Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Improve password reset precess #1116

Open
paustint opened this issue Dec 18, 2024 · 0 comments
Open

Improve password reset precess #1116

paustint opened this issue Dec 18, 2024 · 0 comments

Comments

@paustint
Copy link
Contributor

Describe the bug and steps to reproduce

This describes some issues, solution TBD

if user has 2FA via an authenticator app and no password and no other 2fa factors, then there is no way for a user to recover without having support involved (maybe this is ok? Most users should have email 2fa enabled as a backup...)
☝️ Maybe we can at least warn the user on the profile page that it is recommended to have email 2fa enabled as a backup
☝️Or maybe we can always allow 2fa via email if authenticator app is enabled? (do some research here)

"Remember Device"
IMO this checkbox should be enabled by default... or maybe we should just remove this checkbox and have this be the only behavior, since otherwise it is super annoying for users that do not access the app every day.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant