Skip to content

fix: add first login totp reset flow - #126

Merged
addidotlol merged 4 commits into
mainfrom
addison/totp-reset
Sep 21, 2026
Merged

addidotlol merged 4 commits into
mainfrom
addison/totp-reset

Conversation

@addidotlol

@addidotlol addidotlol commented Sep 20, 2026

Copy link
Copy Markdown
Member

do not merge

- Extract the reset flow into a reusable component
- Handle pending sign-in users and password-verified TOTP removal
- Preserve passkey challenges and return new authenticator setup data
- Return the affected user email when reset requires sign-in
- Mask reset email on the TOTP page
- Update migration copy and support centered flow text
@addidotlol
addidotlol marked this pull request as draft September 20, 2026 19:26
@addidotlol
addidotlol marked this pull request as ready for review September 20, 2026 20:27
@addidotlol
addidotlol requested a review from lleyton September 20, 2026 20:51

@lleyton lleyton left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What's the point of TOTP if you can reset it from your email?

- Remove the standalone TOTP reset dialog and signed-in reset path
- Require legacy TOTP reset flow to run while signed out
- Centralize reset and disable handling through verified password removal
@addidotlol
addidotlol merged commit de4499b into main Sep 21, 2026
4 checks passed
@addidotlol
addidotlol deleted the addison/totp-reset branch September 21, 2026 00:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants