Skip to content

Do not count backup codes as the other second factor (3.3) - #224

Merged
nursoda merged 1 commit into
release/3.3from
security/dont-count-backup-codes-as-a-factor-3.3
Sep 4, 2026
Merged

nursoda merged 1 commit into
release/3.3from
security/dont-count-backup-codes-as-a-factor-3.3

Conversation

@nursoda

@nursoda nursoda commented Aug 27, 2026

Copy link
Copy Markdown
Member

Same change as on main, for the 3.3 line.

When the address a code is mailed to disappears, EMailDeleted switches this provider
off if the account still has another second factor. It counted backup codes as such a
factor, while Nextcloud's own isTwoFactorAuthenticated() takes them out of the list
before deciding whether an account is protected. An account with email 2FA and backup
codes therefore came out of a deleted address as password-only.

hasOtherActiveProvider() now ignores them, so the account keeps email 2FA enabled and
its user logs in with a backup code while an administrator restores the address.

🤖 Generated with Claude Code, verified, tweaked and approved by @nursoda.

@nursoda nursoda added security Related to a security vulnerability php Pull requests that update php code labels Aug 27, 2026
@nursoda nursoda self-assigned this Aug 27, 2026
@nursoda
nursoda requested a review from seyfahni August 27, 2026 22:50
@codecov

codecov Bot commented Aug 27, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@nursoda
nursoda removed the request for review from seyfahni September 4, 2026 22:13
When the address a code is mailed to disappears, the listener switches this
provider off if the account still has another second factor, and leaves it on
otherwise. It asked the registry for any enabled provider other than email, and
backup codes answered that question with yes.

Nextcloud itself does not: IManager::isTwoFactorAuthenticated() takes backup
codes out of the list before deciding whether an account is protected, because
they are a way back in, not a factor to log in with every day. An account with
email 2FA and backup codes therefore came out of a deleted address as
password-only — the one outcome the listener exists to prevent.

It now ignores them for that decision. Such an account keeps email 2FA enabled,
so the login still asks for a second factor, and the user can pick backup codes
at the provider selection to get in while an administrator restores the address.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Olav Seyfarth <olav@seyfarth.de>
@nursoda
nursoda force-pushed the security/dont-count-backup-codes-as-a-factor-3.3 branch from 3b0fa5a to 3b4cc27 Compare September 4, 2026 22:56
@nursoda
nursoda requested a review from seyfahni as a code owner September 4, 2026 22:56
@nursoda
nursoda merged commit 1a59858 into release/3.3 Sep 4, 2026
28 checks passed
@nursoda
nursoda deleted the security/dont-count-backup-codes-as-a-factor-3.3 branch September 4, 2026 22:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

php Pull requests that update php code security Related to a security vulnerability

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant