Warn user about needing app passwords before enabling 2FA
Nobody has claimed this yet.
- Dominant language
- PHP
- Stars
- 36.9k
- Forks
- 5.2k
- Avg merge
- 2d 3h
- Merged PRs (30d)
- 713
Description
How to use GitHub
- Please use the 👍 reaction to show that you are interested into the same feature.
- Please don't comment if you have no relevant information to add. It's just extra noise for everyone subscribed to this issue.
- Subscribe to receive notifications on status change and new comments.
Is your feature request related to a problem? Please describe.
When enabling 2FA, it's not clear that the user would have to only use app passwords with the mobile/desktop application afterwards. This leads to users believing they are being 'locked out' of their existing apps, while really they just need to generate new app passwords.
Describe the solution you'd like
Before enabling 2FA, there should be a (blocking) dialog with a checkbox saying, 'Yes, I understand that once I enable 2FA, I will need to generate app passwords and re-login to all existing applications.'
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
The issue names no files or tests. Start by locating the 2FA enablement flow and its existing confirmation UI, then verify that the warning and acknowledgement appear before activation and that the existing-app reauthentication path is covered by tests.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript, php
- Domain
- authentication, security
- Issue type
- Feature
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100