View Issue Details

IDProjectCategoryView StatusLast Update
0009272Talerlibeufin-bankpublic2024-10-15 18:29
ReporterAntoine A Assigned ToAntoine A  
PriorityhighSeverityfeatureReproducibilityN/A
Status assignedResolutionopen 
Target Version1.0 
Summary0009272: Password recovery and account unlocking
DescriptionWe need users who have forgotten their password but whose 2fa is enabled to be able to change their current password.
We already have an endpoint to change the password of a bank account at PATCH /accounts/$USERNAME/auth, this endpoint should reset the attempt counter and allow password change without entering the current password if 2fa is used.
We can't do this at the moment, as the 2fa challenge access points are authenticated and disclose 2fa channel information (email or phone number).
TagsNo tags attached.

Relationships

related to 0009271 assignedAntoine A Lockout policy 
child of 0009269 assignedAntoine A Password and lockout policy 

Activities

There are no notes attached to this issue.

Issue History

Date Modified Username Field Change
2024-10-15 18:29 Antoine A New Issue
2024-10-15 18:29 Antoine A Status new => assigned
2024-10-15 18:29 Antoine A Assigned To => Antoine A
2024-10-15 18:29 Antoine A Relationship added child of 0009269
2024-10-15 18:29 Antoine A Relationship added related to 0009271