Skip to content

Bypass of 2FA when using mobile version #635

@eboss-dev

Description

@eboss-dev

Is this a BUG REPORT or FEATURE REQUEST?:

  • BUG
  • FEATURE

What happened: I tried setting up the 2FA with Duo. It works fine as long as I use the desktop version. When I switch to the mobile one the 2FA is completely by-passed

What did you expect to happen: 2FA working in the mobile version too

How to reproduce it (as minimally and precisely as possible): I try to reproduce using a phone without the authenticator as well as in chrome with the inspection tool emulating a phone. When I am at this path (yourTrudeskURL/mobile/#/login) I don't get the request for a code.

Anything else we need to know?:

Environment:

  • Trudesk Version: 1.0
  • OS (e.g. from /etc/os-release): Ubuntu 22.04 LTS
  • Node.JS Version: 10.10 Alpine
  • MongoDB Version: Mongo 3.6
  • Is this hosted on cloud.trudesk.io: no

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions