RocketChat / RocketChat/Rocket.Chat.ReactNative
bug: FIDO 2FA with OAuth not working on iOS
Nobody has claimed this yet.
- Dominant language
- TypeScript
- Stars
- 2.4k
- Forks
- 1.5k
- Avg merge
- 1d 18h
- Merged PRs (30d)
- 90
Description
Describe the Bug
Hey there,
I've tried to log in via OAuth2 (GitHub) via the mobile app. The login works well on the browser and also on the desktop app. On the mobile however, after getting past the username/password, I end up on the "Use security key" option, which insta-fails with "Authentication failed".
The same flow works on Mattermost, so I'd assume there's some misconfiguration in the Rocket Chat app, not some platform or library limitation per se.
Steps to Reproduce
Erm, try to log in via GitHub SSO with a Yubikey as 2FA.
Expected Behavior
Get prompted for a security key challenge.
Actual Behavior
Instant error message
Rocket.Chat Server Version
7.11.0
Rocket.Chat App Version
4.65.0
Device Name
iPhone 14
OS Version
iOS
Additional Context
No response
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
No file or test is named in the issue. Start by reproducing GitHub OAuth login with a Yubikey on an iPhone running iOS, then compare the mobile flow with the working browser and desktop flows. Done means the security-key challenge completes successfully instead of immediately showing "Authentication failed".
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github, ios, react-native, typescript
- Domain
- authentication, mobile, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100