Skip to content

Require 2FA when changing password in password recovery flow #95

@santiagorodriguez96

Description

@santiagorodriguez96

Right now, in apps that use this gem along with Devise's recoverable module, users won't be challenged with their two factor to change their password when going through the password recovery flow. In fact, if recoverable module is configured to sign in after changing the password, users are able to essentially sign in bypassing 2FA.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions