Do not count backup codes as the other second factor (3.3) - #224
Merged
nursoda merged 1 commit intoSep 4, 2026
Merged
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
When the address a code is mailed to disappears, the listener switches this provider off if the account still has another second factor, and leaves it on otherwise. It asked the registry for any enabled provider other than email, and backup codes answered that question with yes. Nextcloud itself does not: IManager::isTwoFactorAuthenticated() takes backup codes out of the list before deciding whether an account is protected, because they are a way back in, not a factor to log in with every day. An account with email 2FA and backup codes therefore came out of a deleted address as password-only — the one outcome the listener exists to prevent. It now ignores them for that decision. Such an account keeps email 2FA enabled, so the login still asks for a second factor, and the user can pick backup codes at the provider selection to get in while an administrator restores the address. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Signed-off-by: Olav Seyfarth <olav@seyfarth.de>
nursoda
force-pushed
the
security/dont-count-backup-codes-as-a-factor-3.3
branch
from
September 4, 2026 22:56
3b0fa5a to
3b4cc27
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Same change as on
main, for the 3.3 line.When the address a code is mailed to disappears,
EMailDeletedswitches this provideroff if the account still has another second factor. It counted backup codes as such a
factor, while Nextcloud's own
isTwoFactorAuthenticated()takes them out of the listbefore deciding whether an account is protected. An account with email 2FA and backup
codes therefore came out of a deleted address as password-only.
hasOtherActiveProvider()now ignores them, so the account keeps email 2FA enabled andits user logs in with a backup code while an administrator restores the address.
🤖 Generated with Claude Code, verified, tweaked and approved by @nursoda.