Skip to content

2FA idea #237

Description

@dakhnod

I read here that after receiving a 2FA code, one can just attempt to log in with an email address and a password + the 2FA code.

The login process would then look like this:

  1. Log in using useremail@example.de and password testpassword (fake creds, obviously)
  2. Wait for 2FA sms with code "123456"
  3. Cancel the log in process
  4. Log in using useremail@example.de and password testpassword123456

-> Skips the 2FA step

I could not get this to work, since with multiple registered devices I do not even receive a 2FA SMS.

Yet, this might somehow serve as an option for getting through 2FA.

Just wanted to toss that in, feel free to close

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions