Skip to content

MFA is disabled in settings but if it was already 'on' for the user it's still kinda on #4772

@robinsowell

Description

@robinsowell

So... this one is weird and difficult to replicate.

User had the site offline. Non-logged in users get the offline message. I login - no mfa required. I go to Settings and MFA is disabled there. Cool- I assume it is totally out of the picture.

When I go to visit the frontend the first page loads but when I navigate to another page it either shows me the offline message (treating me as logged out) OR it gives me the MFA page. Which is disabled so I don't know why that would ever happen.

They had some cookie issues which I resolved but would still get that mfa popping up on the frontend.

I finally went in and set all of the individual settings to 'n' via query and everything then worked normal:

Update exp_members set enable_mfa = 'n'

But... I think even when disabled site wide, at least on the frontend there's still some MFA check cropping up if it's set to 'y' for the individual user.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions