Browse Source
* Allow email-only /api/two-factor/send-email-login for mobile clients Mobile clients (iOS) may call /api/two-factor/send-email-login with only the user's email and without a MasterPasswordHash or an AuthRequest. Permit email-only requests so the server will send the email 2FA token in that flow.\n\nModified: src/api/core/two_factor/email.rs Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * fix(email-2fa): use device-identifier fallback when no password hash submitted iOS clients call /api/two-factor/send-email-login with an email and DeviceIdentifier but without masterPasswordHash or authRequestId after receiving a 2FA-required response from the token endpoint. The previous empty else-block allowed any caller to trigger a 2FA email for any account knowing only the email address. Replace the empty block with a device-identifier-based fallback: - Look up the most-recently-active device via find_by_device_for_email2fa. - Verify the device's associated user email matches the submitted email. - Log (debug) when the fallback path is exercised for operator visibility. - Reject with the original error when no device identifier is provided or when the device maps to a different account. Fixes #7568 * Check the pending 2FA login for this user and device Look up the pending 2FA login for the user and device instead of the latest one on the device, answer a failed check with the same error and IP/username log detail as a wrong password, and escape the device id in the logs. --------- Co-authored-by: Arunabha-Mukhopadhyay <dkarunabha2006@gmail.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>pull/7828/head
committed by
GitHub
1 changed files with 19 additions and 2 deletions
Loading…
Reference in new issue