Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Recovery Code - Fallback options after loss of access to Authenticator app #48

Open
smashm opened this issue Mar 16, 2022 · 2 comments
Open
Labels
enhancement New feature or request

Comments

@smashm
Copy link

smashm commented Mar 16, 2022

The remember the browser function was a big step forward for everyday usability.

I would also like to see a fallback option integrated in case users can no longer access their authenticator app, for example if their phone is lost or stolen.

Currently, access can only be granted via manual administrative intervention, which is particularly inconvenient for users without access, in larger communities for admins, too.

I am aware of these options, for example:

  • Hetzner's consoleH provides a recovery key via snail mail
  • Users can generate multiple stock emergency keylists for download, e.g. LinkedIn 5 pieces or Facebook 10 pieces
  • On Xing, this is limited to one, but can also be generated at any time

Personally, I think one code would be enough, but a few more certainly won't hurt for some users.

@luke- luke- changed the title Fallback options after loss of access to Authenticator app Recovery Code - Fallback options after loss of access to Authenticator app Mar 16, 2022
@luke- luke- added the enhancement New feature or request label Mar 16, 2022
@errotu
Copy link

errotu commented Sep 13, 2022

I would also support such an enhancement very much! The backup codes are quite common as fallback option for services using 2FA.

Currently, access can only be granted via manual administrative intervention, which is particularly inconvenient for users without access, in larger communities for admins, too.

How does the manual administrative intervention actually work? Is there a per user possibility to (temporarily) disable 2FA? I didn't find any information about it in the docs.

@E1chn3r
Copy link

E1chn3r commented Jul 6, 2023

I would also love to a function to reset the 2FA. Maybe with backup codes or the possibility for admins to create an admin code for the users to log in which is valid a couple of hours.

Are there any plans for the feature?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

4 participants