Problem/Motivation
When you have some modules like "Login And Logout Redirect Per Role", "Redirect After Login" etc, setting "Redirect users on login to TFA Setup Page" will not work.
The reason is located at 105th line of TfaLoginForm.php
// Redirect user directly to the TFA account setup overview page.
if ($this->getRequest()->request->has('destination')) {
$this->getRequest()->query->remove('destination');
}
It seems like a typo: value is checked in "request", but removed from "query"
Steps to reproduce
1. Install and Enable module Login And Logout Redirect Per Role and configure some login destination for authenticated user.
2. Set checkbox "Redirect users on login to TFA Setup Page" in TFA settings.
3. Try to log in as user without TFA.
Proposed resolution
Repair code
Remaining tasks
No
User interface changes
No
API changes
No
Data model changes
No
Comments
Comment #2
gun_dose commentedComment #3
gun_dose commentedComment #4
cmlaraD.O. has migrated away from patch files.
In order for tests to run we require all submissions to be in the form of a Merge Request.
More details may be found at: https://www.drupal.org/docs/develop/git/using-gitlab-to-contribute-to-dr...
Comment #6
gun_dose commentedComment #7
cmlaraInitial thoughts are why we should be even touching the Global Request.. Turns out this is from a OLD core bug that this was even needed. #2950883: Allow form redirects to ignore ?destination query parameter.
https://www.drupal.org/node/3375113 for how this would apply to newer versions of core.
That all aside, it appears this is the way it needs to be for now and matches code later in the same class.
Forcing commit to bypass tests due to issues from #3496517: Improve phpunit default configuration and make it customisable.
Comment #9
cmlaraI believe this will need to ported to 2.x.
#2672554: Original page lost after TOTP authentication does not on cursory glance appear to be applicable as this is our 'force to redirect' where we do want to ignore the destination.
Comment #10
james.williamsJust reporting this anecdotally for now, as I can imagine it will want dealing with in its own issue, but similar to this report, I've found destination strings on reset password links break the TFA flow too. On following the link, users are sent to the destination in the URL, instead of to the TFA entry page - so may then see a 403 page as they couldn't complete logging in.