Bug in 2FA Force
-
Looks like there is not really a "Enforce" for 2FA.
First Login from the User
After this just open the URL
https://cloudronserver.server/#/apps
Now you can see the dashboard and login etc -
Looks like there is not really a "Enforce" for 2FA.
First Login from the User
After this just open the URL
https://cloudronserver.server/#/apps
Now you can see the dashboard and login etcAccording to the docs, all users should be logged out after activating mandatory 2FA. Haven't testet it.
So you're saying the problem is that users are not logged out immediately?
-
Looks like there is not really a "Enforce" for 2FA.
First Login from the User
After this just open the URL
https://cloudronserver.server/#/apps
Now you can see the dashboard and login etc@savity said in Bug in 2FA Force:
After this just open the URL
Do you mean without setting up 2FA , you can open that URL for that user and just access the dashboard? What happens if you F5/refresh?
Also, the mandatory 2FA is implemented at client side/browser level and there are no server side checks.
-
@savity said in Bug in 2FA Force:
After this just open the URL
Do you mean without setting up 2FA , you can open that URL for that user and just access the dashboard? What happens if you F5/refresh?
Also, the mandatory 2FA is implemented at client side/browser level and there are no server side checks.
-
According to the docs, all users should be logged out after activating mandatory 2FA. Haven't testet it.
So you're saying the problem is that users are not logged out immediately?
-
@subven yeah so configure 2FA if not logout the user. It would be even better to have a own mask after first logon to setup 2FA nad then be able to see the dashboard.
now you can just browse the urls
-
G girish marked this topic as a question on
-
G girish has marked this topic as solved on