You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Thinking this through; there's twothree different cases related to backup codes, each with a slightly different interstitial / redirect case
Logged in with a backup code - Do you need to setup a new 2FA provider? or do you just not have your keys with you right now?
Logged in normally; but now has a few (3?) backup code remaining - Do you need to download/store new backup codes?
Logged in normally; but doesn't have any verified backup codes - Nag, Hey did you download/store those? Go generate new ones plz
2&3 are probably one and the same really, and should be a priority to reduce nuisance account lock-out issues before #9
1 is likely far less urgent, and could potentially be irrelevant depending on how #9 is resolved.
When a user logs in with a backup code / recovery code, it should be assumed that this is a case where they've lost their 2FA details.
We should override the redirection location to be their 2FA settings.
The text was updated successfully, but these errors were encountered: