-
-
Notifications
You must be signed in to change notification settings - Fork 230
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
2FA broken after upgrading to latest Grav, admin-panel, and login-plugin #2109
Comments
Does this happen in admin or site? |
Valid question! Forgot to mention that- My main site doesn't have any content behind a login, so was talking from an "admin panel" point of view. I just tested it on the site I reproduced it on, and there logging in through the normal site does not have the same issue. The admin panel there fails with "Invalid Security Token", but 2FA on the regular site works as intended. |
@Eihrister Thanks for reporting this one! We will release a fix for this soon. |
Hi again, I just saw the release and upgraded; unfortunately, the problem has changed, but is not quite solved yet. This is what I get after entering my 2FA code now; "You have been succesfully logged in", and a "You have been logged out" at the same time, reprompting for a 2FA code, not returning to the username/password screen, either. Reopening in a new private window does not make it work, either. |
Can you ping me in discord as I'm not able to reproduce your issue. Also, do you have some login integration plugin turned on? |
…ication due to `/admin/task:getNotifications` AJAX call [#2109]
All issues should be fixed now (tested with this site), so closing the issue. Fixes are in the next release. |
Hello,
Last night I upgraded one of my sites from the pre-latest Stable versions (I keep up to date) to Grav 1.7.10, and there were also 4 new plugin updates available, amongst which the "login" plugin, and the admin panel.
However, logging in after my session expired, is impossible now without disabling 2FA manually by editing my
user/accounts/danielm.yaml
file.Every time I try to log in with 2FA enabled now, it throws me a "Invalid Security Token" error after entering the 2FA code.
Tried the following:
bin/grav cache
bin/grav clean
I tried reproducing it on another Grav site I run, which was running the same versions and upgraded to the latest Stable versions of the above as well. Same issues, can no longer log in to that site either without disabling 2FA.
Seems as if the login-plugin upgrade broke something, or the admin panel (seems less likely).
Kind regards,
Eih
The text was updated successfully, but these errors were encountered: