-
-
Notifications
You must be signed in to change notification settings - Fork 4.2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Delete or disable backup 2FA codes #9997
Comments
GitMate.io thinks possibly related issues are #9036 ([2FA] longevity of Backup-Codes), #3130 (After upgrade disable/enable 2fa generates a new code ), #1557 (2FA auth backup codes not removed on user deletion), #1108 (2FA: let users create and authenticate via backup codes), and #6636 (Automaitc Upgrade process - Disable backup). |
You can't. And I see no point in being able to do it. If no 2FA provider is active, the Nextcloud server won't ask you for your codes anyway.
Why would you want to do that? That's currently not possible.
See #2348 and nextcloud/twofactor_totp#41. |
Hi CW Thanks for the reply
Regards ZT |
Please file a proper feature request (or update the original post and title) with detailed information of how this should work. Yes, funding usually helps. Thanks |
Solved, via theming custom css app /* HIDE Settings Two Factor Code Button */ |
Assuming this is resolved -> closing. Feel free to reopen if that's still an issue for you. |
just dropping by because of: nextcloud/user_saml#284 and nextcloud/user_saml#339 All in all these solutions (enforce 2fa without 2fa methods and hiding backup codes, as well as using the webserver to block access to "direct=1") feel like hacks that should not be needed if once the SAML backend is activated there was the option to REALLY restrict login to the SAML backend, with the fallback in case of misconfiguration being disabling the app via occ. |
@ChristophWurst thanks for the help here >> #6203 (comment)
i see you are the 2FA guy, so 2 questions
How do i delete backup codes ?
Can i disable backup codes from being created ?
How can i force 2FA and change password at 1st login (via both internal db and external ldap)
Thanks
ZT
The text was updated successfully, but these errors were encountered: