I have installed TFA and TFA Basic Plugins, and this is basically working.  But... fallback options are not working.  When a user cannot access the code to authenticate there is no option to access the fallback - whether that fallback is recovery codes or email.   At the site wide level I have set both fallback options, but nothing is available for a user to access these when they can't access their authentication device.    From a chat with AI, it seems that the problem is these fallback options need to be set 'per user' but I don't see how to do that.  Can anyone help?

Comments

I'll test this tomorrow to see if I can replicate the problem and report back. 

It's not "per user" so it should be working.

Thanks for the response, Herb!

Since I posted that I did some more testing and have posted this issue https://github.com/backdrop-contrib/tfa_basic/issues/33

In fact, if both email and recovery codes fallbacks are checked, a user who can't access their account can use fallbacks.  If you unset email fallback, they can't get to any fallback.  That's the problem.  The client doesn't want email as a fall back since it defeats the security of TOTP.