Skip to content

Don't silently override totp secret during reenrollment - #1210

Merged
j-chmielewski merged 1 commit into
devfrom
fix-totp-reenrollment
Oct 5, 2026
Merged

j-chmielewski merged 1 commit into
devfrom
fix-totp-reenrollment

Conversation

@j-chmielewski

Copy link
Copy Markdown
Contributor

Related issue: DefGuard/defguard#3725

During re-enrollment with no MFA-enabled locations, the client started TOTP setup even though it skipped the setup screen. This replaced the user's existing TOTP secret without showing them the new QR code. The client now starts TOTP setup only when MFA is required.

@j-chmielewski
j-chmielewski merged commit 010bfbf into dev Oct 5, 2026
10 of 11 checks passed
@j-chmielewski
j-chmielewski deleted the fix-totp-reenrollment branch October 5, 2026 10:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants