Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Passkey only recovery flow asks to "change password" doesn't display hardware key #3386

Open
4 of 6 tasks
jmatsushita opened this issue Jul 22, 2023 · 0 comments
Open
4 of 6 tasks
Labels
bug Something is not working.

Comments

@jmatsushita
Copy link

Preflight checklist

Describe the bug

The language after successful recovery via email is confusing since there isn't a password nor social sign-in setup. In addition no hardware token is displayed in the list.

image

In addition when pressing "Add security key" and registering the same device with a different key name (using the id after-recovery in the below example) only then does the key identifier used during sign-up displayed (in the below example j-zero).
image

Worse if I click Remove security key "after-recovery", both keys are removed in the UI.

Reproducing the bug

When, as a project admin, I configure an ory network developer project to passkey only (enabling passkeys and disabling password auth),

The, as a user, I sign up with an email, use the account recovery option using the Ory Account Experience UI, after entering the OTP the Account Recovery page says:
You successfully recovered your account. Please change your password or set up an alternative login method (e.g. social sign in) within the next 15.00 minutes.

Pressing "Add security key" and registering the same device with a different key name now shows 2 keys.

Removing only one of the keys leads to none being displayed.

Relevant log output

No response

Relevant configuration

No response

Version

https://console.ory.sh/

On which operating system are you observing this issue?

Ory Network

In which environment are you deploying?

Ory Network

Additional Context

No response

@jmatsushita jmatsushita added the bug Something is not working. label Jul 22, 2023
@jmatsushita jmatsushita changed the title Passkey only recovery flow asks to "change password"m doesn't display hardware key and can lead to account lock out Passkey only recovery flow asks to "change password" doesn't display hardware key and can lead to account lock out Jul 22, 2023
@jmatsushita jmatsushita changed the title Passkey only recovery flow asks to "change password" doesn't display hardware key and can lead to account lock out Passkey only recovery flow asks to "change password" doesn't display hardware key Jul 22, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something is not working.
Projects
None yet
Development

No branches or pull requests

1 participant