticate with TOTP app (instead of: being asked to setup 2FA). Before logging in the first time after recreation: After logging in but before entering a Token:
|
|
Yeah, so I think the state is cleared. But since the totp app does not clears its state, it will propagate again. The actual bug was reported at nextcloud/twofactor_totp#384. Let's continue there. |
backport of #18738