Skip to content

Issue #2930355: One-time login link bypasses TFA

Mingsong requested to merge issue/tfa-2930355:2930355-39 into 2.x
  • Overwrite user reset password login route.
  • Redirect user to edit form after TFA validation if it is one time login.
  • New method TfaContext::canResetPassSkip().
  • New setting to allow the super admin skipping TFA. Default is false.
  • New test for Tfa password reset.
Edited by Mingsong

Merge request reports