nextcloud / nextcloud/twofactor_admin

Provider active despite expired code

Open
#400 12 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

1. to develop bug
Dominant language
JavaScript
Stars
18
Forks
11
Avg merge
10h 32m
Merged PRs (30d)
2

Description

Steps to reproduce
  1. Generate a code for an admin user
  2. Wait for 48 hours
  3. The twofactor afmin support provider os still shown in the list of 2FA providers
Expected behaviour

The provider should expire as for usual users

Server configuration

Web server: Apache

Database: MySQL/Maria/SQLite/PostgreSQL

PHP version: 8.2

Nextcloud version: 30.0.10

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start at the admin 2FA provider's expiry and provider-listing entry points, comparing them with the usual-user expiry path. Reproduce with an admin-generated code after the 48-hour window and verify that the provider is no longer listed in the PHP 8.2 setup.

Written by the indexing model from the issue text.

Assessment

Tech stack
apache, javascript, php
Domain
authentication, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.