I have installed TFA and TFA Basic Plugins, and this is basically working. But... fallback options are not working. When a user cannot access the code to authenticate there is no option to access the fallback - whether that fallback is recovery codes or email. At the site wide level I have set both fallback options, but nothing is available for a user to access these when they can't access their authentication device. From a chat with AI, it seems that the problem is these fallback options need to be set 'per user' but I don't see how to do that. Can anyone help?
Comments
I'll test this tomorrow to see if I can replicate the problem and report back.
It's not "per user" so it should be working.
Thanks for the response, Herb!
Since I posted that I did some more testing and have posted this issue https://github.com/backdrop-contrib/tfa_basic/issues/33
In fact, if both email and recovery codes fallbacks are checked, a user who can't access their account can use fallbacks. If you unset email fallback, they can't get to any fallback. That's the problem. The client doesn't want email as a fall back since it defeats the security of TOTP.