nextcloud / nextcloud/server

Generate and ask user to copy backup codes when TOTP based 2FA is enabled

Open
#57,541 0 comments 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

0. Needs triage enhancement feature: authentication
Dominant language
PHP
Stars
36.9k
Forks
5.2k
Avg merge
2d 3h
Merged PRs (30d)
713

Description

[!TIP]

Help move this idea forward
  • Use the 👍 reaction to show support for this feature.
  • Avoid commenting unless you have relevant information to add; unnecessary comments create noise for subscribers.
  • Subscribe to receive notifications about status changes and new comments.

Is your feature request related to a problem? Please describe.

  • Backup codes is a section below the TOTP (Authenticator App) setting
  • This means it is an optional thing that users can select
  • So many users don't actually generate backup codes and then lose access to their account

Describe the solution you'd like

  • Clear call to action to generate 2FA backup codes whenever 2FA is enabled
  • For e.g. proton account settings give a modal like:
Image

Describe alternatives you've considered

  • Maybe some text in bold asking user to generate backup codes without fail could be a "quick win" solution

Additional context

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No implementation files or tests are named. Start by locating the TOTP setting and existing backup-code section in the Nextcloud Server UI, then trace what happens when 2FA is enabled. Done should include a clear prompt to generate and copy backup codes without removing the existing backup-code option.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript, php
Domain
authentication, design, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.