The 'disable TFA' asks for password confirmation - but it always checks the password of the user for whom TFA is being disabled, rather than the current user.

Support from Acquia helps fund testing for Drupal Acquia logo

Comments

pjcdawkins’s picture

FileSize
801 bytes
coltrane’s picture

Great catch @pjcdawkins! I'll review soon but in the meantime if you're able to add a test for this it'd be helpful.

coltrane’s picture

Added test. Going to commit this next.

  • coltrane committed 17db775 on 7.x-1.x authored by pjcdawkins
    Issue #2471799 by pjcdawkins, coltrane: Let admins disable users TFA
    
coltrane’s picture

Status: Needs review » Fixed

Committed

pjcdawkins’s picture

Thanks!

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.