You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
fix(mfa): ignore verify-disabled factors in recovery codes guard (#2824)
When a user has a second factor enrolled but verification has been
disabled at the configuration level, we should not allow the enrollment
of recovery codes as that would make the recovery codes the only usable
second factor.
returnapierrors.NewUnprocessableEntityError(apierrors.ErrorCodeMFARecoveryCodesSoleFactor, "Recovery codes cannot be the only verified factor. Please enroll another factor before unenrolling this one or delete your recovery codes.")
{name: "verified factor of a verify-disabled type", factors: []models.Factor{factor(models.Phone, models.FactorStateVerified)}, want: false},
97
+
{name: "recovery-code factor never counts even when verify is enabled", factors: []models.Factor{factor(models.RecoveryCode, models.FactorStateVerified)}, want: false},
returnapierrors.NewUnprocessableEntityError(apierrors.ErrorCodeMFARecoveryCodesSoleFactor, "At least one other verified factor is required to generate recovery codes")
0 commit comments