Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

rember 2FA when remember logging in #352

Open
sweebee opened this issue Mar 18, 2024 · 5 comments
Open

rember 2FA when remember logging in #352

sweebee opened this issue Mar 18, 2024 · 5 comments

Comments

@sweebee
Copy link
Contributor

sweebee commented Mar 18, 2024

When you remember your login and the session expires, it asks for the 2FA code again.

I don't want to enter the 2FA code again if I have enabled the remember me at login.

@andreapollastri
Copy link
Contributor

I think that this is not secure! The 2FA protects from unwanted logins from your personal device too (such as a login from a coworker, a family member, ...)

@sweebee
Copy link
Contributor Author

sweebee commented Mar 23, 2024

Well, never seen a website do it like this. Like Laravel Vapor, GitLab, Home Assistant. If you click "keep me logged in" it will never ask the 2FA again until you manually logout.

@divdax
Copy link

divdax commented Mar 26, 2024

Asking for 2FA Code when login with "remember me" is weird. Never used a service acting like this. If you don't trust your cookie remember token you can logout other devices yourself.

@sweebee
Copy link
Contributor Author

sweebee commented Mar 26, 2024

Also, a lot of services have an option "trust this device" when entering the 2FA code so it doesn't ask it again. Even when you logout.

@zenepay
Copy link

zenepay commented Nov 2, 2024

+1 "Trust this device" option should be available.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants