RSS Feed/News Login via Passkey sets remember but not tfa_trust cookie

Status
Not open for further replies.

ENXF NET

Administrator
Staff member
Administrator
Moderator
+Lifetime VIP+
S.V.I.P.S Member
S.V.I.P Member
V.I.P Member
Collaborate
Registered
Joined
Nov 13, 2018
Messages
29,888
Points
823

Reputation:

When logging in with a Passkey, XenForo automatically sets cookie _user so th user stays "logged in" but it does not set cookie tfa_trust so for the next session a TFA verification is required - which can be performed with the same Passkey that was used to initially log in.

IMHO this doesn't make much sense and probably annoys & confuses users.

XenForo should either
  1. Always set user and tfa_trust cookies when logging in via Passkey
    Preferred
  2. Never...

Read more

Continue reading...
 
Status
Not open for further replies.
Top